Introducing Cortex Cloud
Bringing together best-in-class CDR with the next version of Prisma Cloud's leading CNAPP for real-time cloud security.
Infrastructure as Code (IaC)
Iac enables engineers to version control, deploy, and improve cloud infrastructure while leveraging DevOps processes. This also presents an opportunity to proactively improve the posture of cloud infrastructure and reduce the burden on security and operations teams.
Cloud native infrastructure is evolving
For the sake of agility, businesses are adopting new cloud native design patterns and cloud services. Securing these new technologies without adding developer friction is essential to improving cloud security posture.
DevOps moves fast
DevOps change rates are measured in days, not months, enabled by agile methodologies with CI/CD processes and tools that maximize automation. If security isn’t embedded in these processes and tools, it gets left behind and breaks the release cycle.
Reactive security doesn’t scale
Waterfall review cycles break agile workflows and force developers to context switch. Early feedback fixes the problem at the source, freeing up both development and security teams.
Get the complete guide to leveraging IaC to take a proactive, developer-first approach to cloud security.
Automated Infrastructure as Code security
Prisma Cloud scans IaC templates for misconfigurations and exposed secrets across the development lifecycle, embedding security in integrated development environments, continuous integration tools, repositories and runtime environments. Prisma Cloud enforces policy-as-code early through automation, preventing deploying security issues and providing automated fixes.
- Continuous governance to enforce policies in code
- Embedded in DevOps workflows and tooling
- Automated misconfiguration fixes via pull requests
Our approach to IaC security
Backed by the community
Prisma Cloud IaC security is built on the open source project Checkov. Checkov is a policy-as-code tool with millions of downloads that checks for misconfigurations in IaC templates such as Terraform, CloudFormation, Kubernetes, Helm, ARM Templates and Serverless framework.
Check for policy misconfigurations
Checkov checks IaC templates against hundreds of out of the box policies based on benchmarks, such as CIS, HIPAA, and PCI.
Leverage context-aware policies
Checkov’s policies include graph-based checks that allow multiple levels of resource relationships for complex policies.
Integrated as part of the pipeline
Involving developers in remediation is the fastest way to get things fixed. Prisma Cloud provides feedback directly in DevOps tools, including integrated development environments (IDE), continuous integration (CI) tools, and version control systems (VCS).
Provide fast feedback throughout the development lifecycle
Enable fixes with code review comments
View all IaC security issues in one place
Build remediation work into DevOps workflows
Context aware and actionable feedback
Prisma Cloud includes automatic remediations for many policies along with guidelines for all policies.
Context aware visibility and policies
Provide actionable guidance
Trace cloud to code with code owners for faster remediation
Enable GitOps workflows
Enforced guardrails
Create a secure golden pipeline for infrastructure as code to be vetted and enforce GitOps best practices by leveraging automated guardrails.
Block severe issues from being added to repos and deployed
Set custom levels for blocking builds
Extend policy sets with custom policies
Provide actionable information about failed deployments
Code Security modules
INFRASTRUCTURE AS CODE SECURITY
Automated IaC security embedded in developer workflows
SOFTWARE COMPOSITION ANALYSIS (SCA)
Highly accurate and context-aware open source security and license compliance
CI/CD SECURITY
Graph-based CI/CD security for application development environments
SECRETS SECURITY
Full-stack, multidimensional secrets scanning across repos and pipelines.