Lacework, the data-driven cloud security company announced a new integration with Google Cloud’s Chronicle Security Operations, bringing its cloud-native application protection platform (CNAPP) capabilities to Chronicle deployments.

By tapping into rich multi-cloud runtime alerts from the Lacework Polygraph Data Platform, organiations using Chronicle Security Operations gain better insight into cloud threats, helping them understand, respond to, and remediate incidents more effectively than ever before. Lacework fully integrates multi-cloud runtime telemetry with Chronicle Security Operations.

Modern threat management solution

SOC teams need a modern threat management solution to allow company overall to operate and innovate effectively

SOC teams that rely on legacy security solutions, which are based on static, manually-written rules, can’t keep up with the rate and scale of changes in cloud environments. They are then forced to spend an increasing amount of analyst time and energy sifting through an overwhelming volume of low-context alerts.

SOC teams need a modern threat management solution that can keep up with the constantly changing nature of the cloud and allow them and their company overall to operate and innovate effectively at scale. 

Lacework Polygraph Data Platform

With this integration, organisations using Chronicle Security Operations can access runtime alerts and anomalous activity from multi-cloud environments, generated by the Lacework Polygraph Data Platform.

The Lacework Polygraph Data Platform uses automation to provide teams with an improved signal-to-noise ratio compared to traditional solutions that are not built for the cloud, without the need for manual intervention.

The addition of these high-context alerts allows SOC teams to quicken investigation and remediation and closes the gap between SOC and security teams by embedding Lacework into security playbooks.

Visibility 

Lacework’s integration enables organisations to detect and address the right threats"

Enterprises transforming their security strategies for the cloud require technologies that easily deliver comprehensive visibility across their multi-cloud environments,” Sunil Potti, VP/GM of Security, Google Cloud.

He adds, “Lacework’s integration with Chronicle Security Operations enables organisations to detect and address the right threats via contextual insights that matter the most across their diverse environments.”

Features 

Key capabilities of this integration include:

  • Anomaly detections from Lacework, including the cloud control plane, audit logs, cloud, and container instances for Google Cloud, AWS, and Microsoft Azure are all shared with Chronicle Security Operations.
  • Using Chronicle’s Universal Data Model parsers, customers can easily onboard this integration within their existing Chronicle instance.
  • Customers will be able to create automation, orchestration, and response playbooks using Chronicle SOAR to quickly react to and address issues.

Better multi-cloud understanding 

Cloud threats are only becoming more sophisticated over time, so it’s critical for security teams to have the right context to make the right decisions to remediate issues quickly,” said Jay Parikh, Co-CEO of Lacework.

He adds, “Through our continued partnership with Google Cloud, we’re making it easier for joint customers to take advantage of the richness of Lacework data so they can get a better understanding of what’s happening across their multi-cloud environments and continue to innovate with confidence.”

Download PDF version Download PDF version

In case you missed it

Anviz Global expands palm vein tech for security
Anviz Global expands palm vein tech for security

The pattern of veins in the hand contains unique information that can be used for identity. Blood flowing through veins in the human body can absorb light waves of specific wavelen...

Bosch sells security unit to Triton for growth
Bosch sells security unit to Triton for growth

Bosch is selling its Building Technologies division’s product business for security and communications technology to the European investment firm Triton. The transaction enc...

In age of misinformation, SWEAR embeds proof of authenticity into video data
In age of misinformation, SWEAR embeds proof of authenticity into video data

The information age is changing. Today, we are at the center of addressing one of the most critical issues in the digital age: the misinformation age. While most awareness of thi...

Quick poll
What is the most significant challenge facing smart building security today?