A sanitized portfolio case study exploring how Wiz CNAPP can help security teams discover, correlate and prioritize cloud risks across AWS, Microsoft Azure and Google Cloud.
This reference architecture is independently created to demonstrate cloud-security concepts and Wiz CNAPP workflows. It contains no client information, employer architecture, proprietary code, account details or confidential security findings.
Imagine an enterprise operating dozens of AWS accounts, Microsoft Azure subscriptions and Google Cloud projects. Thousands of cloud resources are continuously created, modified and removed by different engineering teams.
Security teams need visibility into questions such as:
Wiz is a Cloud Native Application Protection Platform (CNAPP) that provides security visibility across cloud environments.
Instead of looking at vulnerabilities, identities, configurations and exposure completely independently, contextual cloud-security analysis can help security teams understand how multiple risks may combine into a more significant attack path.
Cloud configuration and security posture visibility.
Cloud identity, permissions and entitlement risk.
Workload and software vulnerability visibility.
Understanding combinations of risks and exposure.
The following simplified architecture represents a fictional enterprise connecting multiple cloud environments to a centralized cloud-security platform.
ENTERPRISE CLOUD
AWS AZURE GCP
│ │ │
Organizations Subscriptions Projects
│ │ │
EC2 • S3 • IAM VM • Storage GCE • GCS
EKS • RDS AKS • SQL GKE • SQL
│ │ │
└─────────────────┼──────────────────┘
│
▼
WIZ CNAPP
│
┌──────────────────┼──────────────────┐
▼ ▼ ▼
CSPM CIEM Vulnerabilities
│ │ │
└──────────────────┼──────────────────┘
▼
Security Context
│
▼
Attack Path Analysis
│
▼
Risk Prioritization
│
▼
Remediation
A vulnerability by itself may not always represent the organization's highest-priority risk. Context changes the security picture.
Consider this fictional scenario:
Looking at these findings independently may create four separate alerts. Looking at them together reveals a potential path from internet exposure to sensitive data. This context helps security teams prioritize remediation.
This case study will be expanded with detailed sections covering cloud onboarding, CSPM findings, IAM/CIEM analysis, vulnerability investigation, Kubernetes security, compliance and remediation workflows.