Enterprises looking for a network-based approach to identify advanced attacks that have bypassed perimeter security should consider NTA as a way to help identify, manage and triage these events.
Managed detection and response
Managed detection and response (MDR) providers deliver services for buyers looking to improve their threat detection, incident response and continuous-monitoring capabilities, but don't have the expertise or resources to do it on their own.
Demand from the small or midsize business (SMB) and small-enterprise space has been particularly strong, as MDR services hit a "sweet spot" with these organisations, due to their lack of investment in threat detection capabilities.
Once attackers have gained a foothold in enterprise systems, they typically can move unimpeded laterally ("east/west") to other systems.
Micro-segmentation is the process of implementing isolation and segmentation for security purposes within the virtual data centre. Like bulkheads in a submarine, microsegmentation helps to limit the damage from a breach when it occurs.
Micro-segmentation has been used to describe mostly the east-west or lateral communication between servers in the same tier or zone, but it has evolved to be used now for most of communication in virtual data centres.
A software-defined perimeter (SDP) defines a logical set of disparate, network-connected participants within a secure computing enclave.
The resources are typically hidden from public discovery, and access is restricted via a trust broker to the specified participants of the enclave, removing the assets from public visibility and reducing the surface area for attack.
Gartner predicts that through the end of 2017, at least 10 per cent of enterprise organisations will leverage software-defined perimeter (SDP) technology to isolate sensitive environments.
OSS security scanning and software composition analysis for DevSecOps
Information security architects must be able to automatically incorporate security controls without manual configuration throughout a DevSecOps cycle in a way that is as transparent as possible to DevOps teams and doesn't impede DevOps agility, but fulfils legal and regulatory compliance requirements as well as manages risk.
Security controls must be capable of automation within DevOps tool chains in order to enable this objective.
Software composition analysis (SCA) tools specifically analyse the source code, modules, frameworks and libraries that a developer is using to identify and inventory OSS components and to identify any known security vulnerabilities or licensing issues before the application is released into production.
Containers use a shared operating system (OS) model. An attack on a vulnerability in the host OS could lead to a compromise of all containers.
Containers are not inherently unsecure, but they are being deployed in an unsecure manner by developers, with little or no involvement from security teams and little guidance from security architects. Traditional network and host-based security solutions are blind to containers.
Container security solutions protect the entire life cycle of containers from creation into production and most of the container security solutions provide pre production scanning combined with runtime monitoring and protection.