Cloud/next-generation gateway security

Cloud Security Posture Management (CSPM)

What is CSPM

Many companies are migrating from the conventional on-premise environment to a cloud environment such as IaaS or PaaS as their business expands. On the other hand, prioritizing development speed and flexibility may lead to inadequate security settings on IaaS or PaaS, and these setting errors may lead to information leakage incidents.
IaaS and PaaS have their own setting items that do not exist in on-premises environments. Cloud Security Posture Management (CSPM) is a solution that provides detection of configuration errors and compliance diagnosis for these IaaS/PaaS environments.

What CSPM can offer

CSPMでは、IaaSやPaaSの以下のような課題に対する解決策を提供します。

Detects setting errors related to setting items unique to the IaaS/PaaS environment
Provides framework-compliant configuration audit items
Manage from one console for multi-cloud

Number of incidents caused by misconfigurations found in the investigation

Many IaaS setting errors go unnoticed by administrators and operators.
McAfee conducted a survey of 1,000 companies in 11 countries on the number of misconfigurations that occur each month, and found that about 99% of misconfigurations go unrecognized.

Number of incidents caused by misconfigurations found in the investigation

引用:McAfee社 - クラウド固有の問題: IaaS(Infrastructure-as-a-Service )の採用とリスク
https://www.mcafee.com/enterprise/ja-jp/forms/gated-form.html?docID=5580a0ae-cb39-42e8-9d59-ab8385a36a5

At what points are configuration errors likely to occur?

It can occur with IaaS-specific elements such as: It is necessary to have a different perspective from the on-premise environment where security operations have been conducted so far.

At what points are configuration errors likely to occur?

Such…

Issues with Security Monitoring Functions Provided by Cloud Providers

Task ①
We provide audit tools for each cloud provider, but in the case of a multi-cloud environment, an audit mechanism is required for each.

課題②
IaaSでは日々新しいサービスが提供されています。運用者がこれらのサービス追加スピードに追随するためには、高い学習コスト・工数が必要となります。

What you can do with CSPM

Detects setting errors related to setting items unique to the IaaS/PaaS environment

CSPM products store configuration audit items for each IaaS and PaaS environment as templates.
Detect vulnerable settings of IaaS/PaaS through regular scans.

* Excerpt from McAfee MVISION Cloud management console

Provides framework-compliant configuration audit items

It provides audit policies that comply with security frameworks such as NIST (National Institute of Standards and Technology), CIS (Center For Internet Security Controls), HIPAA (Health Insurance Portability and Accountability Act), and PCI-DSS.

Manage from one console for multi-cloud

Multiple cloud environments can be centrally managed on one console.
By integrating and managing settings and access status on a single dashboard, you can break away from complicated management and significantly reduce operation man-hours.

Related solutions