The party responsible for Platform Security in a Platform-as-a-Service PaaS model.
Shared
Infrastructure-as-Code (IaC) templates may be secure, but manual modifications or misconfigured cloud-native services in runtime result in dangerous security gaps, defines
Configuration Drift
Examines if given function, feature, or behavior of an application or code performed as intended.
Functional Testing
A Layer 7 proxy that filters and monitors HTTP/HTTPS traffic.
Web Application Firewall (WAF)
Delegates user authentication to a trusted external provider, eliminating the need to store credentials within your application.
Federated Identity
A tool that scans third-party open-source libraries for known common vulnerabilities and exposures (CVE).
Software Composition Analysis (SCA)
Implement mutual TLS (mTLS) between microservices and restrict lateral movement so that a compromise of one node does not expose the entire application.
Zero-Trust Architecture
Looks at how well a function, feature, or behavior of an application or code performs in its process.
Non-functional testing
A vital supplementary security component. It captures, analyzes, and records all SQL transactions and data plane interactions in real time, independently of native database logging.
Database Activity Monitoring (DAM)
Acts as the central digital gatekeeper in a cloud IAM framework, securely storing credentials and verifying user identities.
Identity Provider (IdP)
A process that ensures cloud configuration files do not introduce security misconfigurations prior to deployment.
Infrastructure as Code (IaC) scanning
Sensitive API keys or cloud credentials accidentally committed to source code or config files create immediate backdoors.
Hardcoded Secrets
A foundational execution method used to validate and assure that a cloud application meets its security objectives from an external perspective.
Black-box testing
Specialized, application-layer proxies designed to protect XML-based services from specific threats like parser-level DoS, coercive parsing, and malicious injections.
XML firewalls
The cornerstone of cloud application security, allowing users to log in just once using centralized credentials to access multiple services.
Single Sign-On (SSO)
Users may purchase cloud service offerings without IT input
Shadow IT
A structured process of identifying assets, defining trust boundaries, and mapping data flows before code is written to anticipate and mitigate attack vectors.
Threat Modeling
It examines the internal source code, architecture, and logic of a cloud application.
White box testing
Application's primary front-door, serving as a reverse proxy that intercepts client requests and securely routes them to backend microservices.
API gateway
It mandates multiple verification factors, rendering stolen passwords useless without the secondary factor (e.g., a hardware token or authenticator app).
Multi-Factor Authentication (MFA)
A concept to train developers to identify and fix flaws in the code and architectural design phases, where patching carries near-zero production performance impact.
Shift Security Left
The implementation phase of the Secure Software Development Life Cycle (SDLC) where developers actively translate secure architecture into hardened code.
Secure Coding
It automates the inventory and validation of third-party and open-source libraries within your cloud applications.
Software Composition Analysis (SCA)
Acts as the primary traffic distributor. It enforces SSL/TLS termination, offloads authentication, and integrates with Web Application Firewalls (WAF) to secure traffic before it reaches your backend components.
Application Load Balancer (ALB)
Acts as a critical gatekeeper between users and cloud services.
Cloud Access Security Broker (CASB)