Cloud Security Posture Management

Also known as:CSPM

Cloud Security Posture Management: Detects misconfigurations and compliance deviations in cloud environments. This capability addresses dynamic cloud resourcesCloud ResourceA provisioned cloud object such as a workload, identity, storage service, network, or key. and shared responsibilitiesResponsibilityAn explicitly assigned obligation to make, perform, or verify a security decision or task.. Automated inventory, secure configurationSecure ConfigurationA configuration baseline that minimizes unnecessary exposure and enforces intended security controls., identity controlsIdentity ControlA control that verifies, governs, or monitors digital identities and their access., and continuous monitoringMonitoringThe continuous observation of systems, identities, networks, and controls for relevant changes. are particularly important.

How it works and where it fits

Cloud Security Posture Management denotes a technical component or operating environment with its own trust boundaries, identities, interfaces, and dependencies. Security is determined not only by the product, but by architecture, configuration, and the way data and privileges cross component boundaries. Management planes and production processing should be considered separately.

Practical security relevance

Secure operation depends on complete inventory, hardened baselines, least privilege, patchability, and centralized telemetry. Changes should be reproducible and reviewable. Exposed interfaces, default access, secrets, and supply-chain dependencies need particular attention; isolation, backup, and recovery must also be exercised in realistic conditions.

  • Security MisconfigurationSecurity MisconfigurationInsecure or incomplete configuration of systems, applications, or cloud services.: Insecure or incomplete configuration of systems, applications, or cloud services.
  • Cloud-Native Application Protection PlatformCloud-Native Application Protection PlatformIntegrated platform for securing cloud applications across development and operations.: Integrated platform for securing cloud applications across development and operations.
  • Infrastructure as Code SecurityInfrastructure as Code SecurityExamination of declarative infrastructure definitions for misconfigurations and risks.: Examination of declarative infrastructure definitions for misconfigurations and risks.
  • Shared Responsibility ModelShared Responsibility ModelDivision of security tasks between the cloud provider and the customer.: Division of security tasks between the cloud provider and the customer.