Volver al glosario

Cloud & containers

Definiciones en lenguaje claro del tema cloud & containers.

19 términos
1
9
C
Cloud & containers

CIEM

Cloud infrastructure entitlement management, or CIEM, is the analysis of who and what can do what in a cloud estate: resolving granted permissions into effective permissions, and comparing those with the permissions actually used. It is the identity side of cloud security posture, and in most estates it is where the exploitable risk sits.

Leer definición
C
Cloud & containers

Cloud attack path

In cloud security, a cloud attack path is the chain of permissions and identity relationships that leads from an attacker’s starting position to the data or control they want, one grant at a time. Presenting the result of a cloud test as this chain, rather than a list of scanner alerts, is what distinguishes it from a posture tool.

Leer definición
C
Cloud & containers

Cloud misconfiguration

In cloud security, a cloud misconfiguration is a permissive or mistaken setting that exposes resources or grants more access than intended: over-broad roles, unrestricted trust between accounts, mis-scoped identity federation and exposed storage. It is a leading cause of public-cloud compromise, and one a scanner finds long before an attacker needs an exploit.

Leer definición
C
Cloud & containers

Cloud security posture management (CSPM)

In cloud security, CSPM (cloud security posture management) is tooling that continuously checks a cloud estate for misconfigurations and policy violations against a baseline. It sits in a crowded acronym space next to CNAPP and CIEM, which vendors themselves often blur, and it is the tool whose output a client brings us to validate.

Leer definición
C
Cloud & containers

CNAPP

A cloud native application protection platform, or CNAPP, is a product category that combines posture management, workload protection, entitlement analysis and infrastructure as code scanning in one console. The term describes a packaging decision by vendors rather than a new technique, and its value is correlation across those views.

Leer definición
C
Cloud & containers

Container escape

In cloud security, a container escape is the act of breaking out of a container to gain access to the host it runs on. It is the finding that turns a compromised container into a compromised node, and it is what decides the severity of a Kubernetes assessment: contained application bug, or foothold on the underlying host.

Leer definición
C
Cloud & containers

Container image scanning

Container image scanning is the analysis of a built image against vulnerability data, to identify the known flaws in the operating system packages and application dependencies inside it. It describes the contents of the artefact at rest and tells you nothing about how that container behaves once it is running.

Leer definición
C
Cloud & containers

Cross-account trust

Cross-account trust is a configuration in which a role in one cloud account permits identities from another account to assume it. It is the intended way to separate environments and to grant a supplier access, and it is also the relationship that turns a compromise of one account into a compromise of several.

Leer definición
C
Cloud & containers

CSP (cloud service provider)

A cloud service provider is the company that supplies computing resources as a service, from raw infrastructure to fully managed applications. Where its responsibility ends and yours begins is the first question of any cloud project.

Leer definición
2
2
1
2
1
1