Palo Alto Networks headquarters in Silicon Valley
– Sundry Photography/Getty Images

Palo Alto Networks has released a tool designed to prevent security issues from entering application production.

Released as part of the Cortex Cloud platform, the application security posture management (ASPM) tool is an example of shift-left security, which sees security testing deployed sooner in the software and application development phase.

Cortex Cloud ASPM integrates directly into cloud development environments to continuously scan code, configurations, and pipelines to identify exposures across each phase of the development lifecycle.

The tool includes graph-based visualization to map out code, infrastructure, data, and identity intersections, demonstrating risks most likely to be exploited. Automated workflows can trigger intelligent responses to these risks, with a view to reducing mean time to remediation (MTTR).

Additionally, the platform consolidates findings from third-party tools into a single data lake for correlation and automated fixes. These partners include HashiCorp, the cloud lifecycle management tool, which offers Terraform’s infrastructure-as-code (IaC), widely used in networking.

ASPM has seen increased traction in networking, with analyst firms referencing it as a formal category in recent years. As an example, last year saw Forrester recognize CrowdStrike for its Falcon ASPM solution.

Similarly, the shift left trend in cybersecurity has been endorsed by hyperscalers such as Amazon Web Services (AWS).

By moving tasks traditionally performed later in the software development lifecycle (SDLC) to earlier in the process, shifting left can help reduce long-term costs and risks while strengthening an organization’s network security posture.