Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Fidelis Halo, a SaaS-based cloud security platform, automates cloud computing security controls. It also provides compliance across containers, servers, and IaaS within any public, private or hybrid cloud environment. Halo's extensive automation capabilities allow for faster workflows between InfoSec (DevOps) and Halo with over 20,000 pre-configured policies and more than 150 policy templates. These templates cover standards like PCI, CIS and HIPAA. The comprehensive, bidirectional Halo API, SDK, and toolkit automate security and compliance controls in your DevOps toolchain. This allows you to identify and correct critical vulnerabilities before they go into production. Free Halo Cloud Secure edition includes full access to the Halo Cloud Secure CSPM Service for up to 10 cloud service account across any mix of AWS and Azure. Get started now to automate your cloud security journey!
Description
Qualys Cloud Security offers a vulnerability analysis plug-in specifically designed for the CI/CD tool Jenkins, with plans to expand to additional platforms such as Bamboo, TeamCity, and CircleCI in the near future. Users can conveniently download these plug-ins straight from the container security module. This integration allows security teams to engage in the DevOps workflow, ensuring that vulnerable images are blocked from entering the system, while developers receive practical insights to address vulnerabilities effectively. It is possible to establish policies aimed at preventing the inclusion of vulnerable images in repositories, with settings adjustable based on factors like vulnerability severity and particular QIDs. The plug-in also provides an overview of the build, detailing vulnerabilities, information on software that can be patched, available fixed versions, and the specific image layers affected. Given that container infrastructure is inherently immutable, it is essential for containers to be consistent with the original images they are created from, thus necessitating rigorous security measures throughout the development lifecycle. By implementing these strategies, organizations can enhance their ability to maintain secure and compliant container environments.
API Access
Has API
Yes
API Access
Has API
Yes
Integrations
Docker
Yes
Jenkins
Yes
Kubernetes
Yes
Akitra Andromeda
No
Amazon EC2
Yes
Apache Mesos
Yes
Archer
Yes
BitSight
No
C1Risk
No
CircleCI
No
Integrations
Docker
Yes
Jenkins
Yes
Kubernetes
Yes
Akitra Andromeda
Yes
Amazon EC2
No
Apache Mesos
No
Archer
No
BitSight
Yes
C1Risk
Yes
CircleCI
Yes
Pricing Details
Free
Free full-featured Cloud Secure CSPM service for up to 10 IaaS accounts across any mix of supported cloud service providers. Includes one API key.
Free 15-day trial of the complete Halo platform and its add-on services for those considering Halo Essentials or Enterprise.
Free 15-day trial of the complete Halo platform and its add-on services for those considering Halo Essentials or Enterprise.
Free Trial
Yes
Free Version
Yes
Pricing Details
No price information available.
Free Trial
Yes
Free Version
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
Yes
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
Yes
Chromebook
No
Customer Support
Business Hours
Yes
Live Rep (24/7)
Yes
Online Support
No
Customer Support
Business Hours
No
Live Rep (24/7)
Yes
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
Yes
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
Fidelis Security
Founded
2002
Country
United States
Website
fidelissecurity.com/platforms/fidelis-halo/
Vendor Details
Company Name
Qualys
Founded
1999
Country
United States
Website
www.qualys.com/apps/container-security/
Product Features
Application Security
Analytics / Reporting
No
Open Source Component Monitoring
No
Source Code Analysis
No
Third-Party Tools Integration
Yes
Training Resources
No
Vulnerability Detection
Yes
Vulnerability Remediation
Yes
Audit
Alerts / Notifications
Yes
Audit Planning
No
Compliance Management
Yes
Dashboard
Yes
Exceptions Management
No
Forms Management
No
Issue Management
Yes
Mobile Access
No
Multi-Year Planning
No
Risk Assessment
No
Workflow Management
No
Cloud Security
Antivirus
No
Application Security
Yes
Behavioral Analytics
Yes
Encryption
No
Endpoint Management
No
Incident Management
No
Intrusion Detection System
Yes
Threat Intelligence
Yes
Two-Factor Authentication
Yes
Vulnerability Management
Yes
Cloud Workload Protection
Anomaly Detection
No
Asset Discovery
No
Cloud Gap Analysis
No
Cloud Registry
No
Data Loss Prevention (DLP)
No
Data Security
No
Governance
No
Logging & Reporting
No
Machine Learning
No
Security Audit
No
Workload Diversity
No
Container Security
Access Roles / Permissions
No
Application Performance Tracking
No
Centralized Policy Management
Yes
Container Stack Scanning
Yes
Image Vulnerability Detection
Yes
Reporting
No
Testing
No
View Container Metadata
Yes
Vulnerability Management
Asset Discovery
Yes
Asset Tagging
No
Network Scanning
Yes
Patch Management
No
Policy Management
Yes
Prioritization
Yes
Risk Management
No
Vulnerability Assessment
Yes
Web Scanning
No
Product Features
Container Security
Access Roles / Permissions
No
Application Performance Tracking
No
Centralized Policy Management
No
Container Stack Scanning
No
Image Vulnerability Detection
No
Reporting
No
Testing
No
View Container Metadata
No