Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

De la Théorie à la pratique





















Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

enable Integrates Terrascan Into Nessus to Enable Secure Cloud Application Delivery

May 2022 by Patrick LEBRETON

Added firepower helps security and DevOps teams ensure that only secure infrastructure and software are launched in the cloud

Tenable® announce Nessus® now includes Terrascan, the leading open-source cloud security analyzer that helps developers secure Infrastructure as Code (IaC). The integration into Nessus continues to further Tenable’s broader cloud strategy, helping enterprises secure their full cloud stacks both during build time and at runtime. The combined solution helps the Nessus user community address security operations and cloud application infrastructure.

Terrascan is an open-source IaC security analyzer that enables cloud developers to scan infrastructure code and find security issues as part of the software delivery process. With more than 500 out-of-the-box policies, it helps identify issues such as missing or misconfigured encryption on resources and communication, and inadvertent exposure of cloud services.

Terrascan enables cloud engineers to test infrastructure code against security policies early in the development process, when it’s least costly and disruptive to fix. It provides more confidence when “shifting left” and makes secure design an integral part of the DevOps process. As organizations move full steam ahead with their cloud, ‘as code’ and containerization projects, they increase their attack surface. Nessus with Terrascan lets them innovate and simultaneously address security concerns.

The benefits that Terrascan adds to Nessus include:

- Increased delivery speed – eliminates lengthy pre-production security gates by automating cloud-native security assessments early in the software development lifecycle.

- Reduced risk – helps Cloud DevOps teams avoid releasing insecure software into the cloud and reduces potential windows of risk.

- Rapid time to value – takes advantage of over 500 predefined, standards-based policies to test a broad range of IaC for alignment with security benchmarks.




See previous articles

    

See next articles