Connect with us

Hi, what are you looking for?

Biz Solutions

Qualys Inc. adds Infrastructure as Code (IaC) scanning to its CloudView app

Qualys CloudView allows complete visibility and security control of public cloud workloads and now assesses IaC templates for misconfigurations. IaC assessments are integrated into the software development cycle to ensure that only code conforming to the organization’s security standards is deployed.

Qualys, Inc. (NASDAQ: QLYS), a pioneer and leading provider of disruptive cloud-based IT, security and compliance solutions, announced it is adding Infrastructure as Code (IaC) scanning to its CloudView app. This will enable detection and remediation of misconfigurations early in the development cycle, removing risk in the production environment.

As noted in the (ISC)2 2021 Cloud Security Report , security professionals’ biggest threat with public clouds is the misconfiguration of resources. Misconfigurations are often detected post-deployment, leaving companies with a much larger attack surface and more vulnerable to exploits. Increasingly, organizations are using IaC to deploy cloud-native applications and provision their cloud infrastructure. Thus, it’s important to shift security left to identify and remediate misconfigurations at the IaC template stage. Detecting security issues earlier in the development cycle accelerates secure application delivery and fosters greater collaboration between DevOps and security teams. More importantly, it enforces better security policies in the production environment. 

“Security and risk management leaders managing cloud infrastructure security should create safe-to-fail environments to facilitate developer innovation by integrating intelligent security tooling with delivery pipelines (such as infrastructure-as-code [IaC] scanning) to identify risks early and alert on unsafe workloads before they are deployed.” Gartner, Cool Vendors in Cloud Security Posture Management, Tom Croll, Neil MacDonald, Mark Wah, Prateek Bhajanka, June 9, 2021.

Qualys CloudView allows complete visibility and security control of public cloud workloads and now assesses IaC templates for misconfigurations. IaC assessments are integrated into the software development cycle to ensure that only code conforming to the organization’s security standards is deployed. Qualys’ Cloud Platform approach delivers complete visibility, bringing together runtime and build-time posture and the drift between the two into a single view.

Advertisement. Scroll to continue reading.

The new capabilities enable organizations to:

Assess security posture throughout CI/CD pipeline

Organizations can now assess the security posture earlier in the development cycle, dramatically reducing security risk post-deployment. CloudView IaC Security provides a command line interface to perform a security assessment locally. To gate deployment if misconfigurations are detected, plug-ins for source code repositories at check-in and CI/CD platforms are also available.  

Adhere to security best practices

CloudView IaC Security makes it easy for organizations to adopt security best practices promoted by cloud platform providers. CloudView IaC Security supports popular IaC languages like – Terraform, CloudFormation (CF), and Azure Resource Manager (ARM). It also checks configurations against thousands of security best practices as prescribed by Amazon Web Services, Azure, Google Cloud Platform, and standard bodies including the Center for Internet Security. Additionally, CloudView automatically provides remediation suggestions when a non-compliant configuration is detected.

Advertisement. Scroll to continue reading.

Ensure compliance with industry mandates

Using CloudView IaC Security, organizations can assure compliance with more than 20 industry mandates such as PCI, HIPAA, and NIST 800-53. This reduces the burden on the DevOps security teams and ensures a streamlined process during mandatory compliance audits.

“With the addition of IaC assessment to CloudView, Qualys is extending its cloud security posture management (CSPM) solution to handle shift-left use cases,” said Sumedh Thakar, president and CEO of Qualys. “Leveraging the Qualys Cloud Platform and its integrated apps, customers can now insert security automation into all stages of their application lifecycle ensuring complete visibility into both runtime and build-time posture via a unified dashboard.”

Availability

Qualys CloudView with IaC Security is currently in beta and will be available later this year. If you would like to participate in the beta program, please sign up at qualys.com/iac-security-beta.

Advertisement. Scroll to continue reading.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Radenta Technologies, one of the country’s leading solutions integrators, joined the 21st annual IT Interaction Philippines (ITIP) 2024 National Conference held recently at Fili NuStar...

HEADLINES

At its current level of mass scale impact, AI may well surpass cloud and even the internet in its significance as a technology disruptor....

HEADLINES

The branch opening reflects Asialink’s strategic expansion to reach underserved communities, offering innovative loan products with fast, accessible and convenient loan approval, and services...

HEADLINES

Kiehl’s introduced exclusive product bundles offering up to 50% savings, along with optimized product availability and enhanced product detail pages. These offerings were complemented...

White Papers

According to the report, the rate of mobile network traffic data is expected to grow almost three-fold by the end of 2030 from present...

HEADLINES

BIGO Philippines Awards Gala 2024 was attended by more than 300 people including creators, users, agencies, partners and media. The awards night, which was...

HEADLINES

Together, IBM and SAP aim to help organizations more seamlessly transition and modernize their on-premises ERP environments to the cloud and support AI-powered business...

HEADLINES

The custom-designed motorcycle channels the essence of Mavuika and her Flamestrider, blending bold flames, intricate detailing, and a sleek, modern design. It’s more than...

Advertisement