Aqua Security released a software-as-a-service (SaaS) cloud security product and an enterprise version of its platform that extends Aqua’s serverless and container-based workload protection tools to virtual machines (VMs).

The new Aqua Wave SaaS offering integrates three products. The first: an updated version of Aqua CSPM, which is the cloud security posture management technology Aqua acquired when it bought CloudSploit last year. It also includes Aqua’s vulnerability scanning product and its new Dynamic Threat Analysis product (Aqua DTA), which it announced in April.

Additionally, the updated Aqua CSPM includes new capabilities including auto-remediation for common misconfiguration errors as well as remediation advice that security analysts can apply manually. It also adds Google Cloud Platform (GCP) and Oracle Cloud support on top of existing Amazon Web Services (AWS) and Microsoft Azure support. And it provides infrastructure of code scanning of Terraform and AWS CloudFormation, which helps find weakness in deployment templates.

Customers wanted to deploy Aqua’s security tools as SaaS, said Andy Feit, VP of go-to-market for Aqua Security.

“Aqua Wave allows you to very quickly and easily get started with Aqua doing scanning, dynamic threat analysis, sandboxing, and cloud security posture management all in a SaaS environment,” he said. “You don’t have to install anything, and it’s up and running literally in minutes, you’re doing your first scan.”

Aqua Enterprise

The second new product — Aqua Enterprise — is essentially the company’s flagship cloud-native security product with several updates including VM support. It’s also available as SaaS or self-hosted software. It now secures the application build process, underlying infrastructure, and running workloads whether they are deployed as VMs, containers, or serverless functions.

Plus, it adds risks-based insight that prioritizes vulnerabilities according to customers’ environments. “So you can say just show me the vulnerabilities to this application that meet these criteria, and all of a sudden you go from thousands or even tens of thousands, down to a handful or a couple of dozen things that we are giving you that advice on and saying these should be addressed right now,” Feit said. “And that’s something that the development team can work on. You can’t show them a report with 370 things — they won’t get to them all. But if it’s 13 big ones, and you show them the risk, they’ll go fix those.”

The enterprise product also enables multi-app role-based access control (RBAC). This allows enterprise-wide deployments that span teams and applications to provide very granular permissions and custom roles. It becomes increasingly important to customers with distributed workforces, and the need for this separation of duties has intensified during the COVID-10 pandemic, Feit said. “That distribution of separation of duties and role-based authentication and access, and the ability to have a big team, a distributed team, not stepping on each other, not seeing things they shouldn’t are definitely higher on the priority list for our larger customers in this pandemic.”

Both Aqua Wave and Aqua Enterprise are generally available now.