From the course: Cloud Security Architecture for the Enterprise
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Cloud-native application protection (CNAPP)
From the course: Cloud Security Architecture for the Enterprise
Cloud-native application protection (CNAPP)
- [Instructor] One of the key decisions of your cloud security monitoring architecture is how you approach monitoring your application workloads. Cloud workloads are applications hosted in virtual machines or containers. Cloud security posture management tools are API based and are not sufficient to protect them as they rely on control plane access to your cloud environment. To protect your workloads, you need to gain visibility inside of the virtual machines or containers themselves. This is often done by installing a monitoring agent into the workload. The approach is why we have limited runtime visibility to most Platform as a Service or serverless workloads as they are often multi-tenant and don't allow installation of agents. Cloud workload monitoring and protection tools provide vulnerability management, anti-malware, and even benchmarks and workload hardening of our workloads. Just like cloud security posture…