Ory is a world renowned expert in cloud & application security with more than 20 years of experience. He is an entrepreneur and a business technology leader. He specializes with more than 20 years of experience in Web application, Cloud and network Security. He is leading teams of security researchers and developing innovative security solutions.
Palo Alto Networks Prisma Cloud CTO says that when software development meets continuous integration and development, security must be efficient and holistic.
Different companies get to the point where they can be considered CNAPPs based on their journey. Some started from container security, like Twistlock (acquired by Palo Alto Networks) or Aqua security, for example. Some arrived … from cloud security posture management. So it really depends on who you ask. But I like Gartner’s point of view: The emphasis is on holistic cloud native security, so it’s not about “cloud security,” “workload security” or “code security.” It’s about providing a platform that allows you to apply the right types of security controls throughout the development lifecycle, from the moment you start coding to the point in time when you are deployed and monitoring the workloads. And under that fall many, many different categories of products, not all of which would be directly thought of as a part of CNAPP.