WTF is ASPM?
Application Security Posture Management (ASPM) is the latest Gartner fueled buzzword to take over cybersecurity, but no one knows exactly what it is. On the one hand, it’s a fancy name for vulnerability management: helping ingest and prioritize vulnerabilities from third party tools. On the other hand, it’s a one stop shop for code scanning. In this article I argue that the only meaningful ASPM is an all in one application security scanning tool. Why would you want an ASPM? Why Disagree with Gartner? CSPM and ASPM, towards an SPM Defining The Perfect ASPM Defining the Minimum ASPM Some Examples Musings About the Future DevSecOps is the only way to ship products quickly while staying secure and compliant. If you care about protecting customer data, and the consumer trust (revenue) tied to that, you need to scan your application for misconfigurations. I have the benefit of being new to application security: I’m not used to long scan times, grumpy security buzzkills, and quarterly patch c
Every ASPM provider provides some combination of the above capabilities. Application Security Posture Management (ASPM) is the latest Gartner fueled buzzword to take over cybersecurity, but no one knows exactly what it is. On the one hand, it’s a fancy name for vulnerability management: helping ingest and prioritize vulnerabilities from third party tools. On the other hand, it’s a one stop shop for code scanning. In this article I argue that the only meaningful ASPM is an all in one application security scanning tool. Why would you want an ASPM? Why Disagree with Gartner? CSPM and ASPM,…
related reading
- The Rise Of Application Security Posture Management (ASPM) Platformssoftwareanalyst.substack.com
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com
- A Deep Dive Into The Cloud & Application Security Ecosystemsoftwareanalyst.substack.com
- WTF is a Cloud Native Application Protection Platform (CNAPP)?pulse.latio.tech
- Software Supply Chain Security (Part 1)softwareanalyst.substack.com
- The Three Types of Remediation Platformspulse.latio.tech
- APM List: Associate Product Manager Job Listapmlist.com
- OWASP Foundation - The Open Source Foundation for Application Securityowasp.org
- [Latio Pulse #10] RSA Takeawayspulse.latio.tech
- The Future Application Security Engineergyan.ca
- What Tool Best Compliments CNAPP?pulse.latio.tech
- Mythos finds a curl vulnerability | daniel.haxx.sedaniel.haxx.se