BOSTON & TEL AVIV, Israel--(BUSINESS WIRE)--Ermetic, the cloud infrastructure security company, today announced its Cloud Native Application Protection Platform (CNAPP) now provides automated capabilities that enable customers to discover and fix misconfigurations, compliance violations, and risky or excessive privileges in Kubernetes clusters. Unlike traditional Kubernetes security tools, Ermetic combines signals from the platform’s cloud workload protection (CWP), infrastructure as code (IaC) scanning, cloud security posture management (CSPM) and cloud infrastructure entitlement management (CIEM) functionality to provide full context visibility into threats.
Kubernetes' powerful facilities for deploying and managing containerized applications across multiclouds introduce complex security challenges including cluster configuration and vulnerability management, network security, role-based access control (RBAC), secrets management and runtime security. The Ermetic CNAPP provides a detailed inventory of the resources inside all Kubernetes clusters, performs continuous posture assessment and prioritization of risks, and offers guided how-tos and workflow integrations to accelerate remediation.
“Existing approaches to Kubernetes security typically provide a siloed view, which results in high false positive rates,” said Sivan Krigsman, Chief Product Officer for Ermetic. “By combining Kubernetes security posture management with our full stack cloud native application protection capabilities we provide unprecedented visibility and context, for accurate risk prioritization and remediation.”
Comprehensive Visibility and Control
To provide full and accurate visibility into Kubernetes resources, Ermetic queries the Kubernetes API for each cluster, and uses agentless scanning and analysis of node configurations and containers. These findings, when coupled with intelligence from Ermetic’s CWP, IaC scans, CSPM and CIEM capabilities, enables customers to:
- Get a detailed inventory of Kubernetes resources within clusters
- Detect misconfigurations and vulnerabilities, and access detailed, step-by-step remediation instructions
- Prioritize workload vulnerabilities within the context of cloud configuration, permissions, network access, and more
- Enforce least privilege for users and services using the internal Kubernetes role based access control (RBAC) mechanism
- Assess and enforce compliance standards for Kubernetes clusters such as CIS benchmarks
The new Kubernetes security posture management (KSPM) capabilities are available immediately in the Ermetic CNAPP, from Ermetic and its business partners worldwide.
Ermetic reveals and prioritizes security gaps in AWS, Azure and GCP and enables organizations to remediate them immediately. The Ermetic cloud native application protection platform (CNAPP) uses an identity-first approach to unify and automate cloud infrastructure entitlement management (CIEM), cloud security posture management (CSPM), cloud workload protection and Kubernetes security posture management (KSPM). It unifies full asset discovery, deep risk analysis, runtime threat detection and compliance reporting, combined with pinpoint visualization and step-by-step guidance. The company is led by proven technology entrepreneurs whose previous companies have been acquired by Microsoft, Palo Alto Networks and others. Ermetic has received funding from Accel, Forgepoint, Glilot Capital Partners, Norwest Venture Partners, Qumra Capital and Target Global. Visit us at https://ermetic.com/ and follow us on LinkedIn, Twitter and Facebook.