For the complete documentation index, see llms.txt. This page is also available as Markdown.

Features Introduced in December 2023

Learn what’s new on Prisma® Cloud in December 2023.

New Features Introduced in December 2023

Announcement

FEATURE

DESCRIPTION

Prisma Cloud Darwin Release

The Prisma Cloud Darwin Release is here for Prisma Cloud environments on app, app3, app.eu, app2.eu except app.gov. With the Code to Cloud™ intelligence capabilities in this release, your security and development teams can work together to reduce application risks and prevent breaches.

With this change, your tenant will be updated with the new intuitive user interface and rich set of security capabilities.

Connect with your Customer Success team for more details.

When you are upgraded to the Darwin release, refer to the Enterprise Edition documentation.

New Features

FEATURE

DESCRIPTION

IAM Policy Scanner Enhancement

Secure the Infrastructure

23.12.1

IAM Policy Scanner now includes enhancements to improve alert accuracy. This may result in some alerts briefly closing and reopening.

API Ingestions

The 23.12.1 release does not include any API Ingestions.

New Policies

NEW POLICIES

DESCRIPTION

New Policies to Configuration Build Policies

Starting from this release 2 new policies are added to Config policies of subtype Build. Here are the policies:

  • AWS CloudFront attached WAFv2 WebACL is not configured with AMR for Log4j Vulnerability

  • Software Composition Analysis (SCA) findings

In addition, 6 new policies integrated with CI/CD Risks are added by default to Prisma Cloud console and visible Governance.

  • BitBucket private repository made public.

  • Unrotated organization secrets in GitHub Actions.

  • Unrotated repository secrets in GitHub Actions.

  • CircleCI pipeline uses an unpinned container image.

  • Azure Pipelines uses an unpinned container image.

  • Secrets found in logs of a GitLab CI pipeline.

Impact- Impact- You will view policy violations for these policies on Prisma Cloud switcher Application Security > Projects in CI/CD Risks with CI/CD module enabled on Application Security > Settings.

Azure Virtual Machine (Linux) does not authenticate using the SSH keys

Changes - The policy name is being updated to reflect the latest changes.

Current Policy Name - Azure instance does not authenticate using the SSH keys

Impact- No impact on alerts.

Policy Updates

POLICY UPDATES

DESCRIPTION

Enhancements to Terraform GitHub and GitLab policies for Configuration Build Policies

Changes - The policy name is being updated to reflect the latest changes.

Current Policy Name - * GitHub Actions Environment Secrets not Encrypted * GitHub repository doesn’t have vulnerabilities alerts enabled * Gitlab project commits are not signed * Gitlab project does not prevent secrets * Gitlab project has less than 2 approvals

Impact- No impact on alerts.

New domain for Application Security Policy Reference Guide

Changes - Starting from this release all policy documentation will be available on Prisma Cloud Application Security Policy Reference.

Impact- No impact on alerts.

Azure Virtual Machine (Linux) does not authenticate using the SSH keys

Changes - The policy name is being updated to reflect the latest changes.

Current Policy Name - Azure instance does not authenticate using the SSH keys

Impact- No impact on alerts.

Policy Deletions

Docker GitHub repository is not private

Changes - This policy is deleted because the GitHub policies are modified in GitHub Policies.

Impact - No impact on alerts.

IAM Policy Updates

The following IAM out-of-the-box (OOTB) policies are updated in Prisma Cloud:

POLICY NAME

Current RQL

Updated RQL

Azure VM instance associated managed identity with Azure built-in roles of Contributor/Owner permissions

Changes— The policy name will be updated.

Current Name— Azure VM instance associated managed identity with Azure built-in roles of Contributor/Owner permissions

Updated Name— Azure VM instance associated managed identity with Azure built-in roles of Owner permissions

NA

AWS IAM policy allows Privilege escalation via PassRole & CodeBuild permissions

AWS IAM policy allows Privilege escalation via PassRole & CodeStar project permissions

AWS IAM policy allows Privilege escalation via PassRole & Data Pipeline permissions

AWS IAM policy allows Privilege escalation via PassRole & EC2 permissions

AWS IAM policy allows Privilege escalation via PassRole & Glue create job permissions

AWS IAM policy allows Privilege escalation via PassRole & Glue development endpoint permissions

AWS IAM policy allows Privilege escalation via PassRole & Glue update job permissions

AWS IAM policy allows Privilege escalation via PassRole & Lambda create & invoke Function permissions

AWS IAM policy allows Privilege escalation via PassRole & Lambda create Function & Event source mapping permissions

AWS IAM policy allows Privilege escalation via PassRole & Lambda create Function & add permissions

AWS IAM policy allows Privilege escalation via PassRole & SageMaker create processing job permissions

AWS IAM policy allows Privilege escalation via PassRole & SageMaker create training job permissions

New Compliance Benchmarks and Updates

COMPLIANCE BENCHMARK

DESCRIPTION

Support for MITRE ATT&CK Cloud IaaS v13 & v14

23.12.1

Prisma Cloud now supports the MITRE ATT&CK Cloud IaaS v13 & v14 compliance standard. This framework includes Att&ck Tactics, Techniques and sub-techniques that attackers can leverage to compromise cloud applications and infrastructure.

You can now view this built-in standard and the associated policies on the Compliance > Standards page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.

Changes in Existing Behavior

FEATURE

DESCRIPTION

Checkov update for SCA Security scanning

Secure the Source

23.12.1

Ensure Checkov or Bridgecrew CLI is updated to version 2.2.234 or later. Support for earlier versions is no longer supported.

Checkov CLI upgrade

Secure the Source

23.12.1

The Checkov CLI has been upgraded to Checkov 3.0. The upgrade impacts a few known changes:

  • Level Up: This capability has been removed. This change is non-disruptive and affects only Bridgecrew standalone sign ups.

  • Multi-Signatures: Multi-signatures in Python checks are being removed. This will only impact custom Python policies using this method.

  • Deprecating flags for Suppression and Fix: CLI command of --skip-fixes and --skip-suppressions are being deprecated. Instead --skip-download is a recommended command.

  • API Key Restriction and Repo-ID Parameter: Scans with API keys will now require the --repo-id parameter for repository scans allowing for easier platform mapping.

  • Enhanced Argument Handling: The way to specify frameworks and skip frameworks will align to other flags where multiple values can be listed (like --check). For example: --framework terraform,arm..

  • Pyston Docker Build Deprecation: The Pyston Docker build has been depreciated due to increasing complexities in support. The regular Checkov image will still be available for use.

REST API Updates

Deprecation Notices

Deprecate the aggregated and rest fields

The aggregated and rest macros from the webhook custom JSON alerts are being deprecated and replaced by AggregatedAlerts and Dropped macros respectively.

Deprecate AccountID macro from the Alerts payload

The AccountID macro in the Alerts payload is deprecated and replaced by the AccountIDs macro.

End of Support Notifications

Support for Cloud Native Network Segmentation (CNNS)

The ability to create CNNS policies that Defenders use to limit traffic from containers and hosts is being removed. The configuration settings on the console (Runtime Security > Defend > CNNS) and the corresponding APIs for CNNS will be removed in v32.00. Radar has a container and a host view, where you can view the network topology for your containerized apps and hosts respectively, and this will continue to be available.

Last updated

Was this helpful?