Cloud-Native Application Protection Platform

Also known as:CNAPP

Cloud-Native Application Protection Platform: Integrated platform for securing cloud applications across development and operations. ImplementationImplementationThe practical realization of a security design, requirement, or control in a system or process. should consider architecture, permissions, hardening, monitoringMonitoringThe continuous observation of systems, identities, networks, and controls for relevant changes., dependencies, and operational recoveryRecoveryThe controlled restoration of systems, data, and business services after a disruption. in a holistic manner.

How it works and where it fits

Cloud-Native Application Protection Platform denotes a technical component or operating environment with its own trust boundaries, identities, interfaces, and dependencies. Security is determined not only by the product, but by architecture, configuration, and the way data and privileges cross component boundaries. Management planes and production processing should be considered separately.

Practical security relevance

Secure operation depends on complete inventory, hardened baselines, least privilege, patchability, and centralized telemetry. Changes should be reproducible and reviewable. Exposed interfaces, default access, secrets, and supply-chain dependencies need particular attention; isolation, backup, and recovery must also be exercised in realistic conditions.

  • Cloud Security Posture ManagementCloud Security Posture ManagementDetects misconfigurations and compliance deviations in cloud environments.: Detects misconfigurations and compliance deviations in cloud environments.
  • Application SecurityApplication SecurityProtects software against vulnerabilities during development, operation, and maintenance.: Protects software against vulnerabilities during development, operation, and maintenance.
  • Shared Responsibility ModelShared Responsibility ModelDivision of security tasks between the cloud provider and the customer.: Division of security tasks between the cloud provider and the customer.
  • Security TestingSecurity TestingExamines systems, applications, and controls for weaknesses and malfunctions.: Examines systems, applications, and controls for weaknesses and malfunctions.