<aside> 📘 relates:

TL;DR;

主要是 CSPM、DSPM,核心点如下:

  1. vendor independent,不依赖于某个云,而是关注于跨云管理
  2. DSPM 以数据为核心,关注敏感数据发现,尤其是数据在哪、谁在访问、访问方式等
  3. CSPM 以配置为核心,提出云时代最大的安全风险就是配置错误

除此之外还有一些其他的概念:

  1. CWPP 这是比较传统的云主机防护 agent
  2. CASB 跨云 API 的跳板机
  3. CIEM 跨云的权限管理(IAM)
  1. NSPM 跨云的网络策略管理
  2. ASPM 安全左移,更关注 dev 侧的安全发现

总的来说,一个大趋势就是跨云、下云,让用户摆脱云的控制。 而且部署方式也从 agent 到 agentless 的演变,提供安全 SaaS 云, 以 API 的形式对多云进行远程扫描。

</aside>

blog-image_Cloud-security-acronyms_Timeline.png

Cloud Security Posture Management

Cloud Security Posture Management

Where did all these acronyms come from? What do they mean? And more importantly, how can they help you figure out how to secure what you’re building in the cloud?

These “C” acronyms typically come from the hard work of analysts at firms like Gartner, Forrester, and 451 Research. Despite adding a bit of confusion, these acronyms are actually a tool for simplicity.

Each of these terms tries to encompass a set of solutions that are trying to solve a problem through similar approaches. They are a vendor-neutral way of making sense of the jam-packed cloud security. market. As a builder, you can use these acronyms to get a quick idea of what a tool is trying to do without having to parse its marketing message and positioning.

Now, the downside is that not every solution fits into a clear box. You’re going to see a number of aspects of each of these categories in various products and in open source projects, depending on the underlying principles of that tool. And that’s okay.

The acronyms still serve an important first filter to help you find the right combination of tools for your environment.

Here in this article, We’re going to focus on the acronyms that apply to tools meant to protect what you’re building in the cloud.

CSPM (cloud security posture management)

It stands for cloud security posture management.

Now there’s a technical definition somewhere, but what it really boils down to is monitoring

The logs and configurations of the services you’re using with your cloud service provider, like AWS, Microsoft Azure, or Google Cloud.The goal is to ensure that nothing is misconfigured and things line up with what you’re expecting.

CSPM tools have more advantages like helping you meet compliance requirements, implementing best practices. And more.

Now, while the PM stands for posture management.

CWPP (Cloud Workload Protection Platforms).