With Wiz adding ”DSPM” or rather data classification, do you see there being much need for DSPM on top of CSPM? I feel like the DLP and Detection and Response are way more important than CSPM checks, but is that just me?

698 views4 Comments
Sort By:
Oldest
Global Chief Cybersecurity Strategist & CISO in Healthcare and Biotecha year ago
CSPM and DSPM are two distinct strategies for cybersecurity. While there might be some overlapping areas, there are key differences between them.

CSPM focuses on protecting the cloud infrastructure and its resources, covering only IaaS and PaaS components like virtual private clouds or machines, relational databases, compute instances, lambda functions, and serverless components. From a risk management perspective, CSPM lacks data intelligence to prioritize data assets.

DSPM emphasizes the security posture of data in public clouds. It delves into data, gaining insights into its type, sensitivity, geography, transformation over time, and how it's accessed or utilized. With such extensive data intelligence, DSPM aids teams in improving the configuration security posture. This includes controlling access to prevent unauthorized access and encrypting or masking sensitive data to comply with global data privacy regulations, particularly policies around cross-border data transfers and sensitive data sharing.

Need to really drill down on any marketed solution that says it is a Unified solution DSPM+CSPM and look at the gaps it isn't doing.
4
CIO in IT Servicesa year ago
There are wonderful vendors available in both the DPSM and CSPM spaces and I worry that Wiz is taking on too many functions for their platform. It's hard to be a unicorn, the pressure must be over the top - but when is it too much?
1
CISO in Softwarea year ago
It is about vendors moving to provide an entire suite of services versus businesses needed to individually deploy and integrate a whole set of independent security products and solutions
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
Chief Information Security Officer in Healthcare and Biotecha year ago
The need for DSPM and CSPM is different. It depends on the organisation's security posture and how they want to manage their digital risk.  

Content you might like

Implementation complete23%

Implementation in progress54%

Planned within the next 12 months12%

Not planned7%

Not enabling O365 on mobile2%

View Results
2.4k views2 Upvotes
Chief Security Officer in Software3 years ago
Its not exactly automation of reports but we are looking at AttackIQ to automate parts of the pentesting process including reporting. Happy to chat further if interested.
3
Read More Comments
4.7k views3 Upvotes5 Comments
Director Information Security in Healthcare and Biotech6 months ago
In a recent call I had with Varonis, they referred to themselves as a "pre" or "post" DLP tool. They lack features for endpoint controls and rely on classification leveraging Microsoft or another DLP tool. While it will give ...read more
1 1 Reply
679 views2 Comments

Building an effective incident response plan32%

Educating and training employees on cybersecurity63%

Enforcing password and access management52%

Protecting endpoint devices38%

Integrating security solutions18%

Embracing the cloud8%

View Results
2.8k views2 Upvotes1 Comment