Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Blog de Tenable

Suscribir

Aprendiendo a amar las auditorías y el cumplimiento, sí es posible

Learn to love cloud audits and compliance with Tenable Cloud Security

Securing running workloads in the public cloud and meeting compliance standards are non-negotiable for most organizations. However, bringing together the necessary visibility, mapping and monitoring capabilities is often a manual, time-consuming process. As a result, audits and compliance exercises can cause delays and anxiety for security and compliance teams.

With audit and compliance requirements being a known dilemma in cloud infrastructure, “learning to love it” may sound more fanciful than realistic. In this blog, we’ll look at compliance and access security challenges in the cloud and how security pros can leverage the right tooling and strategies to make audits a breeze.

Despite appearing seemingly straightforward, achieving compliance in the cloud is not like filling out a few forms and being done with it. While some regulatory standards and best practices are very specific in their instructions, many others are much more abstract. An abstract standard could require you to accomplish a certain goal without explaining how to do it. In such cases, it’s anyone’s guess as to the methods and tools that need to be implemented to meet the standard — and what to do to ensure continuous compliance.

One reason some standards are abstract is that security is not a one-size-fits-all practice. Cloud environments, in particular, are multidimensional and dynamic and new vulnerabilities are constantly emerging. Also, organizations have different compliance requirements depending on their industry, company size and location. Even the longest list of specific compliance instructions still couldn’t cover all possible security scenarios.

The complex mix of regulations and frameworks is just one aspect of what makes security compliance so challenging in cloud environments. In most organizations, many teams and tools work within an organization’s cloud ecosystem, including:

  • Infrastructure teams who are developing and maintaining cloud environments;
  • Developers pushing code to production; and
  • Identity and access management (IAM) professionals provisioning new services and human identities.

The many stakeholders involved makes it extremely time consuming for security teams to map basic compliance details — like which resources are running and with what permissions — to industry benchmarks. Further complicating matters, many organizations use more than one cloud service provider (CSP) in combination with an on-premises infrastructure, leaving compliance teams stuck in endless email threads and meetings while working off of an asset inventory that’s likely out of date almost as soon as it’s created.

While compliance teams may bear the brunt of the labor, compliance is hardly a picnic for the DevOps and infrastructure teams, either. They’re often left scrambling to produce granular insights on their cloud resources.

Without a centralized view of the cloud architecture, compliance teams can’t see across multiple clouds or monitor frequent changes to the configurations of applications as they’re running. It is even more difficult to isolate compliance issues like a publicly exposed Lambda service or poor access management, let alone prioritize which one needs to be fixed first.

Learning to love audits with CNAPP

A high quality cloud native application protection platform (CNAPP) that encompasses infrastructure configuration management, centralized multi-cloud visibility and customizable reporting can relieve a lot of the compliance-related work for teams. In addition, a good CNAPP goes beyond compliance to harden the organization’s security posture in accordance with best practices. Because, as many seasoned security pros know, proving compliance is but only one part of a holistic security strategy. You may be able to pass audits but if you’re not keeping up with new and emerging best practices your cloud security posture will suffer. An ideal CNAPP will balance compliance and security best practices and offer the following four capabilities:

1.Breadth and depth of regulatory scope

The solution should cover a broad range of security best practices, and leading industry and compliance standards. Estos incluyen los siguientes:

  • Benchmarks from bodies such as the Center for Internet Security (CIS), the International Organization for Standardization (ISO) and the National Institute of Standards and Technology (NIST)
  • Industry guidelines such as Payment Card Industry (PCI) Data Security Standard (DSS) and the American Institute of Certified Public Accountant (AICPA) Service Organization Control (SOC) Type 2
  • Regulations such as the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA).

Make sure the standards you need to follow are included in the platform’s provided templates and that they are updated frequently. In addition to having a wide range of out-of-the-box standards and policies, the solution should also allow users to customize them based on evolving needs that might not fit into one of the existing compliance buckets.

Supported compliance standards and statuses in Tenable Cloud Security.
Supported standards and statuses in Tenable Cloud Security.
Fuente de la imagen: Tenable Cloud Security.

2.Compliance-cloud correlation

Context matters in security and compliance. You should be able to easily map each standard to specific cloud configurations, cloud resources and cloud activity policies while providing a clear inventory of compliance status per asset/account. For example, a publicly exposed Amazon Web Services (AWS) Lambda service might be circumventing Cloud Security Alliance (CSA) STAR Program standards , ISO and NIST frameworks or violating compliance regulations. Having this level of granularity in your CNAPP can help you drill down into areas where you might be out of compliance and swiftly remediate using built-in automation.

Tenable Cloud Security enables users to map specific policies and their status to industry standards.
Tenable Cloud Security enables users to map specific policies and their status to industry standards. Remediation tasks can be easily assigned via chatops workflows if policies are failed.
Fuente de la imagen: Tenable Cloud Security.

3.Continuous monitoring

It shouldn’t take a business week to understand where you are relative to industry standards and best practices. Solutions like Tenable Cloud Security constantly check the entire environment against frameworks and benchmarks to ensure compliance and identify deviations and anomalies. The status of compliance should be visible to you — and any of your stakeholders — at any given point and without waiting for strenuous audits. Any delay in monitoring leaves you vulnerable to bad actors.

The Tenable Cloud Security main dashboard shows updated and prioritized findings across the environment,
The Tenable Cloud Security main dashboard shows updated and prioritized findings across the environment, including compliance mapping, open findings and toxic combinations that are most likely to be leveraged by an attacker.
Fuente de la imagen: Tenable Cloud Security.

4.Flexible reporting

Your CNAPP should help you demonstrate compliance to auditors through visibility and flexible reporting for all organizational levels. For example, your tool should allow you to see the security posture and compliance of the entire organization but also allow you to drill down into specific accounts and specific projects to easily generate compliance reports for internal and external auditors.

SOC-2 automated compliance report in Tenable Cloud Security.
SOC-2 automated compliance report in Tenable Cloud Security. Users can download specific in-product compliance reports that map security findings to key compliance requirements and key remediation advice.
Fuente de la imagen: Tenable Cloud Security.

Conclusión

Achieving compliance in the cloud starts with translating compliance guidelines to the reality of cloud architecture. Understanding which cloud assets you have, the types of vulnerabilities they’re susceptible to and how these are related to auditing guidelines is essential for enabling the ongoing compliance work of monitoring, reporting and fixing. Once you have mapped your environment, you can proceed to automated monitoring based on compliance or customized policies. Finally, you can generate an automated report that helps demonstrate your compliance to auditors. Tenable Cloud Security can help you do all of this to reduce compliance hurdles and help you learn to love security audits.

For more information on Tenable Cloud Security or request a demo, please visit the Tenable Cloud Security product page: https://www.tenable.com/products/tenable-cloud-security

Artículos relacionados

Noticias de ciberseguridad que le son útiles

Ingrese su correo electrónico y nunca se pierda alertas oportunas y orientación en seguridad de los expertos de Tenable.

Tenable Vulnerability Management

Disfrute el acceso completo a una plataforma moderna para la gestión de vulnerabilidades en la nube, que le permite ver y rastrear todos sus activos con una precisión inigualable.

Su prueba de Tenable Vulnerability Management también incluye Tenable Lumin y Tenable Web App Scanning.

Tenable Vulnerability Management

Disfrute el acceso completo a una plataforma moderna para la gestión de vulnerabilidades en la nube, que le permite ver y rastrear todos sus activos con una precisión inigualable. Compre una suscripción anual hoy mismo.

100 activos

Seleccione su tipo de suscripción:

Comprar ahora

Tenable Vulnerability Management

Disfrute el acceso completo a una plataforma moderna para la gestión de vulnerabilidades en la nube, que le permite ver y rastrear todos sus activos con una precisión inigualable.

Su prueba de Tenable Vulnerability Management también incluye Tenable Lumin y Tenable Web App Scanning.

Tenable Vulnerability Management

Disfrute el acceso completo a una plataforma moderna para la gestión de vulnerabilidades en la nube, que le permite ver y rastrear todos sus activos con una precisión inigualable. Compre una suscripción anual hoy mismo.

100 activos

Seleccione su tipo de suscripción:

Comprar ahora

Tenable Vulnerability Management

Disfrute el acceso completo a una plataforma moderna para la gestión de vulnerabilidades en la nube, que le permite ver y rastrear todos sus activos con una precisión inigualable.

Su prueba de Tenable Vulnerability Management también incluye Tenable Lumin y Tenable Web App Scanning.

Tenable Vulnerability Management

Disfrute el acceso completo a una plataforma moderna para la gestión de vulnerabilidades en la nube, que le permite ver y rastrear todos sus activos con una precisión inigualable. Compre una suscripción anual hoy mismo.

100 activos

Seleccione su tipo de suscripción:

Comprar ahora

Probar Tenable Web App Scanning

Disfrute de acceso completo a nuestra última oferta de escaneo de aplicaciones web diseñada para aplicaciones modernas como parte de la plataforma Tenable One Exposure Management. Escanee de manera segura todo su portafolio en línea para detectar vulnerabilidades con alto grado de exactitud sin el esfuerzo manual intensivo ni la interrupción de aplicaciones web críticas. Registrarse ahora.

Su prueba de Tenable Web App Scanning también incluye Tenable Vulnerability Management y Tenable Lumin.

Comprar Tenable Web App Scanning

Disfrute el acceso completo a una plataforma moderna para la gestión de vulnerabilidades en la nube, que le permite ver y rastrear todos sus activos con una precisión inigualable. Compre una suscripción anual hoy mismo.

5 FQDN

USD 3578

Comprar ahora

Probar Tenable Lumin

Visualice y explore su gestión de exposición, realice un seguimiento de la reducción de riesgos a lo largo del tiempo y compárese con sus competidores con Tenable Lumin.

Su prueba de Tenable Lumin también incluye Tenable Vulnerability Management y Tenable Web App Scanning.

Comprar ahora Tenable Lumin

Póngase en contacto con un representante de ventas para saber cómo puede ayudarle Tenable Lumin a obtener información de toda su organización y gestionar el riesgo cibernético.

Probar Tenable Nessus Professional gratuitamente

GRATIS POR 7 DÍAS

Tenable Nessus es el escáner de vulnerabilidades más completo en el mercado hoy en día.

NUEVO - Tenable Nessus Expert
Ahora disponible

Nessus Expert viene con aún más funcionalidades, incluyendo escaneo de superficie de ataque externa y la capacidad de agregar dominios y escanear infraestructura en la nube. Haga clic aquí para probar Nessus Expert.

Rellene el formulario a continuación para continuar con la prueba de Nessus Pro.

Comprar Tenable Nessus Professional

Tenable Nessus es el escáner de vulnerabilidades más completo en el mercado hoy en día. Tenable Nessus Professional ayudará a automatizar el proceso de escaneo de vulnerabilidades, ahorrará tiempo en sus ciclos de cumplimiento y le permitirá involucrar a su equipo de TI.

Compre una licencia multi anual y ahorre. Agregue Soporte Avanzado para acceder a soporte por teléfono, chat y a través de la Comunidad las 24 horas del día, los 365 días del año.

Seleccione su licencia

Compre una licencia multi anual y ahorre.

Añada soporte y capacitación

Probar Tenable Nessus Expert gratuitamente

GRATIS POR 7 DÍAS

Diseñado para la superficie de ataque moderna, Nessus Expert le permite ver más y proteger a su organización contra las vulnerabilidades, desde TI hasta la nube.

¿Ya tiene Tenable Nessus Professional?
Actualice a Nessus Expert gratuitamente por 7 días.

Comprar Tenable Nessus Expert

Diseñado para la superficie de ataque moderna, Nessus Expert le permite ver más y proteger a su organización contra las vulnerabilidades, desde TI hasta la nube.

Seleccione su licencia

Compre una licencia plurianual y ahorre más.

Añada soporte y capacitación