Cloud App Development

Cloud Use Improves Risk Management and Mitigation states CSA and Google

Cloud Security Alliance | June 23, 2022

Cloud Security Alliance
Measuring Risk and Risk Governance was just made available by the Cloud Security Alliance (CSA), the foremost global organization for establishing standards, certifications, and best practices to assist assure a safe cloud computing environment. The survey, developed by CSA in partnership with Google Cloud to evaluate the maturity of public cloud adoption and risk management processes within the company, provided a deeper knowledge of these practices.

Adopting technology that improves operational and customer experiences is a part of the digital transformation process. The cloud is increasingly being considered as a way to boost an enterprise's risk posture with a view to enhancing overall business risk management; this action is frequently supported by an improved strategy for application, data, and infrastructure security. Because both the cloud service provider and the customer have ownership in the provision of services, business risk assessment methodologies must be adjusted to the cloud model and take these consequences into account. A greater understanding of IT's impact on an enterprise's entire risk maturity, including the adoption of a shared fate partnership between CSP and customers, is provided by evaluating cloud and business risk together.

"With enterprises continuing to add production in the cloud and the growing use of cloud services, managing cloud and digital assets will be critical in risk management and measurement. While there is still work to be done as organizations mature their ability to manage cloud and multi-cloud security and risk mitigations, these issues are improved in the cloud when compared to current on-premise and legacy IT environments. This study confirms that an organization's best path to viable risk management involves IT modernization into the cloud or cloud-like on-premise infrastructure," 

Jim Reavis, co-founder and CEO, Cloud Security Alliance

The survey, which was conducted in two phases, was designed to advance industry understanding of business risk. More than 600 IT and security experts from a range of company sizes and locations responded to the second component of the study, an online survey, using the information acquired in the first round of interviews, which were conducted by CSA.

"Increasingly, cloud is becoming less of a risk to manage and more of a means to manage these risks. Continuously evaluating your risk status allows enterprises to properly configure and maximize the effectiveness of their security solutions, which in turn, protects their assets and improves business productivity. This study has shone a light on the opportunities enterprises can take to manage and measure their risk, and will hopefully lead to improved risk management practices. And, whereas these practices impact many areas in the enterprise, modernizing the approach helps both businesses and providers improve their cloud adoption," said Phil Venables, Chief Information Security Officer and Vice President of Google Cloud.

Spotlight

Every organization is now defined by the digital services it delivers. From engaging customers with new experiences to building new revenue opportunities, and driving digital-first touchpoints that protect and enable customers and communities, these services have never been more essential. As part of VMware’s work with technolog


Other News
Cloud Security

Lacework Unveils Cloud Security Community to Unite Customers and Peers

Lacework | September 07, 2023

Lacework, a trailblazer in data-driven cloud security, has introduced an innovative community platform, expanding its arsenal of cutting-edge technical resources. This dynamic community is a hub for Lacework's customers, support teams, and fellow cloud security experts. The Lacework Community is a multifaceted network comprising discussion forums, comprehensive documentation, a knowledge base, immersive events, and educational resources. Members are empowered to delve into a wealth of documentation through the platform's federated search or initiate unique discussions to glean insights from Lacework experts and industry peers. Jay Parikh, CEO of Lacework, said they were always looking for new ways to help their customers succeed and that the community would connect them with their peers and partners to learn and share faster and more broadly. He also added that customers would experience a new level of support from Lacework through the discussions, documentation, and engagement. Key features accessible to users of the Lacework Community include: Discussion Forums: Covering a broad spectrum of Lacework and cloud security topics Knowledge Base: Hosting numerous articles addressing common support issues How-to Guides: Curated by Lacework's Customer Success Architects Product Updates: Summarizing monthly releases and offering in-depth feature insights Networked Events: Featuring daily office hours and marketing events Integrated Documentation: Housing thousands of articles indexed for seamless federated search functionality John Turner, Senior Security Architect at LendingTree, said that things changed fast in the cloud security world and that companies faced new daily threats and tactics. He also noted that quick learning and peer feedback could significantly affect any company's security posture. He added that Lacework's community would provide that critical input and elevate the cloud security conversation. The Lacework Community is now open to both existing customers and potential prospects. Lacework is a platform providing comprehensive cloud security, including threat detection, anomaly identification, and compliance management across multi-cloud systems, workloads, and Kubernetes. However, it faces challenges for a few users as visibility is lacking and compliance-related metrics and IAM security control could be improved. IAM security management controls and detection of deviations and misconfigurations are critical, but have yet to be developed in Lacework. There is no data governance or data visibility. About Lacework Lacework, a data-driven cloud security platform, automates security at scale with its Polygraph Data Platform. This platform uniquely collects, analyzes, and correlates data across AWS, Azure, GCP, and Kubernetes, pinpointing crucial security events amid vast data streams. Clients rely on Lacework for revenue growth, safer product launches, and consolidated security solutions. Lacework strengthens cloud security, enabling faster innovation by scaling with an organization's dynamic cloud data, including code, identities, containers, and multi-cloud infrastructure. It offers security and development teams prioritized insights on significant risks.

Read More

Cloud Security

Orca Security Simplifies Cloud Asset Discovery with AI Technology

Orca Security | September 14, 2023

Orca Security, a leader in agentless cloud security, has unveiled a groundbreaking AI-driven cloud asset search feature within its Orca Cloud Security Platform. This innovation positions Orca as the first provider to offer an AI-powered cloud asset search that's as simple as asking a question. This development empowers not only security professionals but also developers, DevOps teams, cloud architects, and risk governance and compliance teams to swiftly and effortlessly gain insights into their cloud environments. Building upon its existing integrations with ChatGPT and Microsoft Azure OpenAI GPT-4 for generating remediation instructions, Orca's new AI-driven search functionality revolutionizes accessibility by enabling users to pose natural language queries like, ‘Do I have any Log4j vulnerabilities exposed to the public?’ or ‘Are there any unencrypted databases with sensitive data accessible on the internet?’ This democratizes cloud security, making it accessible to individuals across the organization, regardless of their expertise, to rapidly respond to zero-day risks, optimize cloud assets, and assess exposure to threats. Gil Geron, CEO and co-founder of Orca Security, emphasized the platform's user friendliness, stating, With our latest AI-powered cloud asset search, we are delivering on our promise to provide cloud security that is easy to operate. We built the industry’s first agentless cloud security platform to eliminate lengthy and labor-intensive deployments. Now we are focused on democratizing cloud security by introducing solutions that do not require reading through lengthy documentation or extensive training to operationalize, allowing security teams, developers, and DevOps teams to get value from day one. [Source: Business wire] Cloud asset discovery is a critical process involving the identification, categorization, and mapping of all digital assets within a cloud environment. This includes virtual machines, databases, storage instances, containers, networking components, and applications. Yet many organizations lack access to this vital information. Orca's patented SideScanning technology offers 100% visibility for asset discovery and is now presenting this data intuitively to various teams across organizations, enabling a comprehensive understanding of their cloud environments. This capability is particularly crucial during zero-day threats, where speed is essential, facilitating faster and more effective mitigations. Orca's solution also eliminates the need for users to understand different naming conventions for each cloud provider. Instead, users can ask general questions, and Orca will automatically search for the relevant status names for each provider, streamlining the search process and ensuring accurate results. The AI-powered cloud asset search feature is immediately available through a feature request in the Orca Cloud Security Platform. About Orca Security Orca Security is a leading provider of cloud security solutions that offer full-stack visibility of the complete cloud infrastructure. It provides deep insights into vulnerabilities, malware, misconfigurations, and more across various platforms, including AWS, Azure, Google Cloud, Alibaba Cloud, and Kubernetes. The platform is designed to provide complete visibility of the entire cloud estate, from development to production, without requiring an agent. The company is known for innovative SideScanning technology that delivers instant-on, workload-level security.

Read More

Cloud App Management

CoreStack Unveils New Cloud Assessment Product for MSPs

Business Wire | September 29, 2023

CoreStack, a global multi-cloud governance provider, today announced the release of CoreStack Assessments, a product that simplifies and streamlines multi-cloud assessments for managed services providers and their enterprise customers. CoreStack Assessments equips MSPs and SIs to run multi-cloud assessments at scale against cloud-native Well-Architected Frameworks as well as custom frameworks, enabling them to quickly and easily identify and resolve issues across security and compliance, cost, and operations. As organizations progress their cloud transformation, it’s imperative that they continue to operate in an optimized and well-architected manner, said Cyril Belikoff, GM of Azure and Industry GTM at Microsoft. CoreStack Assessments hits the mark by empowering single and multi-cloud customers with a comprehensive evaluation of architectural alignment with industry best practices. “We are thrilled to introduce CoreStack Assessments to our partners – and to simplify delivery of cloud assessments,” said Saba Arumugam, CoreStack’s Chief Technology Officer. “Armed with these powerful assessment capabilities, our partners will be able to capitalize more quickly on the opportunities that matter and help their customers realize the full potential of their cloud investments. This solution provides our partners a robust, flexible, and streamlined assessment experience so they can help customers embrace cloud best practices in the most efficient way possible.” Purpose-built for partners, CoreStack Assessments provides out-of-the-box support for Microsoft Azure, AWS, and GCP frameworks. Partners can also import existing custom frameworks, create custom assessment frameworks based on hyperscaler frameworks, or create new frameworks from scratch. With multi-level hierarchy and identity isolation, a clear and centralized workflow, and highly automated issue detection and recommendations, CoreStack Assessments provides MSPs new levels of assessment flexibility and scalability. The solution also provides powerful collaboration, evidence tracking, and reporting features. “For Cloudelligent, CoreStack Assessments has been a game changer,” said Dwayne Lyle, Chief Revenue Officer at Cloudelligent. “It has reduced the internal costs to deliver a Well-Architected Review and automated many of our manual activities, accelerating delivery of these assessments by 50% and helping us ensure our customers are always well-architected. Ultimately it has improved the customer experience and differentiated us from other AWS Well-Architected Partners who deliver reviews in a more traditional way.” CoreStack Assessments is offered alongside CoreStack NextGen Cloud Governance, a powerful set of solutions that leverage AI to provide continuous and autonomous governance for FinOps, SecOps, and CloudOps through one unified dashboard. CoreStack NextGen Cloud Governance is designed to help customers leverage best-of-breed cloud platforms with the least friction possible, boosting top-line revenues and bottom-line efficiencies whether they’re running AWS, Microsoft Azure, GCP, OCI, or a combination of cloud providers. CoreStack was recently named one of the fastest-growing private companies in the U.S., ranking 835th on the Inc. 5000 List for 2023. CoreStack's inclusion on this prestigious list underscores its striking growth and transformative influence within the cloud industry. CoreStack comes in 120th in the Software category and is the 10th best performing company in the Seattle area and 12th in Washington State. CoreStack has also been recognized by Frost & Sullivan, Forrester, Gartner, S&P Global, and IDC as an innovator and leader in cloud management. About CoreStack CoreStack provides a NextGen Cloud Governance platform that empowers enterprises to predictably increase top-line revenues, improve bottom-line efficiencies, and gain a competitive edge through AI-powered real-time cloud governance on autopilot. CoreStack's FinOps, SecOps, and CloudOps solutions embrace, enhance, and extend native-cloud capabilities, enabling reporting, recommendation, and remediation and providing single pane-of-glass governance across multi-cloud. Through executive dashboards for comprehensive real-time insights, CoreStack delivers transformative value such as 40% increase in operational efficiencies, 50% decrease in cloud costs, and 100% security assurance and compliance. CoreStack helps 750+ global enterprises govern $2+ billion in annual cloud consumption, and $300 million in cloud cost savings. Frost & Sullivan, Forrester, Gartner, S&P Global, and IDC have recognized CoreStack as an innovator and leader in cloud management. CoreStack is backed by strategic advisors, including the ex-CEO of Wipro and ex-CIO of Microsoft. The company is a Microsoft Azure (Legacy) Gold Partner, Amazon AWS Technology Partner with Cloud Operations Competency, Oracle Cloud Build Partner, and Google Cloud Build Partner. To learn more, visit www.corestack.io

Read More

Cloud Deployment Models

Mirantis’ Lens AppIQ: Upgrading Kubernetes Application Management

Mirantis | September 22, 2023

Mirantis has introduced Lens AppIQ, a new tool designed to simplify Kubernetes application management. Available directly to the 50,000 organizations using Lens, Lens AppIQ offers application intelligence, making it accessible for non-Kubernetes specialists to oversee applications across multiple clusters. Lens AppIQ aggregates information from various configuration files and sources, presenting it in a user-friendly tabbed display. This feature allows cloud-native developers to streamline the deployment and management of Kubernetes applications, offering web-based tools for viewing application details, configuring security measures, and automating deployment processes. With a quick launch time of under a minute, Lens AppIQ swiftly identifies applications in connected clusters and maps their components. Developers can access application architecture, metadata, logs, events, and more through Lens Desktop’s new 'Applications' view or the Lens AppIQ web portal, simplifying debugging, accelerating code releases, and enhancing performance optimization. DevOps professionals, platform engineers, and operators can utilize Lens AppIQ to define, monitor, and enforce policies related to application performance, security, and compliance. Automation features in Lens AppIQ facilitate repeatable deployments and enable effortless application migration to new Kubernetes environments. Miska Kaipiainen, Vice President of Engineering at Mirantis, reportedly stated, While Lens Desktop already provides an incredibly user-friendly experience for Kubernetes management, we understand that cloud-native development doesn't end there. That's why we've created Lens AppIQ. Lens AppIQ complements Lens Desktop by offering real-time intelligence and additional insights into the apps running on your Kubernetes clusters. This not only makes debugging, operation, and security easier but also opens up Kubernetes to a broader audience of developers who can benefit from streamlined processes without having to become Kubernetes experts. [Source – Businesswire] Lens AppIQ is available for free for small-scale and trial use, accommodating up to 10 nodes, two clusters, and two users. A Pro plan is available for larger-scale use, supporting up to 100 nodes, 10 clusters, and 50 users, priced at $35 per node monthly, inclusive of 8 hours/5-day business hours support. Enterprises can opt for a bespoke version with 24/7 support and custom pricing. Lens AppIQ is accessible within Lens Desktop for the 50,000 organizations currently using Lens and is also available as a Software as a Service (SaaS) solution. About Lens With over 1 million users worldwide, Lens Desktop is a leading tool for boosting productivity in Kubernetes application development and management. This desktop application breaks down barriers for newcomers to Kubernetes while significantly enhancing the efficiency of experienced users. Lens supports all certified Kubernetes distributions on any infrastructure and seamlessly runs on Linux, macOS, and Windows. As the world's largest and most advanced Kubernetes platform, it provides real-time workload management, development, debugging, monitoring, and troubleshooting across multiple clusters. Built on open-source principles, Lens enjoys a strong community with over 20,000 stars on GitHub. About Mirantis Mirantis is a leading company streamlining code delivery on public and private clouds with a ZeroOps approach to Kubernetes. It serves global enterprises, enhancing developer productivity and offering secure cloud solutions. Its clients include Adobe, DocuSign, PayPal, and others across diverse industries. Mirantis contributes to open-source projects like Lens and Kubernetes, empowering businesses to tackle complex challenges.

Read More

Spotlight

Every organization is now defined by the digital services it delivers. From engaging customers with new experiences to building new revenue opportunities, and driving digital-first touchpoints that protect and enable customers and communities, these services have never been more essential. As part of VMware’s work with technolog

Resources