Fidelis Security > Case Studies > CloudPassage Enables Security for the Centrify DevOps Team with Vulnerability Assessment and Reporting, While Providing Compliance Reporting

CloudPassage Enables Security for the Centrify DevOps Team with Vulnerability Assessment and Reporting, While Providing Compliance Reporting

Fidelis Security Logo
Company Size
1,000+
Region
  • America
Country
  • United States
Product
  • CloudPassage Halo
  • Jenkins
  • SaltStack
Tech Stack
  • CI/CD workflow
  • API Integration
Implementation Scale
  • Enterprise-wide Deployment
Impact Metrics
  • Cost Savings
  • Digital Expertise
  • Productivity Improvements
Technology Category
  • Application Infrastructure & Middleware - API Integration & Management
  • Cybersecurity & Privacy - Cloud Security
  • Cybersecurity & Privacy - Security Compliance
Applicable Industries
  • Software
Applicable Functions
  • Discrete Manufacturing
  • Quality Assurance
Use Cases
  • Cybersecurity
  • Regulatory Compliance Monitoring
Services
  • Cloud Planning, Design & Implementation Services
  • Cybersecurity Services
About The Customer
Centrify is a company that delivers Zero Trust Security through the power of Next-Gen Access. They verify every user, validate their devices, and limit the amount of access and privilege to resources while continually learning and adapting. Centrify's Next-Gen Access is the only industry-recognized solution that uniquely converges Identity-as-a Service (IDaaS), enterprise mobility management (EMM) and privileged access management (PAM.) The company serves over 5,000 worldwide organizations, including over half the Fortune 100. They are trusted by these businesses to proactively secure their operations.
The Challenge
Centrify, a company that delivers Zero Trust Security through the power of Next-Gen Access, needed to integrate security into their DevOps process. They wanted to evaluate vulnerability assessments before placing upgrades into production. Additionally, they needed to prepare for the Federal Risk and Authorization Management Program (FedRAMP) and the Service Organization Control (SOC 2) compliance audits. Centrify was searching for a product that could integrate into the organization’s CI/CD workflow – which includes the Jenkins and SaltStack toolsets – so assessments could take place prior to updates being pushed into production. They also needed a solution that provided detailed vulnerability management and reporting tools.
The Solution
Centrify deployed CloudPassage Halo and employed Halo’s vulnerability management and reporting in order to prepare for the FedRAMP and Soc2 compliance audits. They integrated the Halo API into Jenkins and SaltStack, integrating Halo directly with their DevOps processing. Centrify immediately began employing all CloudPassage Halo modules including: software vulnerability assessment, configuration security monitoring, server account monitoring, file integrity monitoring, and log-based intrusion detection. The team used Halo’s API to integrate Halo with Jenkins and SaltStack, working with the CloudPassage customer success team to customize the Halo platform to their specific security policies. The lightweight Halo agent was chosen because it would not interrupt the processes that had been already established, but rather would integrate with and monitor his DevOps team’s CI/CD workflow.
Operational Impact
  • Security has been integrated into Centrify’s CI/CD pipeline.
  • Centrify has full visibility into all workloads and is able to ensure that their work is within compliance, well before any audits take place.
  • The CloudPassage Halo platform has been customized in order to prepare Centrify for the FedRAMP and SOC 2 compliance audits.
  • Centrify has used the Halo API to integrate with Jenkins and SaltStack, ensuring that the platform is fully integrated into all workloads and the work of their DevOps team.
Quantitative Benefit
  • Centrify is currently deploying CloudPassage Halo across hundreds of workloads.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.