惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
博客园 - 聂微东
J
Java Code Geeks
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
D
Docker
B
Blog
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
D
DataBreaches.Net
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Y
Y Combinator Blog
N
Netflix TechBlog - Medium
月光博客
月光博客
F
Fortinet All Blogs
爱范儿
爱范儿
H
Help Net Security
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
WordPress大学
WordPress大学
The Cloudflare Blog
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
U
Unit 42

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Monitor sensitive data [3**-** ***7] that resides in code
Swaroop Sham, Or Heller · 2024-03-13 · via Wiz Blog | RSS feed

Recently, Wiz launched innovative services to become the first CNAPP solution to deliver integrated Data Security Posture Management and to enable secure cloud development. Today, we are expanding Wiz's Data Security Posture Management (DSPM) capabilities to monitor code bases for sensitive data.  

Customers can leverage Wiz's DSPM data classifiers to identify sensitive data in development environments (IDEs), code base, pull requests, and CI/CD platforms. This new capability helps Developer and Security teams reduce the risk of accidental data exposure, avoids compliance violations, prevents data policy violations and helps establish organizational baselines.   

Peek-a-boo, I see you: The risk of sensitive data in code  

Preventing the exposure of sensitive data should be a top priority. Whether intentional or accidental, data leaks can cause substantial risk to the parties involved. Sensitive data, like SSNs or credit card details, can inadvertently end up in code during the application development process, either because it was used during testing or overlooked during the rush to meet deadlines. Traditional approaches to monitor and remediate sensitive data in code are cumbersome to use, lack context and often do not meet the needs of both developer and security teams. This exposes the data to breaches, risking unauthorized access and exploitation, and contravenes laws that require stringent data handling, like GDPR, CCPA, PCI-DSS, and HIPAA. To mitigate these security and privacy risks, it's crucial for organizations and developers to implement secure practices to detect, obfuscate, and report sensitive data in the code base. Neglecting such measures compromises user privacy, attracts legal penalties, and erodes user trust.  

DSPM for code  

Customers can use either the Wiz CLI or Wiz's version control scanners to enable the new DSPM capabilities. These capabilities enable you to identify sensitive data types such as PCI, PII, and PHII during code scanning in your IDE, code base, pull requests, and CI/CD platforms. After you have identified sensitive data in your code, you can take remediation steps to address any issues, so you are building securely from the source. Security teams benefit by reducing the risk of sensitive data in code and compliance violations and developers benefit with quicker detection of sensitive data that might be accidentally included in code.  

How to get started  

Configuring and setting up your scanning policies for sensitive data is easy. Wiz enables complete flexibility and control when defining the scope of policies and what action to take when sensitive data is detected. For example, organizations can scope the application of policies to all resources, or granularly apply the scans to specific directories. Additionally, organizations can choose to either audit or block any findings based on their business needs.   

Analyzing the results of a scan  

Customers can leverage sensitive data findings in a Wiz scan to understand the scope and severity of data leakages in a code base. Under each scan result, you can now review all the sensitive data findings along with severity and count.

These new capabilities will help developers and security teams detect and reduce the risk of accidental sensitive data exposure in their code base and remain compliant at all times. To get started with Wiz DSPM scans for sensitive data in code, read the latest Wiz docs and release notes. New to data scanning? Read the data scanning docs. Questions? We’d love to hear from you. Reach out and our team will be glad to assist.