惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
博客园 - 【当耐特】
月光博客
月光博客
Vercel News
Vercel News
D
Docker
I
InfoQ
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
GbyAI
GbyAI
有赞技术团队
有赞技术团队
雷峰网
雷峰网
博客园 - 聂微东
小众软件
小众软件
Y
Y Combinator Blog
腾讯CDC
L
LangChain Blog
The GitHub Blog
The GitHub Blog
宝玉的分享
宝玉的分享
Stack Overflow Blog
Stack Overflow Blog
大猫的无限游戏
大猫的无限游戏
T
The Blog of Author Tim Ferriss

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Docker and Kubernetes, we have got you covered: Wiz simpl...
Karin Sukonik, Swaroop Sham, Nicolas Ehrman · 2023-08-22 · via Wiz Blog | RSS feed

A few months ago, we announced that Wiz is the first agentless cloud security vendor to attain CIS SecureSuite Vendor Certification for cloud-managed Kubernetes. Building on this commitment to secure containerized environments, we are excited to share that we are now expanding our coverage further.  

Today, we are extending our CIS SecureSuite Vendor Certification coverage by being awarded for: 

  • CIS Kubernetes Benchmark v1.7.x, Level 1 + Level 2 

  • CIS Docker Benchmark 1.6.0 - Level 1 + Level 2 

Customers can use the over 100+ host rules and controls, security guidelines, and best practices reflecting CIS recommendations that must be implemented to ensure their Docker and Kubernetes environments are securely configured. 

Extend CIS benchmark to self-managed Kubernetes 

As detailed in our prior blog post, the configuration of Kubernetes can prove intricate, a complexity further magnified when undertaking manual deployment. In fact, overlooking the incorporation of essential security best practices during deployment, as well as throughout the entire cluster lifecycle, can be a common pitfall. This is precisely where Wiz comes into play: facilitating a comprehensive comprehension of your Kubernetes landscapes' security stance. This is achieved through continuous scrutiny of your clusters, actively identifying potential risks in alignment with the CIS benchmark best practices. 

Why is securing Docker a need?

Docker has emerged as a leading containerization platform in today's fast-paced digital landscape, revolutionizing how applications are developed, deployed, and scaled. Developers can deploy new applications in minutes by simply deploying an entirely new infrastructure via their pipeline. However, misconfigurations can easily reach production as developers may not always implement all security best practices and use public virtual machine images.   

This is a challenge for organizations that increasingly rely on Docker environments to power their applications. The need for robust security controls is paramount. One essential way to achieve this is through CIS certification, which provides a standardized security benchmark for Docker containers. 

The CIS Docker Benchmark helps organizations configure their Docker environments securely and implement the latest best practices to reduce the risk of data breaches and other incidents. These benchmarks keep sensitive data safe and secure. In addition, many compliance frameworks such as PCI DSS, HIPAA, and NIST require exacting security benchmarks as part of their compliance efforts. This means that by implementing the benchmarks, organizations can meet their cloud compliance obligations and avoid potential fines and penalties.   

Wiz automatically and continuously reviews all the information collected against the CIS benchmarks for Docker environments. The benchmarks consist of a set of built-in checks and configuration rules for the hosts and the container.  Wiz provides a handy overview of the checks passed and compliance posture that can be used for quick assessment.  Additionally, customers can customize the compliance framework to suit their individual requirements.

Once you identify the failing check in your environment, Wiz gives you specific remediation guidance to address it. Now you can quickly respond and ensure the security of their infrastructure without sacrificing agility. 

Stay on top of your Docker and Kubernetes compliance posture 

Wiz will continuously monitor your cloud environment and detect new Docker instances and Kubernetes clusters. This allows us to maintain an up-to-date view of the security risks and compliance status of all your Docker instances, Kubernetes instances and their containers. 

Getting started is easy with a few quick clicks.  On the Compliance > Single Framework page, CIS category names are represented as categories while recommendations are represented as sub-categories. Learn more about how you can use these new compliance capabilities.  Use the Wiz docs (login required) to get started. Have questions, comments, or feedback? Do reach out to Wiz. We love hearing from you.