Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable 部落格

訂閱

學著愛上稽核與合規 - 這不是不可能的事

Learn to love cloud audits and compliance with Tenable Cloud Security

Securing running workloads in the public cloud and meeting compliance standards are non-negotiable for most organizations. However, bringing together the necessary visibility, mapping and monitoring capabilities is often a manual, time-consuming process. As a result, audits and compliance exercises can cause delays and anxiety for security and compliance teams.

With audit and compliance requirements being a known dilemma in cloud infrastructure, “learning to love it” may sound more fanciful than realistic. In this blog, we’ll look at compliance and access security challenges in the cloud and how security pros can leverage the right tooling and strategies to make audits a breeze.

Despite appearing seemingly straightforward, achieving compliance in the cloud is not like filling out a few forms and being done with it. While some regulatory standards and best practices are very specific in their instructions, many others are much more abstract. An abstract standard could require you to accomplish a certain goal without explaining how to do it. In such cases, it’s anyone’s guess as to the methods and tools that need to be implemented to meet the standard — and what to do to ensure continuous compliance.

One reason some standards are abstract is that security is not a one-size-fits-all practice. Cloud environments, in particular, are multidimensional and dynamic and new vulnerabilities are constantly emerging. Also, organizations have different compliance requirements depending on their industry, company size and location. Even the longest list of specific compliance instructions still couldn’t cover all possible security scenarios.

The complex mix of regulations and frameworks is just one aspect of what makes security compliance so challenging in cloud environments. In most organizations, many teams and tools work within an organization’s cloud ecosystem, including:

  • Infrastructure teams who are developing and maintaining cloud environments;
  • Developers pushing code to production; and
  • Identity and access management (IAM) professionals provisioning new services and human identities.

The many stakeholders involved makes it extremely time consuming for security teams to map basic compliance details — like which resources are running and with what permissions — to industry benchmarks. Further complicating matters, many organizations use more than one cloud service provider (CSP) in combination with an on-premises infrastructure, leaving compliance teams stuck in endless email threads and meetings while working off of an asset inventory that’s likely out of date almost as soon as it’s created.

While compliance teams may bear the brunt of the labor, compliance is hardly a picnic for the DevOps and infrastructure teams, either. They’re often left scrambling to produce granular insights on their cloud resources.

Without a centralized view of the cloud architecture, compliance teams can’t see across multiple clouds or monitor frequent changes to the configurations of applications as they’re running. It is even more difficult to isolate compliance issues like a publicly exposed Lambda service or poor access management, let alone prioritize which one needs to be fixed first.

Learning to love audits with CNAPP

A high quality cloud native application protection platform (CNAPP) that encompasses infrastructure configuration management, centralized multi-cloud visibility and customizable reporting can relieve a lot of the compliance-related work for teams. In addition, a good CNAPP goes beyond compliance to harden the organization’s security posture in accordance with best practices. Because, as many seasoned security pros know, proving compliance is but only one part of a holistic security strategy. You may be able to pass audits but if you’re not keeping up with new and emerging best practices your cloud security posture will suffer. An ideal CNAPP will balance compliance and security best practices and offer the following four capabilities:

1.Breadth and depth of regulatory scope

The solution should cover a broad range of security best practices, and leading industry and compliance standards. 包含:

  • Benchmarks from bodies such as the Center for Internet Security (CIS), the International Organization for Standardization (ISO) and the National Institute of Standards and Technology (NIST)
  • Industry guidelines such as Payment Card Industry (PCI) Data Security Standard (DSS) and the American Institute of Certified Public Accountant (AICPA) Service Organization Control (SOC) Type 2
  • Regulations such as the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA).

Make sure the standards you need to follow are included in the platform’s provided templates and that they are updated frequently. In addition to having a wide range of out-of-the-box standards and policies, the solution should also allow users to customize them based on evolving needs that might not fit into one of the existing compliance buckets.

Supported compliance standards and statuses in Tenable Cloud Security.
Supported standards and statuses in Tenable Cloud Security.
Image source: Tenable Cloud Security

2.Compliance-cloud correlation

Context matters in security and compliance. You should be able to easily map each standard to specific cloud configurations, cloud resources and cloud activity policies while providing a clear inventory of compliance status per asset/account. For example, a publicly exposed Amazon Web Services (AWS) Lambda service might be circumventing Cloud Security Alliance (CSA) STAR Program standards , ISO and NIST frameworks or violating compliance regulations. Having this level of granularity in your CNAPP can help you drill down into areas where you might be out of compliance and swiftly remediate using built-in automation.

Tenable Cloud Security enables users to map specific policies and their status to industry standards.
Tenable Cloud Security enables users to map specific policies and their status to industry standards. Remediation tasks can be easily assigned via chatops workflows if policies are failed.
Image source: Tenable Cloud Security

3.Continuous monitoring

It shouldn’t take a business week to understand where you are relative to industry standards and best practices. Solutions like Tenable Cloud Security constantly check the entire environment against frameworks and benchmarks to ensure compliance and identify deviations and anomalies. The status of compliance should be visible to you — and any of your stakeholders — at any given point and without waiting for strenuous audits. Any delay in monitoring leaves you vulnerable to bad actors.

The Tenable Cloud Security main dashboard shows updated and prioritized findings across the environment,
The Tenable Cloud Security main dashboard shows updated and prioritized findings across the environment, including compliance mapping, open findings and toxic combinations that are most likely to be leveraged by an attacker.
Image source: Tenable Cloud Security

4.Flexible reporting

Your CNAPP should help you demonstrate compliance to auditors through visibility and flexible reporting for all organizational levels. For example, your tool should allow you to see the security posture and compliance of the entire organization but also allow you to drill down into specific accounts and specific projects to easily generate compliance reports for internal and external auditors.

SOC-2 automated compliance report in Tenable Cloud Security.
SOC-2 automated compliance report in Tenable Cloud Security. Users can download specific in-product compliance reports that map security findings to key compliance requirements and key remediation advice.
Image source: Tenable Cloud Security

總結

Achieving compliance in the cloud starts with translating compliance guidelines to the reality of cloud architecture. Understanding which cloud assets you have, the types of vulnerabilities they’re susceptible to and how these are related to auditing guidelines is essential for enabling the ongoing compliance work of monitoring, reporting and fixing. Once you have mapped your environment, you can proceed to automated monitoring based on compliance or customized policies. Finally, you can generate an automated report that helps demonstrate your compliance to auditors. Tenable Cloud Security can help you do all of this to reduce compliance hurdles and help you learn to love security audits.

For more information on Tenable Cloud Security or request a demo, please visit the Tenable Cloud Security product page: https://www.tenable.com/products/tenable-cloud-security

相關文章

您可以利用的網路安全最新消息

輸入您的電子郵件,就不會錯過來自 Tenable 專家提供的及時警示與安全指引。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,能夠以無與倫比的準確性查看和追蹤所有資產。

您的 Tenable Vulnerability Management 試用版軟體也包含 Tenable Lumin 和 Tenable Web App Scanning。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,使您能夠以無與倫比的準確性查看和追蹤所有資產。 立即訂閱一年。

100 項資產

選取您的訂閱選項:

立即購買

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,能夠以無與倫比的準確性查看和追蹤所有資產。

您的 Tenable Vulnerability Management 試用版軟體也包含 Tenable Lumin 和 Tenable Web App Scanning。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,使您能夠以無與倫比的準確性查看和追蹤所有資產。 立即訂閱一年。

100 項資產

選取您的訂閱選項:

立即購買

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,能夠以無與倫比的準確性查看和追蹤所有資產。

您的 Tenable Vulnerability Management 試用版軟體也包含 Tenable Lumin 和 Tenable Web App Scanning。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,使您能夠以無與倫比的準確性查看和追蹤所有資產。 立即訂閱一年。

100 項資產

選取您的訂閱選項:

立即購買

試用 Tenable Web App Scanning

享受完整存取我們專為新型應用程式所設計、屬於 Tenable One 曝險管理平台一部分的最新 Web 應用程式掃描產品。不需耗費大量人力或中斷重要 Web 應用程式,即可高度準確且安全地掃描您整個線上產品系列中是否含有任何弱點。 立即註冊。

您的 Tenable Web App Scanning 試用版軟體也包含 Tenable Vulnerability Management 和 Tenable Lumin。

購買 Tenable Web App Scanning

享受現代、雲端型的弱點管理平台,使您能夠以無與倫比的準確性查看和追蹤所有資產。 立即訂閱一年。

5 個 FQDN

$3,578

立即購買

試用 Tenable Lumin

利用 Tenable Lumin 視覺化並探索您的曝險管理、追蹤經過一段時間後風險降低的情形以及與同業進行指標分析。

您的 Tenable Lumin 試用版軟體也包含 Tenable Vulnerability Management 和 Tenable Web App Scanning。

購買 Tenable Lumin

聯絡業務代表,瞭解 Tenable Lumin 如何協助您取得您整個環境的深入解析和管理網路風險。

免費試用 Tenable Nessus Professional

免費試用 7 天

Tenable Nessus 是目前市場上最全方位的弱點掃描器。

最新 - Tenable Nessus Expert
現已上市

Nessus Expert 新增了更多功能,包括外部攻擊破綻掃描和新增網域及掃描雲端基礎架構的能力。按這裡試用 Nessus Expert。

請填妥以下表單以繼續 Nessus Pro 試用。

購買 Tenable Nessus Professional

Tenable Nessus 是目前市場上最全方位的弱點掃描器。Tenable Nessus Professional 可協助將弱點掃描流程自動化,節省您執行合規工作的時間並讓您與 IT 團隊合作。

購買多年期授權,節省更多。新增 365 天全年無休 24 小時全天候可使用電話、社群及對談的進階支援。

選擇您的授權

購買多年期授權,節省更多。

增加支援與訓練

免費試用 Tenable Nessus Expert

免費試用 7 天

Nessus Expert 是專為現代攻擊破綻所打造,它能讓您從 IT 到雲端洞察更多資訊,並保護貴公司免於弱點危害。

您已經有 Tenable Nessus Professional 了嗎?
升級至 Nessus Expert,免費試用 7 天。

購買 Tenable Nessus Expert

Nessus Expert 是專為現代攻擊破綻所打造,它能讓您從 IT 到雲端洞察更多資訊,並保護貴公司免於弱點危害。

選擇您的授權

購買多年期授權省更多!

增加支援與訓練