Cloud Native Application Protection (ex Laceworks)

Technology : Public Cloud Security (AWS, Azure, GCP) FortiCloud Protection
Vendor : Fortinet
Product : CNAPP
SKU : INS-CPL01

FortiCNAPP centralizes the fragmented security tools & platforms used in todays cloud environments into a unified platform to simplify and strengthen cloud security re-enforcing greater security in Containers, APIs, development & runtime environment (CD/CI) as the well as the cloud infrastructure itself. FortiCNAPP compromised the main components of the generic CNAPP stack (CSPM. CWPP, CIEM, CDR, IaC & DSPM).

Service Description Extended


FortiCNAPP is a solutions that allows for complete centralized run-time protection of Cloud Native application from development through to runtime and the CD/CI chain. It protects APIs which are fundamental connectors in the cloud world. It Centralizes the security taking into consideration all the other security checks and tools which ofter remain siloed and fragmented and potentially managed by different teams which produce unseen risks. The key capabilities of FortiCNAPP includes CSPM (Cloud Security Posture Management) which continuously monitors cloud configurations, identifies any misconfigurations, and ensures compliance. FortiCNAPP also includes CWPP (Cloud Workload Protection Platform) to protect application containers and other workloads such as VMs, serverless functions using agent & agentless methods. It leverages agents for continuous, deep visibility into cloud workload runtime environments, while also offering. Additional compoenents of FortiCNAPP include CIEM (Cloud Insfrastructure entitlement management) for agentless based vulnerability scanning and entitlements as well as managing identities to prevent any unauthorized access. Another component of FortiCNAPP is IaC (Infrastructure as Code) scanning that will scan application code to identify security vulnerabilities and any misconfigurations. The platform also offers DSPM (Data Security Posture Management) to give SoC operators visibilitiy into data locations, usage and classification to prevent data breaches. Finally FortiCNAPP offers CDR (Cloud Detection & Response) for threat detection & response across the cloud through the backbone of the FortiGuard labs

Deliverables

  • Design & Documentation:
  •   High Level Design (HLD)
  •   Low Level Design (LLD)
  •   Functional Test Plan
  •   As Built Doc

  • Deployment & Testing:
  •  Platform deployment & integration
  •  Configuration of platforms
  •  Running functional test plan

  • Optional Modules:
  • Cloud Security Posture Assessment Report: This would detail the current state of the cloud environments security, identifying vulnerabilities, misconfigurations, and compliance gaps
  • Cloud Security Compliance Report: TGeneration of reports demonstrating compliance against various frameworks (HIPAA, PCI DSS, NIST, ISO 27001, SOC2, CIS)
  • Prioritized Remediation Plan: Based on the assessment, this plan would outline the top security issues, their risk levels, and a recommended order for addressing them
  • Cloud Architectural Recommendations: Analysis on how to adjust the cloud architecture to improve security based on FortiCNAPP`s findings.
  • Integration with CI/CD Pipelines: Integration of FortiCNAPP into your development pipelines.
  • Knowledge Transfer Workshops: Customized Training sessions focused on the solution to effectively manage and operate their Fortinet security environment and SecOps processes.

Related Content

X

We are here to help

Schedule a Meeting

+44 (0) 20 7131 0263
CONTACT
US