Red Hat announced a multi-stage alliance to offer customers a greater choice of operating systems to run on Oracle Cloud Infrastructure (OCI).
Cavirin Systems announced support for the Google Cloud Security Command Center (Cloud SCC).
The Cloud SCC Dashboard now serves as a launching point for Cavirin’s CyberPosture Intelligence platform including assessment and monitoring, scoring, and remediation.
The solution offers customers single-plane visibility into CyberPosture scoring and management for Google Cloud Platform (GCP) services and resources, extending to on-premise assets. It permits visibility into risk posture monitoring and remediation of the customer’s Google Cloud services and resources configurations, and alerts the user to any changes including the what, who, and when.
This new capability builds upon the CyberPosture Intelligence platform’s current hybrid cloud auto-remediation capabilities, and, in our opinion, aligns with an October 2018 Forrester research report, “Best Practices: Cloud Workload Security” that lists as a requirement “comprehensive, cross-platform, multicloud coverage” where “CWS controls must uniformly cover all the cloud platforms that companies use to ensure efficient and comprehensive cloud security.”
This integration delivers the following functionality:
- Visibility into GCP services and resources including Virtual Private Clouds, Subnets, IAM, GKE, Compute Engine, Cloud Storage, BigQuery, and Cloud KMS. Additional services will follow in subsequent releases.
- Support for both the CIS GCP Foundation Benchmark, co-authored by Cavirin, as well as the GCP Network Policy Pack. These are a set of best-practices to establish a security posture baseline.
- Discovery of and visibility into GCP workloads, both VM and container. The solution assesses and then scores these assets against a broad set of controls, including the NIST CSF, CIS, SOC2, PCI, HIPAA, and GDPR, and then offers auto-remediation via Ansible Playbooks.
- Integration to Google StackDriver activity logs to detect new or changed resources.
- Integration to the Google Container Registry for image assurance.
- Roll-back and auto-remediation via Google Functions to specific configurations.
Cavirin’s CyberPosture Intelligence is now available via the Google Cloud Platform Marketplace.
Anupam Sahai, VP of Corporate Strategy and Business Development, Cavirin, said: “By doing a deep integration with Google Cloud Platform, Cavirin now provides a way to assess, monitor and remediate the platform’s assets for risk, security and compliance management. This provides visibility and manageability for Google Cloud Platform and hybrid cloud deployments, including multi-cloud deployments.”
Cavirin removes risk, security and compliance as a barrier to cloud adoption by automating with a broad set of customizable frameworks, benchmarks and guidelines. The company’s solution secures both the public cloud control plane as well as target hybrid cloud workloads (servers), on-premise, within the public cloud, and within containers. Cavirin maintains its cost-optimized footprint, quick deployment on-premise or within AWS, Google Cloud, and Azure, and less than 30 minutes to first remediation on-par with SaaS-based offerings.
Industry News
Snow Software announced a new global partner program designed to enable partners to support customers as they face complex market challenges around managing cost and mitigating risk, while delivering value more efficiently and effectively with Snow.
Contrast Security announced the launch of its new partner program, the Security Innovation Alliance (SIA), which is a global ecosystem of system integrators (SIs), cloud, channel and technology alliances.
Red Hat introduced new security and compliance capabilities for the Red Hat OpenShift enterprise Kubernetes platform.
Jetpack.io formally launched with Devbox Cloud, a managed service offering for Devbox.
Jellyfish launched Life Cycle Explorer, a new solution that identifies bottlenecks in the life cycle of engineering work to help teams adapt workflow processes and more effectively deliver value to customers.
Checkmarx announced the immediate availability of Supply Chain Threat Intelligence, which delivers detailed threat intelligence on hundreds of thousands of malicious packages, contributor reputation, malicious behavior and more.
Qualys announced its new GovCloud platform along with the achievement of FedRAMP Ready status at the High impact level, from the Federal Risk and Authorization Management Program (FedRAMP).
F5 announced the general availability of F5 NGINXaaS for Azure, an integrated solution co-developed by F5 and Microsoft that empowers enterprises to deliver secure, high-performance applications in the cloud.
Tenable announced Tenable Ventures, a corporate investment program.
Ubuntu Pro, Canonical’s comprehensive subscription for secure open source and compliance, is now generally available.
Mirantis, freeing developers to create their most valuable code, today announced that it has acquired the Santa Clara, California-based Shipa to add automated application discovery, operations, security, and observability to the Lens Kubernetes Platform.
SmartBear has integrated the powerful contract testing capabilities of PactFlow with SwaggerHub.
Venafi introduced TLS Protect for Kubernetes.