STOCK TITAN

Palo Alto Networks Helps Organizations Combat Software Supply Chain Threats With New Prisma Cloud Supply Chain Security

Rhea-AI Impact
(Low)
Rhea-AI Sentiment
(Neutral)
Tags
Rhea-AI Summary

Palo Alto Networks (NASDAQ: PANW) announces the launch of Prisma Cloud Supply Chain Security, designed to combat the growing threat of software supply chain attacks. This tool provides organizations with a comprehensive view of vulnerabilities within their supply chains, enabling swift remediation of security flaws. Gartner predicts that by 2025, 45% of organizations will face such attacks, highlighting the tool's timely relevance. Key features include auto-discovery of code assets, graph visualization of dependencies, and code repository scanning for vulnerabilities, enhancing security throughout the software development lifecycle.

Positive
  • Launch of Prisma Cloud Supply Chain Security enhances security measures against software supply chain attacks.
  • Comprehensive features such as auto-discovery and graph visualization improve vulnerability management.
  • Timely solution in response to Gartner's prediction of increased software supply chain attacks by 2025.
Negative
  • None.

SANTA CLARA, Calif., March 9, 2022 /PRNewswire/ -- With software supply chain attacks rising rapidly, Palo Alto Networks (NASDAQ: PANW) today announced Prisma® Cloud Supply Chain Security to provide a complete view of where potential vulnerabilities or misconfigurations exist in the software supply chain — allowing organizations to quickly trace to the source and fix them. If not quickly fixed or, better yet, avoided during coding, these security flaws could allow attackers to infiltrate systems, spread malicious payloads throughout an organization's software and access sensitive data.

According to Gartner®, "By 2025, 45% of organizations worldwide will have experienced attacks on their software supply chains, a three-fold increase from 2021."* Unit 42's Cloud Threat Report also found that access to hardcoded credentials opened the door for lateral movement and continuous integration/continuous delivery (CI/CD) pipeline poisoning.

Many current solutions only provide vulnerability and misconfiguration information at a resource layer in code or in the cloud. With Supply Chain Security, Prisma Cloud, already a leader in cloud native security and the most complete Cloud Native Application Protection Platform (CNAPP), provides not only full lifecycle visibility and protection but the context of where a vulnerability fits into the layers of a cloud architecture. 

"Every day new vulnerabilities are found in open source and other software components that have previously been integrated into the organization's software code. Without the proper tools, it is very difficult for organizations to quickly spot where they have used the unpatched versions of these components," said Ankur Shah, senior vice president, Prisma Cloud products, Palo Alto Networks. "Prisma Cloud is designed to help protect organizations from code to cloud; and now that customers can visualize their software supply chain, it's easier to spot, prioritize, and remediate security weaknesses at the onset of development and during delivery pipelines."

Prisma Cloud Supply Chain Security helps provide a full stack, full lifecycle approach to securing the interconnected components that make up and deliver cloud native applications. It can help to identify vulnerabilities and misconfigurations in code, including open source packages, infrastructure as code (IaC) files and delivery pipelines, such as version control system (VCS) and CI pipeline configurations. It includes the following features:

  • Auto-discovery: Code assets are extracted and modeled using existing Cloud Code Security scanners.
  • Graph visualization: Simple and complete inventory of key application and infrastructure asset dependencies to understand weaknesses across the attack surface.
  • Supply chain code fix: Vulnerable dependencies or misconfigured IaC resources can be remediated using a single consolidated pull request.
  • Code repository scanning: Identify and fix vulnerabilities in open source packages in application code.
  • Branch protection rules: Extends policy-as-code to harden VCS and CI/CD configurations (via Checkov) to help prevent code tampering attacks.

With these features, organizations can better assess the attack surface of their delivery pipelines and all connected application and infrastructure resources to be better equipped to help prevent supply chain attacks. Implementing Prisma Cloud supply chain security as part of a Zero Trust architecture is one of the best ways an organization can prevent software supply chain attacks.

"A thriving community creating a vast array of open-source software helps developers accelerate their coding and product delivery, but it increases the attack surface if you can't make sure the code is secure," says Melinda Marks; ESG Senior Analyst, Application and Cloud Security. "The new enhancements in Prisma Cloud allow DevOps and security teams to fully understand their software supply chains so they can identify and remediate coding flaws to secure their cloud native applications."

Availability
The new Supply Chain Security visualization is now available in both Prisma Cloud and Bridgecrew by Prisma Cloud.

More Information
More information about Prisma Cloud is available here.

*Gartner, How Software Engineering Leaders Can Mitigate Software Supply Chain Security Risks, Manjunath Bhat, Dale Gardner, Mark Horvath, July 15, 2021.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

About Palo Alto Networks
Palo Alto Networks, the global cybersecurity leader, is shaping the cloud-centric future with technology that is transforming the way people and organizations operate. Our mission is to be the cybersecurity partner of choice, protecting our digital way of life. We help address the world's greatest security challenges with continuous innovation that seizes the latest breakthroughs in artificial intelligence, analytics, automation, and orchestration. By delivering an integrated platform and empowering a growing ecosystem of partners, we are at the forefront of protecting tens of thousands of organizations across clouds, networks, and mobile devices. Our vision is a world where each day is safer and more secure than the one before. For more information, visit www.paloaltonetworks.com.

Palo Alto Networks, Prisma, and the Palo Alto Networks logo are registered trademarks of Palo Alto Networks, Inc. in the United States and in jurisdictions throughout the world. All other trademarks, trade names, or service marks used or mentioned herein belong to their respective owners. Any unreleased services or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.

 

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/palo-alto-networks-helps-organizations-combat-software-supply-chain-threats-with-new-prisma-cloud-supply-chain-security-301498763.html

SOURCE Palo Alto Networks, Inc.

FAQ

What is Prisma Cloud Supply Chain Security by Palo Alto Networks?

Prisma Cloud Supply Chain Security is a tool launched by Palo Alto Networks to identify and remediate vulnerabilities in software supply chains.

When was Prisma Cloud Supply Chain Security announced?

Prisma Cloud Supply Chain Security was announced on March 9, 2022.

What are the key features of Prisma Cloud Supply Chain Security?

Key features include auto-discovery of code assets, graph visualization of dependencies, vulnerability scanning of code repositories, and remediation capabilities.

How does Prisma Cloud Supply Chain Security help organizations?

It helps organizations identify and fix vulnerabilities within their software supply chains, reducing the risk of cyber attacks.

What does Gartner predict about software supply chain attacks by 2025?

Gartner predicts that 45% of organizations worldwide will experience software supply chain attacks by 2025.

Palo Alto Networks, Inc.

NASDAQ:PANW

PANW Rankings

PANW Latest News

PANW Stock Data

61.98B
649.18M
0.86%
80.77%
3.14%
Software - Infrastructure
Computer Peripheral Equipment, Nec
Link
United States of America
SANTA CLARA