Set up cloud security
Elastic Security's cloud security features find risks in your cloud accounts and Kubernetes clusters. They check your configuration against security best practices, list your cloud assets, and scan your AWS EC2 Linux workloads for known vulnerabilities.
You set up each feature by adding its integration and connecting it to your cloud provider or cluster. After setup, each integration sends its results to Elastic Security, where you can review them in Cloud Security.
Each feature answers a different question about your cloud environment:
- Cloud Security Posture Management (CSPM): Checks the services in your AWS, GCP, and Azure accounts, such as storage, compute, and identity and access management (IAM), against benchmarks from the Center for Internet Security (CIS).
- Kubernetes Security Posture Management (KSPM): Checks the components of your Kubernetes clusters against CIS benchmarks.
-
Cloud Asset Discovery: Builds an inventory of the resources in your AWS, GCP, and Azure accounts. - Cloud Native Vulnerability Management (CNVM): Scans your AWS EC2 Linux workloads for known vulnerabilities.
| Your goal | Start here |
|---|---|
| Check your AWS, GCP, or Azure accounts for misconfigurations | CSPM for AWS, CSPM for GCP, or CSPM for Azure |
| Give users access to view or manage CSPM data | CSPM privilege requirements |
| Check your Kubernetes clusters for misconfigurations | Get started with KSPM |
|
|
Cloud Asset Discovery for AWS, Cloud Asset Discovery for GCP, or Cloud Asset Discovery for Azure |
| Scan your AWS EC2 Linux workloads for known vulnerabilities | Get started with CNVM → CNVM privilege requirements |
| Turn on cloud security features in a Serverless project | Enable cloud security features in Serverless |
After you set up cloud security, you can:
- Review findings, benchmarks, and vulnerabilities in Cloud Security.
- Monitor posture at a glance on the Cloud Security Posture dashboard.
- Manage cloud workload protection to detect and block threats on your Linux VMs and Kubernetes workloads at runtime.