{"id":1196,"date":"2026-09-11T12:46:35","date_gmt":"2026-09-11T12:46:35","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1196"},"modified":"2026-09-11T12:46:35","modified_gmt":"2026-09-11T12:46:35","slug":"cnapp","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/cnapp\/","title":{"rendered":"CNAPP"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: CNAPP (CLOUD-NATIVE APPLICATION PROTECTION PLATFORM)\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">CNAPP is not a capability. It is five capabilities sold together, and the only reason to buy them together is that they talk to each other.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Cloud<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>CNAPP stands for cloud-native application protection platform. It is an analyst category describing a suite that combines cloud posture, workload protection, cloud entitlements, infrastructure-as-code scanning and container security in one product. The claim is not that any one of those is new, but that combining them reveals risks none of them can see alone.<\/p>\n<\/div>\n\n<p>Judge a CNAPP on whether it delivers that combination. Several are five acquired tools behind one login.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#inside\">What is inside a CNAPP<\/a><\/li>\n    <li><a href=\"#combination\">The combination is the product<\/a><\/li>\n    <li><a href=\"#need\">Do you need one?<\/a><\/li>\n    <li><a href=\"#auditors\">What frameworks ask for<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"inside\">What is inside a CNAPP<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Component<\/th><th>What it does<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a><br>Cloud security posture management<\/td><td>Checks cloud accounts for misconfiguration: public storage, open security groups, unencrypted volumes, disabled logging<\/td><\/tr>\n    <tr><td>CWPP<br>Cloud workload protection<\/td><td>Protects the running thing itself, whether a virtual machine, container or serverless function, through vulnerability detection and runtime monitoring<\/td><\/tr>\n    <tr><td>CIEM<br>Cloud infrastructure entitlement management<\/td><td>Analyses who and what can do what in the cloud, and how far permissions could be chained beyond their intended reach<\/td><\/tr>\n    <tr><td>IaC scanning<\/td><td>Checks Terraform, CloudFormation and similar definitions before deployment, so a misconfiguration is caught in review rather than in production<\/td><\/tr>\n    <tr><td>Container and Kubernetes posture<\/td><td>Image vulnerability scanning, registry checks and cluster configuration review<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Some vendors also fold in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dspm\/\">DSPM<\/a> for sensitive data discovery. The boundary of the category is set by marketing rather than by any standard, so two products both called a CNAPP can differ substantially.<\/p>\n\n<h2 id=\"combination\" class=\"c-sage\">The combination is the product<\/h2>\n\n<p>Four separate tools produce four findings on four dashboards. Each looks moderate. Together they are one exploitable path.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 214\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Four individually moderate findings combining into one critical attack path.\">\n  <defs><marker id=\"cn\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"12\" y=\"14\" width=\"196\" height=\"40\" rx=\"11\" fill=\"#e2eff7\"\/>\n  <text x=\"110\" y=\"32\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#2f6f96\">Container has a critical CVE<\/text>\n  <text x=\"110\" y=\"46\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Found by image scanning<\/text>\n\n  <rect x=\"12\" y=\"60\" width=\"196\" height=\"40\" rx=\"11\" fill=\"#e3f0e9\"\/>\n  <text x=\"110\" y=\"78\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#3a6f5d\">It is reachable from the internet<\/text>\n  <text x=\"110\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Found by posture management<\/text>\n\n  <rect x=\"12\" y=\"106\" width=\"196\" height=\"40\" rx=\"11\" fill=\"#efe4f0\"\/>\n  <text x=\"110\" y=\"124\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#6b4576\">Its role is over-permissive<\/text>\n  <text x=\"110\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Found by entitlement analysis<\/text>\n\n  <rect x=\"12\" y=\"152\" width=\"196\" height=\"40\" rx=\"11\" fill=\"#fbe9dc\"\/>\n  <text x=\"110\" y=\"170\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#a2603a\">That role reaches customer data<\/text>\n  <text x=\"110\" y=\"184\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Found by data discovery<\/text>\n\n  <line x1=\"216\" y1=\"103\" x2=\"266\" y2=\"103\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#cn)\"\/>\n  <text x=\"241\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">correlate<\/text>\n\n  <rect x=\"274\" y=\"52\" width=\"474\" height=\"102\" rx=\"14\" fill=\"#cfd5f2\"\/>\n  <text x=\"511\" y=\"84\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">One attack path, not four medium findings<\/text>\n  <text x=\"511\" y=\"110\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Internet reachable, exploitable, over-permissioned,<\/text>\n  <text x=\"511\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">and one hop from the data that matters<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<div class=\"callout\">\n  <p class=\"k\">This is the only argument for buying a suite<\/p>\n  <p>Each of those findings sits in a backlog of hundreds. Ranked by severity in isolation, none of them reaches the top. What makes the combination urgent is reachability crossed with permission crossed with what sits at the end of the path, and no single-layer tool can compute it. If a CNAPP cannot show you that chain, you have bought a bundle discount rather than a platform.<\/p>\n<\/div>\n\n<h2 id=\"need\" class=\"c-plum\">Do you need one?<\/h2>\n\n<p>The category was designed for organisations running large multi-cloud estates with hundreds of engineers. Below that scale the honest answer changes.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Situation<\/th><th>What is actually needed<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>One cloud, under 50 people<\/td><td>Posture management, image scanning and disciplined entitlements. A full suite mostly surfaces findings nobody has capacity to act on<\/td><\/tr>\n    <tr><td>Multi-cloud, growing engineering team<\/td><td>Correlation starts to earn its cost, because the paths now cross accounts and nobody holds the whole picture<\/td><\/tr>\n    <tr><td>Heavy Kubernetes footprint<\/td><td>Cluster and image posture become genuinely hard to do manually, and this is where the category is strongest<\/td><\/tr>\n    <tr><td>Regulated and audited<\/td><td>Continuous posture evidence matters more than attack path analysis. That is a narrower requirement<\/td><\/tr>\n    <tr><td>Mostly managed services, little container use<\/td><td>Much of a CNAPP would go unused. Posture and identity carry the weight<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Alert volume is the practical constraint. A suite that finds everything and prioritises nothing produces a backlog rather than a security improvement.<\/p>\n\n<h2 id=\"auditors\" class=\"c-sky\">What frameworks ask for<\/h2>\n\n<p>No framework names CNAPP. They ask for outcomes the components happen to produce.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Requirement<\/th><th>Which component evidences it<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Secure configuration baselines<\/td><td>Posture management, with a record of drift and remediation<\/td><\/tr>\n    <tr><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability management<\/a><\/td><td>Image and workload scanning, with time-to-remediate by severity<\/td><\/tr>\n    <tr><td>Least privilege<\/td><td>Entitlement analysis and periodic <a href=\"https:\/\/www.osto.one\/resources\/glossary\/rbac\/\">role review<\/a><\/td><\/tr>\n    <tr><td>Change control<\/td><td>Infrastructure-as-code scanning results attached to the pull request that changed the environment<\/td><\/tr>\n    <tr><td>Logging and monitoring<\/td><td>Runtime detection feeding <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">a SIEM<\/a> with retained records<\/td><\/tr>\n    <tr><td>Risk-based prioritisation<\/td><td>Evidence that severity ratings account for exposure, not just CVSS score<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> all sample the same underlying thing: a finding, a decision, a date and a fix.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Osto is not sold as a CNAPP suite. There is no Kubernetes posture module and no container runtime agent, and a heavy Kubernetes estate is a genuine reason to look at the dedicated category.<\/p>\n\n<p>What Osto does cover is most of the ground a small cloud team actually stands on. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">Cloud posture management<\/a> runs across AWS, Azure and GCP. Code security covers <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> generation, so dependency risk is caught before deployment. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">Web and API protection<\/a> covers the reachable surface at runtime, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">access management<\/a> governs who holds what.<\/p>\n\n<p>The correlation argument still applies, from a different direction. Cloud posture, endpoint, identity and application events land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">one SIEM<\/a> on one stack, so a misconfiguration and the identity exploiting it appear in the same view rather than in two products that were integrated afterwards.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Correlation without the integration project<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Cloud posture, code security, API protection and access control on one stack, with findings and identity events in the same view. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is CNAPP?<\/summary>\n  <p>Cloud-native application protection platform. A suite combining cloud posture management, workload protection, entitlement analysis, infrastructure-as-code scanning and container security, on the argument that correlating those layers reveals risk none of them shows alone.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between CNAPP and CSPM?<\/summary>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> is one component of a CNAPP. It checks cloud configuration. A CNAPP adds workload protection, entitlements, code scanning and container posture on top, and attempts to connect their findings.<\/p>\n<\/details>\n\n<details>\n  <summary>What is an attack path?<\/summary>\n  <p>A chain of individually moderate findings that together allow real compromise: an exploitable workload that is internet reachable, holds an over-permissive role, and can access sensitive data. Computing that chain is the main thing a suite offers over separate tools.<\/p>\n<\/details>\n\n<details>\n  <summary>Does a startup need a CNAPP?<\/summary>\n  <p>Usually not the full suite. On one cloud with a small engineering team, posture management, dependency scanning and disciplined entitlements cover most of the risk. Full suites tend to generate more findings than a small team can work through.<\/p>\n<\/details>\n\n<details>\n  <summary>Is CNAPP required by any compliance framework?<\/summary>\n  <p>No framework names it. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> ask for secure baselines, vulnerability management, least privilege and change control. Those outcomes can be evidenced with or without a suite.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dspm\/\">DSPM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/rbac\/\">RBAC<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/easm\/\">EASM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>CNAPP is not a capability. It is five capabilities sold together, and the only reason to buy them together is\u2026<\/p>\n","protected":false},"author":8,"featured_media":1197,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[597,595,594,596],"class_list":["post-1196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-attack-path-analysis","tag-cloud-native-application-protection-platform","tag-cnapp","tag-cnapp-vs-cspm"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1196"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1196\/revisions"}],"predecessor-version":[{"id":1198,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1196\/revisions\/1198"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1197"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}