AWS Inspector Use Cases
Transcript
thanks for joining I'm Joe Peterson I'm the vice president of cloud and security for clarify 360. and I'm here today on behalf of the CTO advisor and their series AWS every day I'm here to talk about AWS security so let's talk about AWS inspector today what is it inspector is a vulnerability Management Service that continually scans AWS workloads for software vulnerabilities and unintended Network exposure with a few clicks in the AWS Management console you can use Amazon inspector across all accounts in your organization once started the tool automatically discovers running ec2 instances container images residing in Amazon container registry and AWS Lambda functions at scale and immediately starts assessing them for known vulnerabilities Amazon inspector calculates a highly contextualized risk score for each finding by correlating Common vulnerabilities and exposures with factors such as network access and exploitability then this score is used to prioritize the most critical vulnerabilities to improve remediation response and efficacy all findings are aggregated in a newly designed Amazon inspector console and pushed to AWS security Hub and Amazon event bridge to automate workflows so vulnerabilities found in container images for instance are also sent to Amazon ECR for resource owners to view and remediate with Amazon inspector even small security teams and developers can ensure infrastructure workload security and compliance across their AWS workloads so here's four use cases that you may not know about you can quickly discover vulnerabilities and compute workloads like we talked about you can prioritize patch remediation which is a big deal use up-to-date common vulnerabilities and expose your information combined with factors such as Network accessibility to create context-based risk scores that help you prioritize and address vulnerable resources you can meet with compliance requirements it'll allow you to support compliant requirements and best practices for nist CSF PCI DSS and other regulations within an Amazon inspector scans and then you can identify a zero day vulnerability sooner thanks for tuning in