Palo Alto Networks claims the only way to secure applications from code to the cloud is to prevent risk from entering the development pipeline and application breaches in production. That’s why the vendor unveiled its Prisma Cloud Darwin release to specifically address the longstanding gap between developers and security professionals.
Melinda Marks, practice director at Enterprise Strategy Group (ESG), agrees. “Organizations have struggled to scale security to keep up with cloud-native application development — which typically brings greater speed and volume of releases.”
“To scale, security responsibilities shifted left to development so developers could use security tools to secure their code, but then, typically, security had limited visibility and control into security processes in development,” she told SDxCentral in an email.
Marks said developers might not consistently scan or test their code. Even when they use tools, they might lack the information for remediation or get overwhelmed by numerous alerts, leading to missed vulnerabilities. On the security side, their tools primarily detect issues when the application is already in use. By then, it's often too late for security teams to triage and for developers to remediate at a late stage in the software development lifecycle.
Ankur Shah, senior VP of Prisma Cloud at Palo Alto Networks, echoed this disconnect: “In many organizations, the ratio of developers to security professionals can be 100 to 1, resulting in understaffed teams. The current approach of working in silos does not guarantee comprehensive code to cloud security."
“This gap will widen as developers increasingly use AI [artificial intelligence] to write and deploy code more quickly,” Shah added.
For closing this gap, Marks said, “A code-to-cloud platform approach gives security teams visibility and control over the entire development process so they can better support development to more efficiently secure their code. So they can set policies and secure practices and processes in place, they can more effectively manage security risk, and if there is a security issue in runtime, they can more efficiently respond to protect their applications.”
Palo Alto Networks’ Prisma Cloud Darwin releaseShah said Palo Alto Networks’ cloud-native application protection platform (CNAPP) — Prisma Cloud — fosters developer-security professional collaboration by linking production security issues to specific remediation recommendations in code.
He noted that the vendor introduced the Darwin release to enhance the code-to-cloud intelligence, which includes the following features:
- AppDNA provides an application-centric view of cloud security for visibility into cloud services, infrastructure assets, compute workloads, API endpoints, data and code of applications.
- Infinity graph allows an easier understanding of risks by correlating the entire security stack, including misconfigurations, vulnerabilities, pipeline risks, exposure, identity and secrets, and sensitive data, to reveal potential attack paths leading to breaches.
- Code-to-cloud remediation streamlines the remediation process by directly addressing risks in the cloud to replace the inefficient ticket opening system. It also enables developers to rectify issues at the source, preventing future occurrences.
- Code-to-cloud vulnerability management reduces vulnerability resolution times, emphasizing secure-by-design practices by allowing users to trace vulnerabilities to the source and easily fix the base image or code repo.
- Code-to-cloud dashboard simplifies reporting processes for leadership and boards by offering visibility and control across the entire application lifecycle, down to the supply chain.
- Cloud discovery and exposure management provides an external perspective into cloud environments and enables security teams to discover, evaluate and mitigate unknown and unmanaged internet exposure.
Palo Alto Networks said that current code-to-cloud security often is siloed with an average of six to 10 tools for cloud security alone, which leads to an incomplete security posture and creates a massive operational burden for security teams.
The CNAPP offers a unified platform to connect insights from the developer environment through application runtime for security teams, the vendor claims.
Gartner defines CNAPPs as consolidating a large number of previously siloed capabilities including runtime cloud workload protection platform (CWPP), cloud security posture management (CSPM), cloud infrastructure entitlements management (CIEM), development artifact scanning, and infrastructure-as-code (IaC) scanning.
“These were seen as separate essential capabilities that were needed, but when organizations had to buy and use the separate tools, they couldn’t keep up with development because they would get separate alerts, without the context to prioritize them,” Marks said.
“So consolidation is the right approach, and organizations should evaluate them based on whether they give them visibility and control of all the things that scale rapidly and introduce risk with cloud-native development,” she added.
Comments