Welcome!

@CloudExpo Authors: Jason Bloomberg, Elizabeth White, Roger Strukhoff, Liz McMillan, Pat Romanski

Related Topics: @CloudExpo, Java IoT, Microservices Expo, IoT User Interface, Agile Computing, Cloud Security

@CloudExpo: Article

Security Posture Management Enters the Cloud

A “pure” cloud-based IT security monitoring and compliance management product

When eGestalt of Santa Clara, CA, announced in November they were launching a cloud-based security and compliance solution, it set the stage to change the way enterprise businesses could cope with complex compliance and security issues.

The solution, powered by Rapid7 scanning technology, was to deliver a "pure" cloud-based IT security monitoring and compliance management product that worked in real time without requiring any hardware, "a first of its kind solution," say the vendors.

Called Aegify, the technology delivers Security Posture Management (SPM), which first measures the security status of all assets within a network, then delivers a report that can be used to remediate problems, strengthen security, and create and manage compliance policies. It leverages the compliance and security engine of eGestalt's SecureGRC (governance, risk management and compliance) product with Rapid7's Nexpose vulnerability management technology.

Aegify uses a patent-pending expert systems technology from eGestalt to automatically map the security vulnerabilities to compliance mandates, thereby automating the task of security posture management and compliance management, which is manually done today. The tool can import data from other standard vulnerability scanners in the industry as well.

The advantage of using a cloud-based solution to perform this type of sophisticated network diagnoses is a vast reduction in complexity and time, said Anupam Sahai, President of eGestalt.

"Currently, you do this with on-site hardware," Sahai explained. "You run a scan and get a report. Then the IT person has to study it and perform the needed remediation. That takes time, and then once this is performed the network settings change" and you can fall back out of compliance and into a weakened security state all over again.

With a cloud-based solution like Aegify, scanning and remediation can be run in perpetuity, and IT administrators can "see results on the fly," said Sahai. The cloud solution does the work, and you get SPM and/or the compliance posture in real time, or you can schedule it.

"You don't need specialized IT resources to understand and interpret the results or have to deal with remediation," Sahai explained.

The combined solution from eGestalt and Rapid7 performs a massive amount of work, combining asset discovery with vulnerability analysis and compliance mandates. This gives even the largest company an easy way to identify exactly what they have operating in their network, check the level of their exposure to a potential threat, and make any adjustments that have them falling out of compliance. It can identify 28,000 vulnerabilities and perform over 85,000 checks across physical and virtual networks.

"It's a completely multi-tenant solution," said Sahai, who adds that the cloud-based approach and the integration of the security, compliance, and scanning system in Aegify solves the cumbersome, time consuming and inefficient method of approaching the task with separate, siloed applications that don't communicate well with one another.

Aegify will be marketed to the customer and partner bases of both eGestalt and Rapid7. Sheldon Malm, senior director of Strategic Partners and Alliances at Rapid7, said the alliance creates "a very complementary offering that will benefit our joint customers."

On the compliance side, Aegify covers practically every industry that falls under compliance regulations. The cloud solution can control and manage compliance across more than 400 regulations, from the commonly known ones such as PCI, HIPAA/HITECH, SOX, FISMA, and GLBA, to compliance rules from other countries outside the U.S.

An added advantage of Aegify being a cloud solution is that an IT reseller or consultant can manage it remotely for customers and present the reporting wrapped with upsell and cross-sell offerings. And Aegify can be white-labeled with a reseller's or consultant's own branding, said Sahai.

Public cloud services like Aegify are predicted to grow five times faster than traditional on-premise IT, at a growth rate of 19 percent through 2015, according to a study by MarketBridge. The reason for this growth is multi-faceted. The simplicity that cloud computing offers by moving the complexity away from the customer also means customers no longer have to maintain upgrades or version enhancements. The capital expense of purchasing additional server or storage capacity is also greatly reduced with a cloud-based service.

Still, traditional legacy IT networks dominate the computing landscape, which is why Aegify is such an effective solution for reaching out to these networks and keeping them secure and in compliance. In a press release, Bryan Britz, a research director at Gartner, said a mixture of cloud solutions and traditional networks "will permeate most organizations in the coming years."

Sahai of eGestalt agrees and pointed out that a residual effect of Aegify is helping preserve the investment a company has in its traditional IT network.

"Many customers claim they have no security or compliance issues," Sahai said, adding that this makes Aegify community edition, a free tool downloadable from the web (www.egestalt.com), a conversation starter with customers - a conversation that can lead to the purchase of traditional network equipment, or more cloud services.

"We are solving a number of problems by making networks cheaper, better, and more effective by delivering it to the cloud," he said.

More Stories By Dan Neel

Dan Neel is an award-winning journalist who has covered technology trends and best practices for over 15 years working with leading technology publications like Infoworld, CRN, VARbusiness and Investment Management Weekly. He led the direction of technology channel content at United Business Media, and is the recipient of 9 industry awards, including Best News Story for 2000 from the American Society of Business Press Editors.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@CloudExpo Stories
Internet-of-Things discussions can end up either going down the consumer gadget rabbit hole or focused on the sort of data logging that industrial manufacturers have been doing forever. However, in fact, companies today are already using IoT data both to optimize their operational technology and to improve the experience of customer interactions in novel ways. In his session at @ThingsExpo, Gordon Haff, Red Hat Technology Evangelist, will share examples from a wide range of industries – includin...
Organizations planning enterprise data center consolidation and modernization projects are faced with a challenging, costly reality. Requirements to deploy modern, cloud-native applications simultaneously with traditional client/server applications are almost impossible to achieve with hardware-centric enterprise infrastructure. Compute and network infrastructure are fast moving down a software-defined path, but storage has been a laggard. Until now.
We're entering the post-smartphone era, where wearable gadgets from watches and fitness bands to glasses and health aids will power the next technological revolution. With mass adoption of wearable devices comes a new data ecosystem that must be protected. Wearables open new pathways that facilitate the tracking, sharing and storing of consumers’ personal health, location and daily activity data. Consumers have some idea of the data these devices capture, but most don’t realize how revealing and...
Unless your company can spend a lot of money on new technology, re-engineering your environment and hiring a comprehensive cybersecurity team, you will most likely move to the cloud or seek external service partnerships. In his session at 18th Cloud Expo, Darren Guccione, CEO of Keeper Security, revealed what you need to know when it comes to encryption in the cloud.
"We build IoT infrastructure products - when you have to integrate different devices, different systems and cloud you have to build an application to do that but we eliminate the need to build an application. Our products can integrate any device, any system, any cloud regardless of protocol," explained Peter Jung, Chief Product Officer at Pulzze Systems, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
"We are an all-flash array storage provider but our focus has been on VM-aware storage specifically for virtualized applications," stated Dhiraj Sehgal of Tintri in this SYS-CON.tv interview at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
It's easy to assume that your app will run on a fast and reliable network. The reality for your app's users, though, is often a slow, unreliable network with spotty coverage. What happens when the network doesn't work, or when the device is in airplane mode? You get unhappy, frustrated users. An offline-first app is an app that works, without error, when there is no network connection. In his session at 18th Cloud Expo, Bradley Holt, a Developer Advocate with IBM Cloud Data Services, discussed...
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at 20th Cloud Expo, Ed Featherston, director/senior enterprise architect at Collaborative Consulting, will discuss the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
Between 2005 and 2020, data volumes will grow by a factor of 300 – enough data to stack CDs from the earth to the moon 162 times. This has come to be known as the ‘big data’ phenomenon. Unfortunately, traditional approaches to handling, storing and analyzing data aren’t adequate at this scale: they’re too costly, slow and physically cumbersome to keep up. Fortunately, in response a new breed of technology has emerged that is cheaper, faster and more scalable. Yet, in meeting these new needs they...
In addition to all the benefits, IoT is also bringing new kind of customer experience challenges - cars that unlock themselves, thermostats turning houses into saunas and baby video monitors broadcasting over the internet. This list can only increase because while IoT services should be intuitive and simple to use, the delivery ecosystem is a myriad of potential problems as IoT explodes complexity. So finding a performance issue is like finding the proverbial needle in the haystack.
When it comes to cloud computing, the ability to turn massive amounts of compute cores on and off on demand sounds attractive to IT staff, who need to manage peaks and valleys in user activity. With cloud bursting, the majority of the data can stay on premises while tapping into compute from public cloud providers, reducing risk and minimizing need to move large files. In his session at 18th Cloud Expo, Scott Jeschonek, Director of Product Management at Avere Systems, discussed the IT and busin...
According to Forrester Research, every business will become either a digital predator or digital prey by 2020. To avoid demise, organizations must rapidly create new sources of value in their end-to-end customer experiences. True digital predators also must break down information and process silos and extend digital transformation initiatives to empower employees with the digital resources needed to win, serve, and retain customers.
"We are the public cloud providers. We are currently providing 50% of the resources they need for doing e-commerce business in China and we are hosting about 60% of mobile gaming in China," explained Yi Zheng, CPO and VP of Engineering at CDS Global Cloud, in this SYS-CON.tv interview at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
"Once customers get a year into their IoT deployments, they start to realize that they may have been shortsighted in the ways they built out their deployment and the key thing I see a lot of people looking at is - how can I take equipment data, pull it back in an IoT solution and show it in a dashboard," stated Dave McCarthy, Director of Products at Bsquare Corporation, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
@DevOpsSummit taking place June 6-8, 2017 at Javits Center, New York City, is co-located with the 20th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. @DevOpsSummit at Cloud Expo New York Call for Papers is now open.
Predictive analytics tools monitor, report, and troubleshoot in order to make proactive decisions about the health, performance, and utilization of storage. Most enterprises combine cloud and on-premise storage, resulting in blended environments of physical, virtual, cloud, and other platforms, which justifies more sophisticated storage analytics. In his session at 18th Cloud Expo, Peter McCallum, Vice President of Datacenter Solutions at FalconStor, discussed using predictive analytics to mon...
Today we can collect lots and lots of performance data. We build beautiful dashboards and even have fancy query languages to access and transform the data. Still performance data is a secret language only a couple of people understand. The more business becomes digital the more stakeholders are interested in this data including how it relates to business. Some of these people have never used a monitoring tool before. They have a question on their mind like “How is my application doing” but no id...
@GonzalezCarmen has been ranked the Number One Influencer and @ThingsExpo has been named the Number One Brand in the “M2M 2016: Top 100 Influencers and Brands” by Onalytica. Onalytica analyzed tweets over the last 6 months mentioning the keywords M2M OR “Machine to Machine.” They then identified the top 100 most influential brands and individuals leading the discussion on Twitter.
As data explodes in quantity, importance and from new sources, the need for managing and protecting data residing across physical, virtual, and cloud environments grow with it. Managing data includes protecting it, indexing and classifying it for true, long-term management, compliance and E-Discovery. Commvault can ensure this with a single pane of glass solution – whether in a private cloud, a Service Provider delivered public cloud or a hybrid cloud environment – across the heterogeneous enter...
In IT, we sometimes coin terms for things before we know exactly what they are and how they’ll be used. The resulting terms may capture a common set of aspirations and goals – as “cloud” did broadly for on-demand, self-service, and flexible computing. But such a term can also lump together diverse and even competing practices, technologies, and priorities to the point where important distinctions are glossed over and lost.