Learning Library

← Back to Library

CNAPP Explained: Integrated Cloud Security

Key Points

  • Cloud security challenges arise from fragmented, independent tools that make it difficult to manage threats, compliance, and the overall security landscape across an organization’s cloud and application lifecycle.
  • Gartner’s Cloud Native Application Protection Platform (CNAPP) unifies security and compliance capabilities into a tightly integrated solution designed to protect cloud‑native applications from development through production.
  • CNAPP’s core components include Cloud Security Posture Management (CSPM) for continuous monitoring and remediation of misconfigurations, Cloud Workload Protection Platform (CWPP) for detecting threats and vulnerabilities in containers, VMs, serverless functions, and other workloads, and Cloud Infrastructure Entitlement Management (CIEM) for governing identity and access.
  • By consolidating these functions, CNAPP enables organizations to streamline security tool management, maintain continuous compliance, and more effectively mitigate risks across all cloud workloads.

Full Transcript

# CNAPP Explained: Integrated Cloud Security **Source:** [https://www.youtube.com/watch?v=N6hRVM7fo0E](https://www.youtube.com/watch?v=N6hRVM7fo0E) **Duration:** 00:08:45 ## Summary - Cloud security challenges arise from fragmented, independent tools that make it difficult to manage threats, compliance, and the overall security landscape across an organization’s cloud and application lifecycle. - Gartner’s Cloud Native Application Protection Platform (CNAPP) unifies security and compliance capabilities into a tightly integrated solution designed to protect cloud‑native applications from development through production. - CNAPP’s core components include Cloud Security Posture Management (CSPM) for continuous monitoring and remediation of misconfigurations, Cloud Workload Protection Platform (CWPP) for detecting threats and vulnerabilities in containers, VMs, serverless functions, and other workloads, and Cloud Infrastructure Entitlement Management (CIEM) for governing identity and access. - By consolidating these functions, CNAPP enables organizations to streamline security tool management, maintain continuous compliance, and more effectively mitigate risks across all cloud workloads. ## Sections - [00:00:00](https://www.youtube.com/watch?v=N6hRVM7fo0E&t=0s) **Introducing the Cloud Native Application Protection Platform** - CNAPP is a unified, tightly integrated security and compliance framework that streamlines protection across the entire cloud‑native application lifecycle, addressing the challenges of fragmented tools and evolving threats. - [00:03:10](https://www.youtube.com/watch?v=N6hRVM7fo0E&t=190s) **Key CNAPP Components: CWPP & CIEM** - The excerpt outlines the essential capabilities of a Cloud-Native Application Protection Platform, highlighting continuous threat detection and vulnerability management for workloads (CWPP) and the oversight of identities, permissions, and excessive privileges across single and multi‑cloud environments (CIEM). - [00:06:23](https://www.youtube.com/watch?v=N6hRVM7fo0E&t=383s) **Unified CNAPP Automation Benefits** - The passage outlines how a CNAPP platform enables proactive risk identification, early detection across development and production, extensive pipeline automation, and consolidation of disparate security tools to reduce complexity and manual effort. ## Full Transcript
0:00Cloud security can be a complex area, 0:02and with security being top of mind for businesses and organizations, 0:06it becomes crucial when having to address and manage emerging security threats 0:12and risks that can occur in their cloud and application lifecycle. 0:19This becomes important in order to figure out 0:21what types of security solutions 0:23are going to help address those security risks and gaps. 0:26There are security solutions that are there today 0:30that can do what needs to be done 0:32to be able to manage these types of threats and risk. 0:35However, a lot of these types of solutions take an independent approach 0:40that can make it challenging overall 0:42in how to strategically manage and implement these types of security solutions 0:47throughout your application and workload life cycle. 0:51And overall with this bigger challenge, 0:53it is how do you manage the overall landscape of all your security tools, 0:58while also being able to strategically and continuously achieve 1:02your security compliance goals 1:04across your workloads and applications? 1:07In this video, we're going to talk about Cloud Native Application Protection Platform, 1:12also known as CNAPP. 1:17CNAPP was coined by Gartner 1:19as a unified and tightly integrated set of security compliance capabilities 1:24designed to secure and protect cloud native applications 1:28across development and production. 1:31So what does that mean for businesses and organizations 1:35that are looking to not only adopt, 1:38but even consider replacing 1:40their security and compliance strategies and approaches? 1:44Well, with the CNAPP platform, it consists of some critical 1:48and key common components that are available today. 1:52Some of those key components can be considered as CSPM, 1:58CWPP, 2:02and CIEMM. 2:09To start, CSPM is cloud security posture management. 2:15And with this type of security solution, 2:17it generally provides the ability to continuously monitor 2:22your cloud infrastructure environments and data, 2:26and be able to offer configuration management 2:29across these types of environments. 2:31And that can be done by proactively implementing and applying controls 2:36based on regulatory and security requirements 2:39that can help surface any misconfigurations in these type of environments, 2:44and be able to allow you to quickly assess your security and compliance state 2:49and any sort of security issues and compliance risks that may come up. 2:54The next key component of a CNAPP platform 2:57is CWPP, also known as Cloud Workload Protection Platform. 3:04This type of security solution 3:06is targeted on how can you protect your workloads. 3:10Workloads such as containers, hosts, 3:14virtual machines, serverless functions, and more. 3:19And the key capabilities that are generally provided 3:22in a CWPP solution consists of 3:25being able to detect threats continuously, 3:28and manage and surface vulnerabilities that may occur 3:33and be discovered across your workloads and applications. 3:37This becomes important when being able to 3:40not only address security risk upfront, 3:43but able to potentially remediate them as they are discovered. 3:49The next key component for CNAPP platform is CIEM. 3:55Also known as cloud identity entitlement management. 4:00This security solution is generally targeted at the process 4:04of how to not only manage your identities, 4:07but be able to manage the identities of a single and multi-cloud. 4:11This can consists of access rights, privileges and permissions. 4:18Now, not only is the management of identities important for your cloud environments, 4:22but being able to surface any unintentional 4:26and excessive permissions that can lead to threats 4:30and data breaches is what's going to be achieved 4:33when you adopt a CIEM security solution. 4:38Again, these are key common components of a CNAPP platform. 4:42However, there are more types of components that can be considered 4:47and tightly integrated in a CNAPP platform, 4:49which makes it a compelling type of security platform 4:53and strategy to adopt. 4:55Now, what are some of the benefits 4:57that businesses and organizations can consider 5:00as they are looking to either adopt a security approach for their cloud, 5:06or potentially displace and replace 5:09to be able to effectively meet their security and compliance goals, 5:13strategically and uniformly. 5:16A CNAPP platform can provide you centralized management. 5:21And not only centralized management of their overall postures, 5:26but be able to also centrally manage 5:29the different types of automation and monitoring results 5:33that can come up from the different types of security solutions 5:37that are applied and implemented into their workloads. 5:41So this means that you can centrally, you can have a centralized view 5:44of all of your types of results 5:46that can come up into a visible, unified form 5:50where you can essentially see how can you manage 5:53the security compliance overall 5:55and be able to understand where your posture is 5:58for your business and organization. 6:01This can also lead to the ability to have more insights 6:06and visibility into your cloud environments. 6:10So that way you can really understand 6:12where your workloads are and how are they doing 6:16against security requirements that either your organization sets, 6:20or that regulatory frameworks are requiring. 6:23And this becomes crucial as you not only proactively identify 6:27these types of security risks and threats, 6:29but be able to address them and prevent them in the future. 6:34And with that comes earlier detection 6:37of these types of threats and vulnerabilities 6:40to be able to effectively understand 6:42how can you not only address these 6:45types of threats and vulnerabilities in production, 6:48but from the development to production states. 6:50And this helps development and DevOps team 6:54be able to be more productive 6:56in the sense of how can they not only apply 6:59this level of automation that is available, 7:01but to be able to also detect these types of risks and issues 7:07earlier on in the pipeline process? 7:12And with that becomes again adding not only a level of automation, 7:17but being able to have extensive and cohesive automation 7:21that is supported throughout a CNAPP platform 7:24and throughout your security solutions 7:27that are tackling your individual 7:29areas that need to be focussed and addressed. 7:32And lastly, the biggest part of what a CNAPP platform 7:37can provide and address is what we talked about earlier, 7:40those challenges of how do you manage multiple security solutions 7:44that can be available today that you're already adopting today 7:49and being able to understand how can we reduce the overhead 7:52and complexity that is required to be able to 7:56manage and maintain these independent approaches, 7:59as well as how to reduce the level of overhead 8:03and manual effort that is required in order to be able to 8:07address your security and compliance posture. 8:10And these are going to be some of the key benefits to consider 8:14when looking at a CNAPP platform 8:16and considering how can you apply this strategically 8:19into your business and organization's 8:21security compliance structure. 8:24To learn more about CNAPP, you can select the link below 8:28and learn more through the KuppingerCole Leadership Compass report on CNAPP. 8:34If you liked this video and want to see more like it, 8:37please like and subscribe. 8:39If you have any questions or want to share your thoughts about this topic, 8:43please leave a comment below.