CIO Influence
CIO Influence News Cloud Security

Sysdig and Snyk Announce Partnership to Enable End-to-End Container Security

Sysdig and Snyk Announce Partnership to Enable End-to-End Container Security
Industry-First Integration Empowers Teams from Developers to SecOps with Prioritized Remediation

Sysdig, the unified container and cloud security leader, and Snyk, the leader in developer security,  announced the integration of Sysdig Secure with Snyk Container to cover container security from development through operations. Based on initial internal testing, this integration allows teams to eliminate up to 95 percent of vulnerability alerts using runtime intelligence from Sysdig Secure with Snyk Container.

With this partnership, Sysdig and Snyk bring together the industry-leading container runtime and developer security tools, for the first integration that bridges developer, DevOps, and SecOps silos. Sysdig runtime context provides Snyk users the ability to quickly pinpoint exploitable packages that are active in production applications. The integration aligns developer, operations, and security teams on which vulnerabilities to prioritize fixing first, focusing scarce developer resources on the biggest risks.

Top iTechnology 5G Technology News: Hitachi Energy Brings 5G Connectivity To Mission-Critical Industrial And Utility Operations

Today’s Container Security Reality: Balancing Risk Reduction with Developer Agility

  • Developers are overwhelmed with vulnerabilities and don’t know where to focus remediation efforts. Attempting to wade through the unmanageable number of issues is noise that takes precious time away from coding and leaves organizations open to risk. By understanding business impact, as well as severity s****, teams can fix the most critical issues first.
  • Security and operations teams responsible for monitoring the runtime environment need the container and Kubernetes visibility required to flag newly identified vulnerabilities for workloads running in production. They also need to detect threats attacking vulnerabilities that have not been fixed, and to stay ahead of zero-day exploits.

Sysdig’s unique container visibility and threat protection and Snyk’s developer-first tooling pair accurate runtime threat protection with early detection and vulnerability management. By bringing this information into the development pipeline, Sysdig and Snyk are in a unique position to help development teams instantly eliminate up to 95 percent of the vulnerabilities that would otherwise demand their attention.

Bridging The Gap: Sysdig + Snyk

Sysdig and Snyk’s new collaboration helps organizations more effectively remove the security barriers that stand in the way of faster innovation.

Top iTechnology Cloud News: Tempest Risk Management Launches The Tempest Gateway, A Mobile SaaS Platform To Help Small Businesses Adapt To Hybrid And Virtual Work

This is accomplished by:

  • Securing the entire container lifecycle: Every aspect of the container and Kubernetes lifecycle is now covered — from the most secure base images to detecting and prioritizing which vulnerabilities require attention, to monitoring running workloads for real-time threats and new vulnerabilities.
  • Building securely from the start: Snyk’s security insights and automated remediation are seamlessly integrated to more easily find, prioritize, and fix vulnerabilities in containers and open source dependencies.
  • Protecting against runtime threats: Sysdig’s runtime security, based on open source Falco, detects threats across containers and Kubernetes, and captures detailed activity, enabling teams to accelerate incident response.
  • Prioritizing the security alerts that matter most: With the integration of Snyk and Sysdig, organizations can quickly pinpoint exploitable packages that are active in production applications. This enables organizations to prioritize container vulnerabilities that pose the greatest risk, reducing noise and overall risk to gain developer speed and efficiency.

Top iTechnology IT and DevOps News: JFrog Unveils New DevSecOps Contextual Analysis Capabilities

[To share your insights with us, please write to sghosh@martechseries.com]

Related posts

American Tower Completes Acquisition of CoreSite Realty Corporation

J.P. Morgan Launches Payments Partner Network Powered by Salesforce Commerce Cloud

PR Newswire

NetNumber Expands 5G Capabilities for Private Networks

CIO Influence News Desk

Leave a Comment