CloudSec Academy

Welcome to CloudSec Academy, your guide to navigating the alphabet soup of cloud security acronyms and industry jargon. Cut through the noise with clear, concise, and expertly crafted content covering fundamentals to best practices.

What is CVE scanning?

Wiz Experts Team

CVE scanning is the automated process of checking your software, systems, and networks against a database of known security flaws to identify vulnerabilities before attackers can exploit them.

What is container image scanning?

Wiz Experts Team

Container image scanning is the automated process of analyzing container images for security vulnerabilities, misconfigurations, and compliance violations.

What is API scanning?

Wiz Experts Team

API scanning is the automated process of analyzing APIs to detect security vulnerabilities, misconfigurations, and logic flaws.

See Wiz in action

Wiz connects the dots across your cloud, from code to runtime.

For information about how Wiz handles your personal data, please see our Privacy Policy.

Wiz wand

What is internal vulnerability scanning?

Wiz Experts Team

Internal vulnerability scanning is the process of identifying security weaknesses within an organization’s internal network infrastructure.

AWS Budgets vs. Cost Explorer: Why you need both

Wiz Experts Team

This article will help you understand the benefits of using both tools together, along with a solution like Wiz to fill the cross-cloud visibility gap and optimize both costs and security.

How to Evaluate Wiz: Common FAQs

Wiz Experts Team

This FAQ is designed to help teams evaluate whether Wiz is the right cloud security solution for them by answering the most common technical, strategic, and logistical questions.

Attack surface discovery: From blind spots to visibility

Wiz Experts Team

Attack surface discovery (ASD) is the continuous, automated process of identifying and mapping every asset, connection, and service an attacker could target across your entire digital footprint (cloud, hybrid, and on-premises environments).

Container runtime scanning best practices

Wiz Experts Team

Runtime scanning answers a critical question: 'What is runtime security for containers?' It focuses on detecting live behaviors, active threats, and anomalies that only appear when containers execute under real production traffic.

Source code scanning best practices for cloud security

Wiz Experts Team

Source code scanning is automated analysis of your code, dependencies, and infrastructure definitions to find security issues before you deploy. This means a tool reads your code the way a careful reviewer would, but at high speed and at scale.

How to implement CI/CD security scanning: Best practices

Wiz Experts Team

CI/CD security scanning is the practice of adding automated security checks into your build and deployment pipelines. This means every meaningful code change is tested for risk before it can reach production.