Fortinet extended its cloud security and posture management capabilities to containers, Kubernetes, and continuous integration, continuous development (CI/CD) pipelines. The new product, FortiCWP Container Guardian, secures container registries from vulnerabilities and scans for misconfigurations to protect Kubernetes workloads.
This is important as companies increasingly use microservices to build and run applications. Gartner predicts that by 2022, more than 75% of global organizations will be running containerized applications in production, up from less than 30% today.
Fortinet’s new product comes about a week after McAfee announced a platform that provides data protection, threat prevention, governance, and compliance for both container and OS-based workloads.
Container Guardian makes it easier for developers and security teams to “shift left,” or build security into the software development lifecycle, wrote Vince Hwang, senior director of products and solutions at Fortinet, in a blog post. Shift left practices include “rapid detection of vulnerabilities for images and misconfigurations, integrations with leading CI/CD tools to automate and manage build cycles, automated policy enforcement for response actions, and overall compliance to security best practices using industry leading benchmark baselines,” he wrote.
And Container Guardian, he added, checks all of these boxes.
What Container Guardian DoesSpecifically, Container Guardian’s centralized dashboard gives developers expanded visibility into container registries and image inventory.
It scans container images for vulnerabilities and misconfigurations during the build process and enforces policies to prevent vulnerability propagation before images are deployed into container registries. Additionally, Container Guardian integrates with other container-based platforms to scan for vulnerabilities and categorize risk levels by container repository. It also continuously monitors and scans registries for new vulnerabilities.
Plus, it integrates with CI/CD tools to embed security testing into the software development cycle and enforces policies to control the build process. And to ensure compliance, Container Guardian continuously audits containers and clusters to detect misconfigurations and other security practices that aren’t compliant with policies. It can automate remediation or make recommendations to IT teams.
Comments