CSPM
Cloud Security Posture Management (CSPM) continuously scans cloud environments for security misconfigurations and potential risks.
Cloud Security Posture Management (CSPM) continuously checks cloud environments for misconfigurations. It finds issues like publicly accessible storage, missing encryption, or overly permissive network rules.
How it works
A CSPM reads the configuration of Azure, AWS, or Google Cloud through APIs. It compares the configuration against rules and standards such as the CIS Benchmarks. Deviations appear as findings with a severity level and a recommended action. Many solutions also show how findings combine to form a realistic attack path.
For example, a developer sets up storage with public access for a test. This storage contains copies of customer data. The CSPM reports the finding within hours. The team removes public access and checks logs to see if the data was accessed.
What to look out for
- Prioritise findings. A CSPM often discovers thousands of issues, so start with public access and identities.
- Assign findings to clear owners, usually the teams operating the cloud resources.
- Prevent misconfigurations early by using checks within your Infrastructure as Code.
- Include all accounts and subscriptions in your scans, including test and development environments.
How it differs from related tools
CSPM checks the configuration, which is the state of the cloud environment. It does not detect active attacks. Detecting attacks requires cloud logs in a SIEM and corresponding detection rules. CIEM complements CSPM with permission analysis, while CWPP protects the workloads themselves.
Switzerland and regulation
Organisations processing personal data must implement appropriate technical measures under the revFADP (revised Federal Act on Data Protection). A continuous configuration audit helps to demonstrate compliance. Financial institutions must also meet FINMA's requirements for outsourcing and cloud data security.
Typical mistakes
A common mistake is implementing a CSPM without a process for handling findings. The list of findings grows, and no one feels responsible for fixing them.
How we implement it
We integrate findings from your CSPM and the corresponding cloud logs into our SOC. We treat critical findings that are part of an attack as a Case.