{"id":110870,"date":"2020-05-08T06:00:37","date_gmt":"2020-05-08T13:00:37","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=110870"},"modified":"2020-12-04T03:32:31","modified_gmt":"2020-12-04T11:32:31","slug":"cloud-secure-cloud-native-applications","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2020\/05\/cloud-secure-cloud-native-applications\/","title":{"rendered":"Using a Full Lifecycle Approach to Secure Cloud Native Applications"},"content":{"rendered":"<p><div style=\"max-width:100%\" data-width=\"900\"><span class=\"ar-custom\" style=\"padding-bottom:41.78%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter wp-image-110889 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/05\/prisma_gartner-trends-2020_lp-1400x585-1.png\" alt=\"Prisma Cloud by Palo Alto Networks, lifecycle protection for cloud native applications. Describing the Gartner 2020 report on &quot;Top Security and Risk Management Trends.&quot;\" width=\"900\" height=\"376\" \/><\/span><\/div><\/p>\n<p><span style=\"font-weight: 400;\">Security professionals are being deluged by a profusion of tools \u2013 there seem to be point tools for nearly every single issue. Thankfully, there are platforms that smartly package these tools into more comprehensive solutions. The trend many are seeing now, though, is that these platforms have so far only focused on certain parts of the software development lifecycle. What many security teams need are simpler, full lifecycle approaches to secure cloud native applications.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I want to highlight a trend of consolidating cloud security posture management (CSPM) and cloud workload protection platforms (CWPP) into the emerging area of cloud native application protection, which offer a full lifecycle approach and simplify security. In addition, I'll present subsequent recommendations stemming from the consolidation.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Palo Alto Networks was recently listed by Gartner in \u201cTop Security and Risk Management Trends\u201d as one of three sample vendors converging <\/span><a href=\"https:\/\/start.paloaltonetworks.com\/gartner-market-guide-cwpp.html\"><span style=\"font-weight: 400;\">CWPP<\/span><\/a><span style=\"font-weight: 400;\"> and CSPM capabilities across development and production, including container\/serverless protection.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><strong>It Can Be Challenging to Secure Cloud Native Applications<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">Cloud native applications present tremendous challenges for security and risk professionals:<\/span><\/p>\n<h6>A larger number of entities to secure<\/h6>\n<p><span style=\"font-weight: 400;\">DevOps and infrastructure teams are leveraging microservices \u2013 using a combination of containers, Kubernetes and serverless functions \u2013 to run their cloud native applications. This growth is happening in conjunction with a constantly increasing cloud footprint. This combination leads to a larger number of entities to protect, both in production and across the application lifecycle.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h6>Environments are constantly changing<\/h6>\n<p><span style=\"font-weight: 400;\">Public and private cloud environments are constantly changing due to the rapid-release cycles employed by today\u2019s development and DevOps teams. As enterprises deploy weekly or even daily, this presents a challenge for security personnel looking to gain control over these deployments without slowing down release velocity.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h6>Architectures are diverse, spanning multi- and hybrid-cloud environments<\/h6>\n<p><span style=\"font-weight: 400;\">Enterprises are using a wide-ranging combination of public and private clouds, cloud services and application architectures. Security teams are responsible for addressing this entire infrastructure and how any gaps impact visibility and security.\u00a0<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><strong>The Need for Integrated Security Across the Application Lifecycle<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">In order to secure cloud native applications and cloud environments, security controls need to be addressed before deployment. This includes integrating vulnerability scanning and hardening checks into integrated developer environments (IDEs), security configuration management (SCM), continuous integration (CI) workflows and image registries to quickly pass feedback to the development teams and address security issues before deployments.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Additionally, protecting cloud environments and running applications is a top requirement for modern enterprises. Security teams need to continuously monitor cloud configurations, while also protecting the VMs, containers and serverless applications running on top of that infrastructure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is where a consolidated platform helps organizations scale their security efforts, both across the lifecycle and up and down the entire stack.<\/span><\/p>\n<p>&nbsp;<\/p>\n<h2><strong>An Emerging Category: Cloud Native Application Protection Platforms<\/strong><\/h2>\n<p><span style=\"font-weight: 400;\">Recently, Gartner published \u201cTop Security and Risk Management Trends,\u201d highlighting key themes and requirements for security and risk professionals. In the report, Gartner states:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cAs a result of the protection needs of cloud-native applications, the CWPP and CSPM market are rapidly converging into cloud-native application protection platforms. Support for scanning of containers and serverless functions in development is becoming a mandatory requirement for any CWPP. Runtime protection of containers and serverless functions is also becoming a requirement. CSPM across development and runtime is becoming a requirement.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the report, under Trend No. 8, we think Gartner includes recommendations for security and risk management (SRM) leaders looking to improve their cloud workload protection. Here are a few key recommendations that Palo Alto Networks has chosen to summarize:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Address the requirements of protecting cloud workloads, including server workload protection and <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2019\/11\/cloud-container-security\/\"><span style=\"font-weight: 400;\">container security<\/span><\/a><span style=\"font-weight: 400;\"> capabilities.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Prioritize CSPM to ensure workloads are configured properly and extend CSPM into the development process.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ensure your security provider is fully API-enabled for automation.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Consider a comprehensive cloud-native application protection platform that combines CWPP and CSPM, including capabilities for containers and <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2020\/03\/cloud-securing-serverless\/\"><span style=\"font-weight: 400;\">serverless<\/span><\/a><span style=\"font-weight: 400;\">, in a single solution.<\/span><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h6><strong>We believe Palo Alto Networks is well-positioned to secure cloud native applications.<\/strong><\/h6>\n<p><span style=\"font-weight: 400;\">In November 2019, Palo Alto Networks announced that Prisma Cloud was <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2019\/11\/cloud-native-security-platform\/\"><span style=\"font-weight: 400;\">the industry\u2019s most complete Cloud Native Security Platform<\/span><\/a><span style=\"font-weight: 400;\">, officially combining best-in-class capabilities from evident.io, RedLock, PureSec and Twistlock to address the needs that organizations have across CSPM and CWPP. And in the second half of 2020, Prisma Cloud will strengthen its capabilities, adding identity-based microsegmentation for applications running on any cloud, through the integration of the <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/company\/press\/2019\/palo-alto-networks-completes-acquisition-of-aporeto\"><span style=\"font-weight: 400;\">recent acquisition of Aporeto<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We\u2019re proud to be formally mentioned in this report, as we strongly feel our capabilities map directly to the suggested requirements for cloud native application protection.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To learn more about Gartner\u2019s insights and recommendations for securing cloud native applications, <\/span><a href=\"https:\/\/start.paloaltonetworks.com\/cloud-native-application-protection.html\"><span style=\"font-weight: 400;\">download \u201cTop Security and Risk Management Trends\u201d today<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Gartner's recent \u201cTop Security and Risk Management Trends\u201d introduces cloud native application protection platforms. Learn more and get your copy.<\/p>\n","protected":false},"author":663,"featured_media":110876,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6768],"tags":[7009,117,232],"coauthors":[6882],"class_list":["post-110870","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-the-cloud","tag-30-days-of-cloud","tag-gartner","tag-trends","cloud_sec_category-cloud-workload-protection-platform","cloud_sec_category-devsecops"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2020\/05\/Screen-Shot-2020-05-05-at-7.59.55-AM.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/110870","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/663"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=110870"}],"version-history":[{"count":6,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/110870\/revisions"}],"predecessor-version":[{"id":110902,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/110870\/revisions\/110902"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/110876"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=110870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=110870"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=110870"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=110870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}