{"id":41308,"date":"2026-04-02T23:00:29","date_gmt":"2026-04-02T23:00:29","guid":{"rendered":"https:\/\/ramsdata.com.pl\/prisma-cloud-how-palo-alto-networks-protects-multi-cloud-environments\/"},"modified":"2026-04-02T23:00:29","modified_gmt":"2026-04-02T23:00:29","slug":"prisma-cloud-how-palo-alto-networks-protects-multi-cloud-environments","status":"publish","type":"post","link":"https:\/\/ramsdata.com.pl\/en\/prisma-cloud-how-palo-alto-networks-protects-multi-cloud-environments\/","title":{"rendered":"Prisma Cloud &#8211; how Palo Alto Networks protects multi-cloud environments"},"content":{"rendered":"<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Cloud computing has changed the rules of the game in IT &#8211; and at the same time changed the rules of the game for attackers. Misconfiguration of cloud resources, invisible lateral paths between services, privileged identities without oversight &#8211; these are today&#8217;s biggest sources of incidents in cloud environments. Prisma Cloud from Palo Alto Networks is a CNAPP platform that addresses these problems comprehensively &#8211; from code to runtime, from infrastructure configuration to identities and workloads. In this article, we explain how it works and what it realistically gives organizations operating across multiple clouds.   <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Table of contents<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<ol class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\">What is Prisma Cloud and what does CNAPP stand for?<\/li>\n<li class=\"whitespace-normal break-words pl-2\">What risks are specific to multi-cloud environments?<\/li>\n<li class=\"whitespace-normal break-words pl-2\">CSPM &#8211; cloud security level management<\/li>\n<li class=\"whitespace-normal break-words pl-2\">CWPP &#8211; workload protection in the cloud<\/li>\n<li class=\"whitespace-normal break-words pl-2\">CIEM &#8211; identity and privilege management<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Code Security &#8211; security at the development stage<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Prisma Cloud and regulatory compliance<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Key findings<\/li>\n<li class=\"whitespace-normal break-words pl-2\">FAQ<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Summary<\/li>\n<\/ol>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">What is Prisma Cloud and what does CNAPP stand for?<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">CNAPP &#8211; Cloud-Native Application Protection Platform &#8211; is a category of security products that combines features previously available only as separate tools into a single platform: CSPM, CWPP, CIEM and Code Security. Prisma Cloud from Palo Alto Networks is one of the leaders in this category. The idea behind CNAPP stems from the observation that attacks on cloud environments are rarely based on a single vulnerability &#8211; they are usually a chain of events: misconfiguration plus unused permissions plus lack of runtime monitoring equals a successful attack.  <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Separate tools for each of these layers cannot see the entire chain. Prisma Cloud can see &#8211; and this is its fundamental advantage. The platform integrates with AWS, Azure, GCP and Oracle Cloud via native APIs, scanning all resources automatically and continuously. <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/ramsdata.com.pl\/producenci\/palo-alto-networks\/\">Palo Alto Networks&#8217; Ramsdata portfolio<\/a> covers the full spectrum of its products, including Prisma Cloud and next-generation NGFW.  <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">What risks are specific to multi-cloud environments?<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Multi-cloud environments generate specific security risks that traditional security tools do not see. Misconfigurations are statistically the largest source of incidents &#8211; open S3 buckets, public disk snapshots, overly open security groups. Each cloud platform has thousands of possible configurations, and manual verification is impossible at scale.  <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The explosion of identities and permissions is another problem &#8211; in large organizations there are tens of thousands of IAM roles, service accounts and API keys, a significant number of which have permissions far broader than they need. An attacker who seizes one such account can move laterally throughout the environment. The lack of visibility between services in a microservices architecture means that anomalous data flows go unnoticed. All these problems are addressed by Prisma Cloud modules.   <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">CSPM &#8211; cloud security level management<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">CSPM (Cloud Security Posture Management) is a Prisma Cloud module responsible for continuously scanning the configuration of cloud resources for deviations from security patterns and compliance requirements. The platform connects to AWS, Azure and GCP accounts via API and automatically scans all resources &#8211; instances, containers, databases, networks, IAM policies. <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The results are presented as a list of faulty configurations with risk prioritization and precise remediation instructions. Some configurations can be remediated automatically by auto-remediation mechanisms. CSPM covers the regulatory requirements of CIS Benchmarks, PCI-DSS, HIPAA, SOC 2 and GDPR, generating ready-to-use compliance reports for auditors. For companies operating in a regulated environment, this saves hundreds of hours of manual work.   <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">CWPP &#8211; workload protection in the cloud<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">CWPP (Cloud Workload Protection Platform) protects what runs in the cloud &#8211; virtual machines, containers, serverless functions. The Prisma Cloud agent installed on hosts and in Kubernetes clusters provides visibility into processes, network connections and file activity at runtime. Any anomalies &#8211; process spawning from a web container, connection to an external IP, modification of a system file &#8211; are detected and alerted in real time.  <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">CWPP also includes scanning container images prior to deployment &#8211; each image is checked for known vulnerabilities (CVEs), secrets embedded in code and non-compliance with CIS policies. This &#8220;shift-left security&#8221; approach &#8211; problems are detected before anything goes into production. For detailed information on endpoint layer security solutions, visit <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/ramsdata.com.pl\/oferta\/technologie\/nac-endpoint-security-nowej-generacji\/\">Ramsdata&#8217;s NAC Endpoint Security<\/a> page.  <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">CIEM &#8211; identity and privilege management<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">CIEM (Cloud Infrastructure Entitlement Management) is a module that addresses the problem of excessive permissions in cloud environments. Prisma Cloud maps all identities &#8211; users, IAM roles, service accounts, API keys &#8211; and analyzes their actual usage compared to granted privileges. The result is a graphical identity risk map with recommendations for reducing permissions to the minimum required (least privilege principle).  <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">CIEM also detects dangerous patterns: accounts with administrative privileges that have not been used for months, service accounts with access to production resources, temporary API keys that have become permanent. Automatic remediation recommendations quickly reduce the attack surface without manually analyzing thousands of permissions. <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Code Security &#8211; security at the development stage<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Code Security is a module that integrates with code repositories (GitHub, GitLab, Bitbucket) and scans IaC (Infrastructure as Code) &#8211; Terraform, CloudFormation, Kubernetes YAML &#8211; for security misconfigurations before code is deployed. Developers get feedback on problems directly in pull requests, eliminating the risk of deploying incompatible configurations. <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Prisma Cloud also scans for secrets &#8211; API keys, passwords, tokens &#8211; embedded in code or configuration files. This is one of the most common attack vectors against cloud environments, which Code Security eliminates as early as the code review stage. <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Prisma Cloud and regulatory compliance<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">For organizations operating in a regulated environment, Prisma Cloud offers turnkey compliance frameworks &#8211; CIS Benchmarks for AWS\/Azure\/GCP, PCI-DSS, HIPAA, SOC 2, ISO 27001, GDPR and many others. Each resource is automatically mapped to regulatory requirements and assessed for compliance. Compliance reports are generated automatically and can be exported to formats acceptable to auditors.  <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Key findings<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\">Prisma Cloud is a CNAPP platform that combines CSPM, CWPP, CIEM and Code Security in a single tool.<\/li>\n<li class=\"whitespace-normal break-words pl-2\">CSPM constantly scans cloud resource configurations and detects deviations from security patterns.<\/li>\n<li class=\"whitespace-normal break-words pl-2\">CWPP protects workloads at runtime and scans container images before deployment.<\/li>\n<li class=\"whitespace-normal break-words pl-2\">CIEM maps all identities and permissions, indicating excessive access rights.<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Code Security integrates with the CI\/CD pipeline, detecting problems before the code goes into production.<\/li>\n<li class=\"whitespace-normal break-words pl-2\">The platform supports AWS, Azure, GCP and Oracle Cloud with a unified management panel.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">FAQ<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Does Prisma Cloud require an agent on every machine?<\/strong>  The CSPM module runs without an agent &#8211; via the cloud API. CWPP requires a lightweight agent (Defender) on protected hosts and in Kubernetes clusters. <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>How does Prisma Cloud integrate with existing SIEM?<\/strong>  Prisma Cloud supports integration with Splunk, Elastic, QRadar and other SIEMs via standard APIs and ready-made connectors. Alerts and logs can be sent in real time. <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Does Prisma Cloud work in on-prem environments?<\/strong>  Prisma Cloud is optimized for cloud environments. On-prem environments can be monitored by CWPP agents, but full CSPM and CIEM functionality requires cloud resources. <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>What does Prisma Cloud licensing look like?<\/strong>  Licensing is modular &#8211; organizations can buy only the modules they need. Pricing is based on the number of protected resources or bandwidth. <\/p>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<h3 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\">Summary<\/h3>\n<\/div>\n<\/div>\n<div>\n<div class=\"standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3\">\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Prisma Cloud is a comprehensive answer to security challenges in multi-cloud environments &#8211; from misconfigurations to excessive permissions to runtime threats. Integrating all layers of protection in a single platform allows you to see the full attack chain and respond faster. If you manage a multi-cloud infrastructure and are looking for a platform that gives you full visibility and control, contact <a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/ramsdata.com.pl\/producenci\/palo-alto-networks\/\">Ramsdata &#8211; a Palo Alto Networks partner<\/a>.  <\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cloud computing has changed the rules of the game in IT &#8211; and at the same time changed the rules of the game for attackers. Misconfiguration of cloud resources, invisible lateral paths between services, privileged identities without oversight &#8211; these are today&#8217;s biggest sources of incidents in cloud environments. Prisma Cloud from Palo Alto Networks [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":29076,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"categories":[56],"tags":[],"class_list":["post-41308","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-en"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/ramsdata.com.pl\/en\/wp-json\/wp\/v2\/posts\/41308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ramsdata.com.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ramsdata.com.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ramsdata.com.pl\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ramsdata.com.pl\/en\/wp-json\/wp\/v2\/comments?post=41308"}],"version-history":[{"count":0,"href":"https:\/\/ramsdata.com.pl\/en\/wp-json\/wp\/v2\/posts\/41308\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ramsdata.com.pl\/en\/wp-json\/wp\/v2\/media\/29076"}],"wp:attachment":[{"href":"https:\/\/ramsdata.com.pl\/en\/wp-json\/wp\/v2\/media?parent=41308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ramsdata.com.pl\/en\/wp-json\/wp\/v2\/categories?post=41308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ramsdata.com.pl\/en\/wp-json\/wp\/v2\/tags?post=41308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}