Palo Alto Networks announced Prisma Cloud 3.0, the industry’s first integrated platform to shift security left — significantly improving organizations’ entire cloud security posture by reducing security risk at runtime. With a customer base that already includes 77% of the Fortune 100, the most complete Cloud Native Application Protection Platform (CNAPP) now also offers organizations cloud code security to embed critical protections in the development process, agentless security to complement existing agent-based protection and Cloud Infrastructure Entitlement Management (CIEM) for Microsoft Azure®.
“We developed Prisma Cloud as a fully integrated platform with best-of-breed capabilities that help our customers stay one step ahead of attackers and threats as their security needs evolve,” said Ankur Shah, senior vice president of product management, Prisma Cloud at Palo Alto Networks.
He added, “Prisma Cloud 3.0 takes that commitment even further. Our recent Unit 42 Cloud Threat Report shows the extent of emerging cloud code security risks: we found 63% of templates used in building cloud infrastructure contained misconfigurations that can expose environments to vulnerabilities. Prisma Cloud’s new capabilities secure cloud environments from development to runtime in a single platform, shifting security left to proactively address issues that begin in development.”
Earlier this year, Gartner® created the CNAPP category, stating that “optimal security of cloud-native applications requires an integrated approach that starts in development and extends to runtime protection,” and urging organizations to evaluate “cloud-native application protection platforms that provide a complete life cycle approach.”
“For security to keep up with the velocity of modern software development, it’s important to have integrated security controls across the development lifecycle — helping developers release code that is tested and secure, and to quickly correct security issues as they are found in runtime,” said Melinda Marks, senior analyst, Cloud and Application Security, Enterprise Strategy Group.
She added, “The new capabilities from Prisma Cloud will help customers scale modern development as they can deploy more secure infrastructure and applications in cloud environments.”
“Prisma Cloud has helped us rapidly expand our cloud security program to reach the current maturity level,” said Birat Niraula, regional co-head, Platform Security Architecture, Goldman Sachs.
He also said, “We believe the new enhancements to Prisma Cloud will empower us to provide comprehensive coverage and adopt more proactive strategies for securing our multi-cloud environment.”
As enterprises increase their cloud usage, the rate of creation and introduction of new cloud apps is expanding tremendously. A single misconfiguration in the code templates that development and DevOps teams rely on, on the other hand, might result in hundreds of warnings being generated in real time, which security teams must then handle. Infrastructure as Code (IaC) security and code changes are included directly into developer tools across the development lifecycle in Prisma Cloud 3.0, proactively addressing such misconfigurations.
With capabilities that cover all five of Gartner’s CNAPP categories, we believe Prisma Cloud 3.0 strengthens its position as the most comprehensive CNAPP by adding new features, such as: