Lacework, the data-driven cloud security company announced a new integration with Google Cloud’s Chronicle Security Operations, bringing its cloud-native application protection platform (CNAPP) capabilities to Chronicle deployments.

By tapping into rich multi-cloud runtime alerts from the Lacework Polygraph Data Platform, organiations using Chronicle Security Operations gain better insight into cloud threats, helping them understand, respond to, and remediate incidents more effectively than ever before. Lacework fully integrates multi-cloud runtime telemetry with Chronicle Security Operations.

Modern threat management solution

SOC teams need a modern threat management solution to allow company overall to operate and innovate effectively

SOC teams that rely on legacy security solutions, which are based on static, manually-written rules, can’t keep up with the rate and scale of changes in cloud environments. They are then forced to spend an increasing amount of analyst time and energy sifting through an overwhelming volume of low-context alerts.

SOC teams need a modern threat management solution that can keep up with the constantly changing nature of the cloud and allow them and their company overall to operate and innovate effectively at scale. 

Lacework Polygraph Data Platform

With this integration, organisations using Chronicle Security Operations can access runtime alerts and anomalous activity from multi-cloud environments, generated by the Lacework Polygraph Data Platform.

The Lacework Polygraph Data Platform uses automation to provide teams with an improved signal-to-noise ratio compared to traditional solutions that are not built for the cloud, without the need for manual intervention.

The addition of these high-context alerts allows SOC teams to quicken investigation and remediation and closes the gap between SOC and security teams by embedding Lacework into security playbooks.

Visibility 

Lacework’s integration enables organisations to detect and address the right threats"

Enterprises transforming their security strategies for the cloud require technologies that easily deliver comprehensive visibility across their multi-cloud environments,” Sunil Potti, VP/GM of Security, Google Cloud.

He adds, “Lacework’s integration with Chronicle Security Operations enables organisations to detect and address the right threats via contextual insights that matter the most across their diverse environments.”

Features 

Key capabilities of this integration include:

  • Anomaly detections from Lacework, including the cloud control plane, audit logs, cloud, and container instances for Google Cloud, AWS, and Microsoft Azure are all shared with Chronicle Security Operations.
  • Using Chronicle’s Universal Data Model parsers, customers can easily onboard this integration within their existing Chronicle instance.
  • Customers will be able to create automation, orchestration, and response playbooks using Chronicle SOAR to quickly react to and address issues.

Better multi-cloud understanding 

Cloud threats are only becoming more sophisticated over time, so it’s critical for security teams to have the right context to make the right decisions to remediate issues quickly,” said Jay Parikh, Co-CEO of Lacework.

He adds, “Through our continued partnership with Google Cloud, we’re making it easier for joint customers to take advantage of the richness of Lacework data so they can get a better understanding of what’s happening across their multi-cloud environments and continue to innovate with confidence.”

Download PDF version Download PDF version

In case you missed it

AMPELMANN GmbH enhances security with ASSA ABLOY eCLIQ solution
AMPELMANN GmbH enhances security with ASSA ABLOY eCLIQ solution

The Ampelmännchen (“little traffic light man”) from the former GDR is a cult figure around the globe. For tourists, the shops of AMPELMANN GmbH in Berlin are a big...

What are the unique challenges of the government market for security?
What are the unique challenges of the government market for security?

Factors such as stable demand and large contracts make the government market particularly enticing for security companies and professionals. However, entering and thriving in the g...

RapidSOS enables critical data sharing to improve emergency response
RapidSOS enables critical data sharing to improve emergency response

In an emergency, information is pivotal. More information provides better understanding of an emergency and empowers potentially life-saving decision-making. Emergency response tea...

Quick poll
Which feature is most important in a video surveillance system?