Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

Fidelis Halo, a SaaS-based cloud security platform, automates cloud computing security controls. It also provides compliance across containers, servers, and IaaS within any public, private or hybrid cloud environment. Halo's extensive automation capabilities allow for faster workflows between InfoSec (DevOps) and Halo with over 20,000 pre-configured policies and more than 150 policy templates. These templates cover standards like PCI, CIS and HIPAA. The comprehensive, bidirectional Halo API, SDK, and toolkit automate security and compliance controls in your DevOps toolchain. This allows you to identify and correct critical vulnerabilities before they go into production. Free Halo Cloud Secure edition includes full access to the Halo Cloud Secure CSPM Service for up to 10 cloud service account across any mix of AWS and Azure. Get started now to automate your cloud security journey!

Description

Qualys Cloud Security offers a vulnerability analysis plug-in specifically designed for the CI/CD tool Jenkins, with plans to expand to additional platforms such as Bamboo, TeamCity, and CircleCI in the near future. Users can conveniently download these plug-ins straight from the container security module. This integration allows security teams to engage in the DevOps workflow, ensuring that vulnerable images are blocked from entering the system, while developers receive practical insights to address vulnerabilities effectively. It is possible to establish policies aimed at preventing the inclusion of vulnerable images in repositories, with settings adjustable based on factors like vulnerability severity and particular QIDs. The plug-in also provides an overview of the build, detailing vulnerabilities, information on software that can be patched, available fixed versions, and the specific image layers affected. Given that container infrastructure is inherently immutable, it is essential for containers to be consistent with the original images they are created from, thus necessitating rigorous security measures throughout the development lifecycle. By implementing these strategies, organizations can enhance their ability to maintain secure and compliant container environments.

API Access

Has API Yes 

API Access

Has API Yes 

Screenshots View All

Screenshots View All

Integrations

Docker Yes 
Jenkins Yes 
Kubernetes Yes 
Akitra Andromeda No 
Amazon EC2 Yes 
Apache Mesos Yes 
Archer Yes 
BitSight No 
C1Risk No 
CircleCI No 
Compyl No 
CyberDNA Command and Control Center No 
Git Yes 
Google Compute Engine Yes 
KernelCare Enterprise No 
Ping Identity Yes 
Polarity No 
Puppet Enterprise Yes 
Splunk SOAR Yes 
anecdotes No 

Integrations

Docker Yes 
Jenkins Yes 
Kubernetes Yes 
Akitra Andromeda Yes 
Amazon EC2 No 
Apache Mesos No 
Archer No 
BitSight Yes 
C1Risk Yes 
CircleCI Yes 
Compyl Yes 
CyberDNA Command and Control Center Yes 
Git No 
Google Compute Engine No 
KernelCare Enterprise Yes 
Ping Identity No 
Polarity Yes 
Puppet Enterprise No 
Splunk SOAR No 
anecdotes Yes 

Pricing Details

Free
Free full-featured Cloud Secure CSPM service for up to 10 IaaS accounts across any mix of supported cloud service providers. Includes one API key.

Free 15-day trial of the complete Halo platform and its add-on services for those considering Halo Essentials or Enterprise.
Free Trial Yes 
Free Version Yes 

Pricing Details

No price information available.
Free Trial Yes 
Free Version No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App Yes 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux Yes 
Chromebook No 

Customer Support

Business Hours Yes 
Live Rep (24/7) Yes 
Online Support No 

Customer Support

Business Hours No 
Live Rep (24/7) Yes 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

Fidelis Security

Founded

2002

Country

United States

Website

fidelissecurity.com/platforms/fidelis-halo/

Vendor Details

Company Name

Qualys

Founded

1999

Country

United States

Website

www.qualys.com/apps/container-security/

Product Features

Application Security

Analytics / Reporting No 
Open Source Component Monitoring No 
Source Code Analysis No 
Third-Party Tools Integration Yes 
Training Resources No 
Vulnerability Detection Yes 
Vulnerability Remediation Yes 

Audit

Alerts / Notifications Yes 
Audit Planning No 
Compliance Management Yes 
Dashboard Yes 
Exceptions Management No 
Forms Management No 
Issue Management Yes 
Mobile Access No 
Multi-Year Planning No 
Risk Assessment No 
Workflow Management No 

Cloud Security

Antivirus No 
Application Security Yes 
Behavioral Analytics Yes 
Encryption No 
Endpoint Management No 
Incident Management No 
Intrusion Detection System Yes 
Threat Intelligence Yes 
Two-Factor Authentication Yes 
Vulnerability Management Yes 

Cloud Workload Protection

Anomaly Detection No 
Asset Discovery No 
Cloud Gap Analysis No 
Cloud Registry No 
Data Loss Prevention (DLP) No 
Data Security No 
Governance No 
Logging & Reporting No 
Machine Learning No 
Security Audit No 
Workload Diversity No 

Container Security

Access Roles / Permissions No 
Application Performance Tracking No 
Centralized Policy Management Yes 
Container Stack Scanning Yes 
Image Vulnerability Detection Yes 
Reporting No 
Testing No 
View Container Metadata Yes 

Vulnerability Management

Asset Discovery Yes 
Asset Tagging No 
Network Scanning Yes 
Patch Management No 
Policy Management Yes 
Prioritization Yes 
Risk Management No 
Vulnerability Assessment Yes 
Web Scanning No 

Product Features

Container Security

Access Roles / Permissions No 
Application Performance Tracking No 
Centralized Policy Management No 
Container Stack Scanning No 
Image Vulnerability Detection No 
Reporting No 
Testing No 
View Container Metadata No 

Alternatives

Runecast  Reviews

Runecast

Runecast Solutions

Alternatives

DisruptOps Reviews

DisruptOps

FireMon
Aqua Reviews

Aqua

Aqua Security