Academia CloudSec

Bem-vindo à CloudSec Academy, seu guia para navegar pela sopa de letrinhas dos acrônimos de segurança em nuvem e jargão do setor. Livre-se das distrações com conteúdo claro, conciso e habilmente elaborado, cobrindo os fundamentos para as melhores práticas.

What is Application Security testing?

Application security testing (AST) is a set of processes designed to detect and address security gaps during the early phases of the software development lifecycle (SDLC). In other words, teams take steps in pre-production to identify and mitigate risks before applications are released into operational environments.

Managed Cloud Security

Equipe de especialistas do Wiz

Managed cloud security helps organizations scale protection across cloud environments by outsourcing key operations like detection, response, and compliance monitoring.

Assista à demonstração de 12 minutos

Veja como a Wiz transforma a visibilidade instantânea em uma remediação rápida.

Para obter informações sobre como a Wiz lida com seus dados pessoais, consulte nosso Política de Privacidade.

Wiz starWiz starWiz starWiz star

O que é SSPM? (Gerenciamento de postura de segurança SaaS)

O gerenciamento de postura de segurança SaaS (SSPM) é um conjunto de ferramentas projetado para proteger aplicativos SaaS identificando configurações incorretas, gerenciando permissões e garantindo a conformidade regulatória em todo o patrimônio digital da sua organização.

What is Data Risk Management?

Data risk management involves detecting, assessing, and remediating critical risks associated with data. We're talking about risks like exposure, misconfigurations, leakage, and a general lack of visibility.

What are Application Security Frameworks?

Equipe de especialistas do Wiz

Application security frameworks are essential guidelines, best practices, and tools designed to help organizations stay consistent in their security practices, meet compliance requirements, and effectively manage risks associated with application security.

How to implement CI/CD security scanning: Best practices

Equipe de especialistas do Wiz

CI/CD security scanning is the practice of adding automated security checks into your build and deployment pipelines. This means every meaningful code change is tested for risk before it can reach production.

The top 11 open-source Kubernetes security tools

It’s a good idea to consider a range of Kubernetes security tools. Open source solutions can greatly improve the security of your Kubernetes clusters, so this section explores the top 11 open-source Kubernetes security tools that can help to safeguard your Kubernetes environment.

MTTD and MTTR in Cybersecurity Incident Response

Most incident response teams measure both MTTD and MTTR to not only shorten attackers’ dwell times in their systems but also to gauge the team’s readiness to combat future security incidents and then optimize response times.

Black-box testing explained for security teams

Equipe de especialistas do Wiz

Black-box security testing shows what your cloud environment actually exposes to the internet, helping teams focus on reachable and exploitable risk rather than theoretical weaknesses.

Cloud penetration testing: A practical guide

Equipe de especialistas do Wiz

Cloud penetration testing is primarily about identities, permissions, trust relationships, and exposed services; it’s not just IP ranges and open ports.

External penetration testing: A practitioner's guide

Equipe de especialistas do Wiz

External penetration testing assesses the exploitability of public-facing assets. It doesn’t just determine whether vulnerabilities exist; it also indicates whether attackers can actually reach and leverage them.