Securing your cloud with CSPM

David Amrani Hernandez
3 min readDec 5, 2019

As companies begin to move their infrastructure and products to cloud environments, attackers’ interest also increases in them. This, coupled with the rise of new technologies such as Docker or Kubernetes makes it difficult to track the assets belonging to a product or organization.

This generates some dangerous situations that, in addition, are the principal attack vector: We don’t know what we have and, therefore, how insecure we are.

Figure 1 — Scope of CSPM, CASB and CWPP by Gartner

To solve this problem we found 3 main cloud security tools:

  • CASB · Cloud Security Access Brokers
  • CWPP · Cloud Workload Protection Platforms
  • CSPM · Cloud Security Posture Management

CASB, CWPP, and CSPM offer a set of capabilities to fight cloud risks, but no single group performs all the functions of the others.¿Que es CSPM?

What is CSPM?

CSPM is responsible for security assessment and security compliance monitoring (CIS, NIST, HIPAA, GDPR…).

The CSPM tools include use cases for compliance assessment, operational monitoring, DevOps process integrations, incident response, risk…

--

--

David Amrani Hernandez
David Amrani Hernandez

Written by David Amrani Hernandez

Senior Cloud Security | Secdevops @ Telefonica ☕️ Writing about Cloud, Cybersecurity, new technologies and other hobbies 🚀

Responses (1)