CloudSec Academy

Bienvenido a CloudSec Academy, tu guía para navegar por la sopa de alfabeto de los acrónimos de seguridad en la nube y la jerga de la industria. Cortar el ruido con contenido claro, conciso y elaborado por expertos que cubra los fundamentos de las mejores prácticas.

What is Application Security testing?

Application security testing (AST) is a set of processes designed to detect and address security gaps during the early phases of the software development lifecycle (SDLC). In other words, teams take steps in pre-production to identify and mitigate risks before applications are released into operational environments.

Managed Cloud Security

Equipo de expertos de Wiz

Managed cloud security helps organizations scale protection across cloud environments by outsourcing key operations like detection, response, and compliance monitoring.

Problemas de Seguridad en la Nube: 17 Riesgos, Amenazas y Desafíos

Equipo de expertos de Wiz

Descubra los principales problemas de seguridad en la nube que afectan a las organizaciones en la actualidad. Aprenda a abordar los riesgos, las amenazas y los desafíos de seguridad en la nube para proteger su entorno en la nube.

Ver demostración de 12 minutos

Mira cómo Wiz convierte la visibilidad instantánea en una remediación rápida.

Para obtener información sobre cómo Wiz maneja sus datos personales, consulte nuestra Política de privacidad.

Wiz starWiz starWiz starWiz star

¿Qué es SSPM? (Gestión de la postura de seguridad de SaaS)

La gestión de la postura de seguridad de SaaS (SSPM) es un conjunto de herramientas diseñado para proteger las aplicaciones de SaaS mediante la identificación de configuraciones incorrectas, la administración de permisos y la garantía del cumplimiento normativo en todo el patrimonio digital de su organización.

What is Data Risk Management?

Data risk management involves detecting, assessing, and remediating critical risks associated with data. We're talking about risks like exposure, misconfigurations, leakage, and a general lack of visibility.

What are Application Security Frameworks?

Equipo de expertos de Wiz

Application security frameworks are essential guidelines, best practices, and tools designed to help organizations stay consistent in their security practices, meet compliance requirements, and effectively manage risks associated with application security.

How to implement CI/CD security scanning: Best practices

Equipo de expertos de Wiz

CI/CD security scanning is the practice of adding automated security checks into your build and deployment pipelines. This means every meaningful code change is tested for risk before it can reach production.

The top 11 open-source Kubernetes security tools

It’s a good idea to consider a range of Kubernetes security tools. Open source solutions can greatly improve the security of your Kubernetes clusters, so this section explores the top 11 open-source Kubernetes security tools that can help to safeguard your Kubernetes environment.

MTTD and MTTR in Cybersecurity Incident Response

Most incident response teams measure both MTTD and MTTR to not only shorten attackers’ dwell times in their systems but also to gauge the team’s readiness to combat future security incidents and then optimize response times.

Black-box testing explained for security teams

Equipo de expertos de Wiz

Black-box security testing shows what your cloud environment actually exposes to the internet, helping teams focus on reachable and exploitable risk rather than theoretical weaknesses.

Cloud penetration testing: A practical guide

Equipo de expertos de Wiz

Cloud penetration testing is primarily about identities, permissions, trust relationships, and exposed services; it’s not just IP ranges and open ports.

External penetration testing: A practitioner's guide

Equipo de expertos de Wiz

External penetration testing assesses the exploitability of public-facing assets. It doesn’t just determine whether vulnerabilities exist; it also indicates whether attackers can actually reach and leverage them.