For the complete documentation index, see llms.txt. This page is also available as Markdown.

Governance

Learn about the different types of Prisma Cloud policies and how to manage them.

In Prisma Cloud, a policy is a set of one or more constraints or conditions that must be adhered to. Prisma Cloud provides predefined policies for configurations and access controls that adhere to established security best practices such as PCI, GDPR, ISO 27001:2013,and NIST, and a larger set of policies that enable you to validate security best practices with an impact beyond regulatory compliance. These Prisma Cloud default policies cannot be modified.

In addition to these predefined policies, you can create custom policies to monitor for violations and enforce your own organizational standards. You can use the Default policies as templates to create custom policies. After you set up the policies, any new or existing resources that violate these policies are automatically detected.

Prisma Cloud includes out-of-the-box (OOTB) policies that are part of the Prisma Cloud Recommended Policies Pack.

Governance at a Glance

What do you want to do?

Start here

Monitor your resource configurations for potential policy violations

Monitor and flag audit events in your environment for potential policy violations

Assess the possible attack paths that exploit your environment in a graphical representation when an attack path policy is violated

Enforce IAM policies to your resources and regulate access to only authorized users

Enforce network rules to govern the behaviors of network devices

Identify unusual user activity in your environment

Detect misconfigurations and provide automated fixes for security issues seen across your integrated code repositories and pipelines.

Workload Protection policies

  • Create vulnerability policies for hosts and create host rules to apply these policies on

  • Create vulnerability policies for containers and create container rules to apply these policies on

  • Create vulnerability policies for Serverless functions

Detect potential threats across your environment

Last updated

Was this helpful?