Check Point Expands its Cloud Native Application Protection Platform (CNAPP) with Risk Management Engine Giving Organizations Smarter Prevention and Faster Remediation
February 2023 by Marc Jacob
Check Point® Software Technologies Ltd. introduces a new risk management engine along with enhanced capabilities to the Check Point CloudGuard Cloud Native Application Protection Platform (CNAPP). The new capabilities add intelligent risk prioritization, agentless scanning, entitlement management and pipeline security. With a focus on context, speed and automation, the new capabilities operationalize cloud security, removing complexities and overhead noise associated with traditional standalone cloud security alerts, allowing security teams to focus on comprehensive threat preventions from code-to-cloud across the entire application lifecycle, while supporting DevOps’ agility.
Cloud adoption and digital transformation continues to accelerate. The 2022 Cloud Security Report revealed that 35% of respondents are running more than 50% of their workloads in the cloud. However, 72% are extremely concerned about cloud security, and 76% are hindered by the complexity of managing multiple cloud vendors, which often results in misconfigurations, lack of visibility, and exposure to cyberattacks. Moreover, the study revealed that misconfiguration is seen as the number one cause of security related incidents, which can be attributed to the need for around-the-clock security operations and alert fatigue.
With the launch of Effective Risk Management (ERM), in addition to Cloud Identity & Entitlement Management (CIEM), Agentless Workload Posture (AWP), and pipeline security tools, Check Point CloudGuard now provides smart risk prioritization that allows teams to quickly eliminate critical vulnerabilities, such as misconfigurations and over-privileged access, based on severity throughout the software development lifecycle. The collaborative output that enterprises receive is simple, easy to understand and focused on the threats that matter to them, thereby reducing the complexity that was once a challenge. By minimizing this complexity, the threat landscape is also reduced.
Check Point CloudGuard combines the latest tools into a new generation of CNAPP capabilities to aid security professionals, while removing barriers to DevSecOps with ShiftLeft tools. Check Point CloudGuard utilizes the power and potential of unification along with operational value to end users including:
Effective Risk Management: CloudGuard’s ERM engine prioritizes risks and provides actionable remediation guidance based on full context including workload posture, identity permissions, attack path analysis and the application business value. Security teams can now focus on the critical threats and administer “minimal effective dose” of security for maximum impact.
Cloud Identity & Entitlement Management: The CIEM capabilities understand effective permissions of users and cloud services, identify exposure and risks, and automatically generates explicit least privilege role recommendations to reduce access and revoke unused permissions. With CIEM built into ERM, users can understand their permissions and enforce least privilege across their cloud environments.
Agentless Workload Posture: AWP extends CloudGuard’s agentless infrastructure visibility into workloads. AWP scans and identifies risks including misconfigurations, malware detection, vulnerabilities and secrets across all cloud workloads including virtual machines, container and serverless functions. With this agentless deployment model, security teams gain deep workload security visibility at scale without impacting performance.
Pipeline Security: The pipeline security capabilities fully integrate the Spectral offering to detect and resolve misconfigurations, secrets, and vulnerabilities within CloudGuard. The developer-first security extends workload protection to the CI/CD to pipeline to remediate issues before reaching production. Security teams can shift CNAPP left and secure cloud applications from the start.