Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Qualys Cloud Security offers a vulnerability analysis plug-in specifically designed for the CI/CD tool Jenkins, with plans to expand to additional platforms such as Bamboo, TeamCity, and CircleCI in the near future. Users can conveniently download these plug-ins straight from the container security module. This integration allows security teams to engage in the DevOps workflow, ensuring that vulnerable images are blocked from entering the system, while developers receive practical insights to address vulnerabilities effectively. It is possible to establish policies aimed at preventing the inclusion of vulnerable images in repositories, with settings adjustable based on factors like vulnerability severity and particular QIDs. The plug-in also provides an overview of the build, detailing vulnerabilities, information on software that can be patched, available fixed versions, and the specific image layers affected. Given that container infrastructure is inherently immutable, it is essential for containers to be consistent with the original images they are created from, thus necessitating rigorous security measures throughout the development lifecycle. By implementing these strategies, organizations can enhance their ability to maintain secure and compliant container environments.
Description
Only StackRox offers an all-encompassing view of your cloud-native environment, covering everything from images and container registries to Kubernetes deployment settings and container runtime activities. With its robust integration into Kubernetes, StackRox provides insights specifically tailored to deployments, equipping security and DevOps teams with a thorough understanding of their cloud-native systems, which includes images, containers, pods, namespaces, clusters, and their respective configurations. You gain quick insights into potential risks within your environment, your compliance standing, and any suspicious traffic that may be occurring. Each overview allows you to delve deeper into specifics. Furthermore, StackRox simplifies the process of identifying and scrutinizing container images in your environment, thanks to its native integrations and support for nearly all types of image registries, making it a vital tool for maintaining security and efficiency.
API Access
Has API
Yes
API Access
Has API
No
Integrations
Kubernetes
Yes
Akitra Andromeda
Yes
C1Risk
Yes
Check Point Exposure Management
Yes
Complyance
Yes
Compyl
Yes
CyberDNA Command and Control Center
Yes
Docker
Yes
Fork
Yes
Graylog
Yes
Integrations
Kubernetes
Yes
Akitra Andromeda
No
C1Risk
No
Check Point Exposure Management
No
Complyance
No
Compyl
No
CyberDNA Command and Control Center
No
Docker
No
Fork
No
Graylog
No
Pricing Details
No price information available.
Free Trial
Yes
Free Version
No
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
Yes
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
Yes
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
Qualys
Founded
1999
Country
United States
Website
www.qualys.com/apps/container-security/
Vendor Details
Company Name
StackRox
Founded
2014
Country
United States
Website
stackrox.com
Product Features
Container Security
Access Roles / Permissions
No
Application Performance Tracking
No
Centralized Policy Management
No
Container Stack Scanning
No
Image Vulnerability Detection
No
Reporting
No
Testing
No
View Container Metadata
No
Product Features
Cloud Workload Protection
Anomaly Detection
No
Asset Discovery
No
Cloud Gap Analysis
No
Cloud Registry
No
Data Loss Prevention (DLP)
No
Data Security
No
Governance
No
Logging & Reporting
No
Machine Learning
No
Security Audit
No
Workload Diversity
No
Container Security
Access Roles / Permissions
No
Application Performance Tracking
No
Centralized Policy Management
No
Container Stack Scanning
No
Image Vulnerability Detection
No
Reporting
No
Testing
No
View Container Metadata
No
DevOps
Approval Workflow
No
Dashboard
No
KPIs
No
Policy Management
No
Portfolio Management
No
Prioritization
No
Release Management
No
Timeline Management
No
Troubleshooting Reports
No
IT Asset Management
Asset Tracking
No
Audit Management
No
Compliance Management
No
Configuration Management
No
Contract/License Management
No
Cost Tracking
No
Depreciation Management
No
IT Service Management
No
Inventory Management
No
Maintenance Management
No
Procurement Management
No
Requisition Management
No
Supplier Management
No
IT Security
Anti Spam
No
Anti Virus
No
Email Attachment Protection
No
Event Tracking
No
IP Protection
No
Internet Usage Monitoring
No
Intrusion Detection System
No
Spyware Removal
No
Two-Factor Authentication
No
Vulnerability Scanning
No
Web Threat Management
No
Web Traffic Reporting
No