For the complete documentation index, see llms.txt. This page is also available as Markdown.

Features Introduced in January 2024

Learn what’s new on Prisma® Cloud in January 2024.

Announcement

Feature

Description

Prisma Cloud Darwin Release

The Prisma Cloud Darwin Release is now available for all Prisma Cloud environments except app.cn and app.gov. With the Code to Cloud™ intelligence capabilities in this release, your security and development teams can work together to reduce application risks and prevent breaches.

With this change, your tenant will be updated with the new intuitive user interface and rich set of security capabilities. When you are upgraded to the Darwin release, refer to the Enterprise Edition documentation.

Contact your Prisma Cloud Customer Success team for more details.

New Features

Feature

Description

Compliance Dashboard

Secure the Infrastructure

24.1.2

Prisma Cloud’s out of the box dashboards now include a Compliance dashboard. Select Home > Dashboards > Compliance to view a snapshot of assets and their compliance status, compliance trends over time, and top compliance policies by failed status.

Update Code to Cloud Dashboard

Secure the Infrastructure

24.1.2

Prisma Cloud’s Latest Events tracker now provides redirections on the events from all phases of the Code Build Deploy Run (CBDR) cloud deployment lifecycle. Select any event from Home > Dashboards > Code to Cloud > Latest Events to immediately take action and investigate the risk or incident. Learn more about optimizing Prisma Cloud Dashboards.

Update Code to Cloud Dashboard

Secure the Infrastructure

24.1.2

Prisma Cloud’s Dashboards > Add Dashboard > Widget Selector now includes two additional widgets to help you easily report on your organization’s efficiency in responding to alerts. Widgets are currently available to System Administrators and include:

  • Alerts by MTTR - Displays alerts by severity and their mean time to resolution.

  • Alert by Resolution Reason - Displays the resolved alerts by their method of resolution.

Learn more about leveraging these widgets to create your own custom dashboards.

Send Ad hoc Alert Notifications to Email and Slack

Secure the Infrastructure

24.1.2

In addition to sending ad hoc Alert notifications to your Jira integration, now you can also send a notification to Email and Slack for any open alert. From Alerts > Overview, select an Alert ID link to view the details. From the Send To dropdown, select Email or Slack to send the notification.

Selecting View Alert from the Email received or the Slack channel will directly open the Alert Overview (for all Policies, except Attack Path) or the Evidence Graph (for Attack Path policies) in the Prisma Cloud console.

Unique Counts on the Prioritized Funnel

Secure the Runtime

24.1.2

In Vulnerability Management, the Prioritized Funnel widget now displays the unique CVE count instead of the total number of CVE occurrences.

Dashboard Widgets

Secure the Infrastructure

24.1.1

Prisma Cloud’s Dashboards > Add Dashboard > Widget Selector now includes eight additional widgets to help you create customized dashboards to track your organization’s key metrics. Widgets include:

  • Adoption Progress

  • Assets with Urgent Alerts

  • Anomalous Threats Detected

  • Top Custom Alerts Generated

  • Discovered vs. Secured Resources

  • Vulnerabilities Trend by Resource Type

  • Risks Burndown

  • Incidents Burndown

Terraform Module Scanning

Secure the Source

24.1.1

Prisma Cloud now supports rendering and scanning public, private, and locally cached Terraform modules. This capability enables you to analyze misconfigurations that may result from the module definition and the variables defined in the resource block. For more information, see Terraform Module Scanning.

Agentless Scanning

Secure the Runtime

24.1.1

Added agentless scanning support of encrypted volumes in Azure for the hub account mode.

Agentless Scanning

Secure the Runtime

24.1.1

Added agentless scanning hub account mode for Azure.

Vulnerability Management

Secure the Runtime

24.1.1

Added support for Debian Bullseye and Bookworm Security fixes.

Operating System Support

Secure the Runtime

24.1.1

Added support for OpenShift 4.14.

Vulnerability Management

Secure the Runtime

24.1.1

From 32.01, support is added to detect the Java version number when IBM Java is used during vulnerability management. This enhancement covers IBM Java version 1.8 and earlier. For IBM Java version 1.9 and later, support is partial and depends on the presence of the jdk/release file.

API Ingestions

Service

API Details

Azure Cache

24.1.2

azure-cache-redis-diagnostic-settings

Additional permissions required:

  • Microsoft.Cache/redis/read

  • Microsoft.Insights/DiagnosticSettings/Read

The Reader role includes the permissions.

Google Cloud VMware Engine

24.1.2

gcloud-vmware-engine-private-cloud

Additional permissions required:

  • vmwareengine.locations.list

  • vmwareengine.privateClouds.list

  • vmwareengine.privateClouds.getIamPolicy

The Viewer role includes the permissions.

Google Cloud VMware Engine

24.1.2

gcloud-vmware-engine-cluster

Additional permissions required:

  • vmwareengine.locations.list

  • vmwareengine.privateClouds.list

  • vmwareengine.clusters.list

  • vmwareengine.clusters.getIamPolicy

The Viewer role includes the permissions.

Google Cloud VMware Engine

24.1.2

gcloud-vmware-engine-hcx-activation-key

Additional permissions required:

  • vmwareengine.locations.list

  • vmwareengine.privateClouds.list

  • vmwareengine.hcxActivationKeys.list

  • vmwareengine.hcxActivationKeys.getIamPolicy

The Viewer role includes the permissions.

Google Cloud VMware Engine

24.1.2

gcloud-vmware-engine-subnet

Additional permissions required:

  • vmwareengine.locations.list

  • vmwareengine.privateClouds.list

  • vmwareengine.subnets.list

The Viewer role includes the permissions.

Google Vertex AI AIPlatform

24.1.2

gcloud-vertex-ai-aiplatform-custom-job

Additional permission required:

  • aiplatform.customJobs.list

The Viewer role includes the permission.

Google Vertex AI AIPlatform

24.1.2

gcloud-vertex-ai-aiplatform-endpoint

Additional permission required:

  • aiplatform.endpoints.list

The Viewer role includes the permission.

Google Vertex AI AIPlatform

24.1.2

gcloud-vertex-ai-aiplatform-training-pipeline

Additional permission required:

  • aiplatform.trainingPipelines.list

The Viewer role includes the permission.

Google Vertex AI AIPlatform

24.1.2

gcloud-vertex-ai-aiplatform-pipeline-job

Additional permission required:

  • aiplatform.pipelineJobs.list

The Viewer role includes the permission.

Google Speech to text

24.1.2

gcloud-speech-projects-locations-phraseSets-list

Additional permission required:

  • speech.phraseSets.list

The Viewer role includes the permission.

Google Speech to text

24.1.2

gcloud-speech-projects-locations-customClasses-list

Additional permission required:

  • speech.customClasses.list

The Viewer role includes the permission.

Google Cloud Composer

24.1.2

gcloud-composer-projects-locations-imageVersions-list

Additional permission required:

  • composer.imageversions.list

The Viewer role includes the permission.

Google Data Migration

24.1.2

gcloud-datamigration-projects-locations-privateConnections-list

Additional permissions required:

  • datamigration.privateconnections.list

  • datamigration.privateconnections.getIamPolicy

The Viewer role includes the permissions.

Google Data Migration

24.1.2

gcloud-datamigration-projects-locations-connectionProfiles-list

Additional permissions required:

  • datamigration.connectionprofiles.list

  • datamigration.connectionprofiles.getIamPolicy

The Viewer role includes the permissions.

Google Data Migration

24.1.2

gcloud-datamigration-projects-locations-conversionWorkspaces-list

Additional permissions required:

  • datamigration.conversionworkspaces.list

  • datamigration.conversionworkspaces.getIamPolicy

The Viewer role includes the permissions.

Google Data Migration

24.1.2

gcloud-datamigration-projects-locations-migrationJobs-list

Additional permissions required:

  • datamigration.migrationjobs.list

  • datamigration.migrationjobs.getIamPolicy

The Viewer role includes the permissions.

Update Google Deployment Manager

24.1.2

gcloud-deployment-manager-deployment-manifest

Prisma Cloud will update the Resource Name and Asset ID fields in the backend for gcloud-deployment-manager-deployment-manifest API. Due to this change, when you perform an RQL search query, you will be able to see a change in the Resource Name and Asset ID fields making it easier for you to identify the resources. Also, all the existing resources will be deleted, and then regenerated on the management console.

Existing alerts corresponding to this resource will be resolved as Resource_Deleted, and new alerts will be generated against any policy violations.

Impact— None. Once the resources for gcloud-deployment-manager-deployment-manifest resume ingesting data, you will notice the correct alert count in the console.

Update Google Cloud SQL

24.1.2

gcloud-sql-instances-list

Prisma Cloud has updated the gcloud-sql-instances-list API to exclude the settings.settingsVersion field from the JSON response because it changes frequently and does not add much value to the response.

OCI Service Catalog

24.1.1

oci-servicecatalog-catalog

Additional permissions required:

  • SERVICE_CATALOG_INSPECT

  • SERVICE_CATALOG_READ

You must update the Terraform template to enable the permissions.

Update OCI Data Safe

24.1.1

oci-data-safe-target-database

The resource JSON for this API no longer includes the timeUpdated field.

Update OCI Database

24.1.1

oci-database-autonomous-database

The resource JSON for this API no longer includes the actualUsedDataStorageSizeInTBs field.

Update OCI MySQL

24.1.1

oci-mysql-dbsystems

The resource JSON for this API no longer includes the timeUpdated field.

New Policies

Policies

Description

Azure Cognitive Services account not configured with private endpoint

24.1.2

Identifies Azure Cognitive Services accounts that are not configured with private endpoint. Private endpoints in Azure AI service resources allow clients on a virtual network to securely access data over Azure Private Link. Configuring a private endpoint enables access to traffic coming from only known networks and prevents access from malicious or unknown IP addresses which includes IP addresses within Azure. It is recommended to create private endpoint for secure communication for your Cognitive Services account.

Policy Severity— Medium

Policy Type— Config

Azure Cognitive Services account is not configured with managed identity

24.1.2

Identifies Azure Cognitive Services accounts that are not configured with managed identity. Managed identity can be used to authenticate to any service that supports Azure AD authentication, without having credentials in your code. Storing credentials in a code increases the threat surface in case of exploitation and also managed identities eliminate the need for developers to manage credentials. So as a security best practice, it is recommended to have the managed identity to your Cognitive Services account.

Policy Severity— Informational

Policy Type— Config

Azure Cognitive Services account configured with public network access

24.1.2

Identifies Azure Cognitive Services accounts configured with public network access. Overly permissive public network access allows access to resource through the internet using a public IP address. It is recommended to restrict IP ranges to allow access to your cognitive Services account and endpoint from specific public internet IP address ranges and is accessible only to restricted entities.

Policy Severity— High

Policy Type— Config

Attack Path Policies

New Attack Path policies are available. Log in to the Prisma Cloud console and filter for the list of available policies.

AWS S3 bucket encrypted using Customer Managed Key (CMK) with overly permissive policy

24.1.1

Identifies Amazon S3 buckets that use Customer Managed Keys (CMKs) for encryption that have a key policy overly permissive. Amazon S3 bucket encryption key overly permissive can result in the exposure of sensitive data and potential compliance violations. As a security best practice, It is recommended to follow the principle of least privilege ensuring that the KMS key policy does not have all the permissions to be able to complete a malicious action.

Policy Severity— Medium

Policy Type— Config

AWS S3 bucket encrypted with Customer Managed Key (CMK) is not enabled for regular rotation

24.1.1

Identifies Amazon S3 buckets that use Customer Managed Keys (CMKs) for encryption but are not enabled with key rotation. Amazon S3 bucket encryption key rotation failure can result in prolonged exposure of sensitive data and potential compliance violations. As a security best practice, it is important to rotate these keys periodically. This ensures that if the keys are compromised, the data in the underlying service remains secure with the new keys.

Policy Severity— Informational

Policy Type— Config

AWS RDS database instance encrypted with Customer Managed Key (CMK) is not enabled for regular rotation

24.1.1

Identifies Amazon RDS instances that use Customer Managed Keys (CMKs) for encryption but are not enabled with key rotation. Amazon RDS instance encryption key rotation failure can result in prolonged exposure of sensitive data and potential compliance violations. As a security best practice, it is important to periodically rotate these keys. This ensures that if the keys are compromised, the data in the underlying service remains secure with the new keys.

Policy Severity— Informational

Policy Type— Config

Azure Storage account encrypted by an encryption key configured access policy with privileged operations

24.1.1

Identifies Azure Storage accounts which are encrypted by an encryption key configured access policy with privileged operations. Encryption keys should be kept confidential and only accessible to authorized entity with limited operation access. Allowing privileged access to an encryption key also allows to alter/delete the data that is encrypted by it, making the data more easily accessible. It is recommended to have restricted access policies to an encryption key so that only authorized entities can access it with limited operation access.

Policy Severity— Medium

Policy Type— Config

Azure Storage account encrypted by an encryption key that is not rotated regularly

24.1.1

Identifies Azure Storage accounts which are encrypted by an encryption key that is not rotated regularly. As a security best practice, it is important to rotate the keys periodically so that if the keys are compromised, the data in the underlying service is still secure with the new keys.

Policy Severity— Informational

Policy Type— Config

Azure AKS cluster configured with overly permissive API server access

24.1.1

Identifies AKS clusters configured with overly permissive API server access. In Kubernetes, the API server receives requests to perform actions in the cluster such as to create resources or scale the number of nodes. To enhance cluster security and minimize attacks, the API server should only be accessible from a limited set of IP address ranges. These IP ranges allow defined IP address ranges to communicate with the API server. A request made to the API server from an IP address that is not part of these authorized IP ranges is blocked. It is recommended to configure AKS cluster with defined IP address ranges to communicate with the API server.

Policy Severity— Low

Policy Type— Config

Azure Machine learning workspace configured with overly permissive network access

24.1.1

Identifies Machine learning workspaces configured with overly permissive network access. Overly permissive public network access allows access to resource through the internet using a public IP address. It is recommended to restrict IP ranges to allow access to your workspace and endpoint from specific public internet IP address ranges and is accessible only to restricted entities.

Policy Severity— High

Policy Type— Config

New CI/CD Configuration Build Policies

24.1.1

Added the following default CI/CD policies within the Build subtype of Configuration policies under Governance for enhanced continuous integration and deployment pipeline security.

Azure Repo Policies

  • Potential dependency confusion in an Azure Repos repository due to package name or scope available in registry

  • Deprecated package used in NPM project of an Azure Repos repository

  • Missing ‘.npmrc’ file in Azure Repos repository

  • Possible Python typosquatting detected in an Azure Repos repository

  • Secret exposed in registry URL within ‘.npmrc’ file of an Azure Repos repository

  • Unencrypted channel used by ‘.npmrc’ file of an Azure Repos repository to download dependencies from proxy

  • Azure Pipelines uses an unpinned container image

  • Secret exposed in proxy URL within ‘.npmrc’ file of an Azure Repos repository

  • Deprecated package used in NPM project of a Bitbucket repository

Bitbucket Policies

  • Missing ‘.npmrc’ file in Bitbucket repository

  • Possible Python typosquatting detected in a Bitbucket repository

  • Potential dependency confusion in a Bitbucket repository due to package name or scope available in registry

  • Private Bitbucket repository made public

  • Secret exposed in proxy URL within ‘.npmrc’ file of a Bitbucket repository

  • Secret exposed in registry URL within ‘.npmrc’ file of a Bitbucket repository

  • Unencrypted channel used by ‘.npmrc’ file of a Bitbucket repository to download dependencies from proxy

  • Unencrypted channel used by ‘.npmrc’ file of a Bitbucket repository to download dependencies from registry

CircleCI Policies

  • CircleCI pipeline uses an unpinned container image

GitHub Policies

  • Deprecated package used in NPM project of a GitHub repository

  • Missing ‘.npmrc’ file in GitHub repository

  • Possible Python typosquatting detected in a GitHub repository

  • Potential dependency confusion in a GitHub repository due to package name or scope available in registry

  • Secret exposed in proxy URL within ‘.npmrc’ file of a GitHub repository

  • Secret exposed in registry URL within ‘.npmrc’ file of a GitHub repository

  • Unencrypted channel used by ‘.npmrc’ file of a GitHub repository to download dependencies from proxy

  • Unencrypted channel used by ‘.npmrc’ file of a GitHub repository to download dependencies from registry

  • Unrotated organization secrets in GitHub Actions

  • Unrotated repository secrets in GitHub Actions

GitLab Policies

  • Deprecated package used in NPM project of a GitLab repository

  • Missing ‘.npmrc’ file in GitLab repository

  • Possible Python typosquatting detected in a GitLab repository

  • Potential dependency confusion in a GitLab repository due to package name or scope available in registry

  • Secrets found in logs of a GitLab CI pipeline

  • Secret exposed in proxy URL within ‘.npmrc’ file of a GitLab repository

  • Secret exposed in registry URL within ‘.npmrc’ file of a GitLab repository

  • Unencrypted channel used by ‘.npmrc’ file of a GitLab repository to download dependencies from proxy

  • Unencrypted channel used by ‘.npmrc’ file of a GitLab repository to download dependencies from registry

Policy Updates

Policy Updates

Description

Policy Updates—RQL

Azure Function App authentication is off

24.1.2

Changes— The policy RQL is updated to only report Function Apps for which authentication is disabled. Azure Function App Authentication prevents anonymous HTTP requests from reaching the API app or authenticates token-enabled requests before they reach the API app, but not the Logic app or Web App resources created in Azure.

Severity— Low

Policy Type— Config

Current RQL—

Updated RQL—

Impact— Low. Existing alerts generated for Logic App and Web App will be resolved and new alerts will be generated.

AWS Elasticsearch domain publicly accessible

24.1.1

Changes— The policy RQL is updated to check for vpc-options instead of vpc.endpoints.

Severity— Medium

Policy Type— Config

Current RQL—

Updated RQL—

Impact— No impact on alerts.

Azure Key Vault Firewall is not enabled

24.1.1

Changes— The policy RQL is updated to not trigger alerts when the public access is disabled.

Severity— Low

Policy Type— Config

Current RQL—

Updated RQL—

Impact— Low. Existing alerts which were triggered when the public access was disabled will be resolved.

Azure Storage account is not configured with private endpoint connection

24.1.1

Changes— The policy RQL has been updated to report azure storage account which allow all networks with IPrule and VirtualNetworkRule not being empty.

Severity— Medium

Policy Type— Config

Current RQL—

Updated RQL—

Impact— Low. New alerts will be generated when the IPrule and VirtualNetworkRule are retained.

AWS S3 bucket publicly readable

24.1.1

Changes— The policy remediation steps and RQL will be updated to check for Authenticated User with read access.

Policy Type— Config

Severity— High

Current RQL—

Updated RQL—

Impact— Low. New alerts will be generated when Authenticated users have read permissions.

Policy Updates—Metadata

GCP VM instance using a default service account with full access to all Cloud APIs

24.1.1

Changes— The policy name, description and remediation details are updated.

Current Policy Name— GCP VM instance using a default service account with full access to all Cloud APIs

Updated Policy Name— GCP VM instance using a default service account with Cloud Platform access scope

Current Policy Description— This policy identifies the GCP VM instances which are using a default service account with full access to all Cloud APIs. To compliant with the principle of least privileges and prevent potential privilege escalation it is recommended that instances are not assigned to default service account 'Compute Engine default service account' with scope 'Allow full access to all Cloud APIs'.

Updated Policy Description— This policy identifies the GCP VM instances that are using a default service account with cloud-platform access scope. To compliant with the principle of least privileges and prevent potential privilege escalation it is recommended that instances are not assigned to default service account 'Compute Engine default service account' with scope 'cloud-platform'.

Severity— Medium

Policy Type— Config

Impact— No impact on alerts.

Policy Deletion

Azure Policies Deletion

24.1.1

Changes— Azure has deprecated Azure Storage classic metrics. Due to this change the following associated policies have been deleted:

  • Azure storage account logging (Classic Diagnostic Setting) for queues is disabled (fde9482f-3ac2-43f6-bda2-bf2013074acd)

  • Azure storage account logging (Classic Diagnostic Setting) for blobs is disabled (85a4a77f-0d46-4c3d-ae8c-37d945a0b44e)

  • Azure storage account logging (Classic Diagnostic Setting) for tables is disabled (f4784022-48f3-4f3b-bc16-2b7fef56aea3)

Impact— Low. Existing alerts are resolved as Policy_Deleted.

Policy Updates - IAM

tt:[24.1.2]

The following IAM policy has updated RQL.

Policy Name

Old RQL

New RQL

AWS cross-account resource access through IAM policies

tt:[24.1.1]

The following IAM policies has updated names and description.

Old Policy Name

Old Policy Description

New Policy Name

New Policy Description

AWS EC2 instance with IAM permissions management access level

This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.AWS IAM permissions management access level that are risky for AWS EC2 instances. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of permissions management access to minimize security risks.

AWS EC2 Instance with IAM policy management permissions

This policy identifies IAM permissions that allow EC2 instances to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

AWS EC2 instance with IAM write access level

This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS EC2 Instance with IAM write permissions

This policy identifies IAM permissions that allow EC2 instances to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

AWS EC2 instance with org write access level

This policy identifies org write access that is defined as risky permissions. Ensure that the AWS EC2 instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS EC2 Instance with AWS Organization management permissions

This policy identifies IAM permissions that allow EC2 instances to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

AWS Lambda Function with IAM permissions management access level

This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS Lambda Function instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS Lambda Function with IAM policy management permissions

This policy identifies IAM permissions that allow Lambda functions to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

AWS Lambda Function with IAM write access level

This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS Lambda Function instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS Lambda Function with IAM write permissions

This policy identifies IAM permissions that allow Lambda functions to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

AWS Lambda Function with org write access level

This policy identifies org write access that is defined as risky permissions. Ensure that the AWS Lambda Function instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS Lambda Function with AWS Organization management permissions

This policy identifies IAM permissions that allow Lambda functions to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

Okta User with IAM permissions management access level

This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the Okta Users in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS Okta User with IAM policy management permissions

This policy identifies IAM permissions that allow Okta users to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

Okta User with IAM write access level

This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the Okta Users in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS Okta User with IAM write permissions

This policy identifies IAM permissions that allow Okta users to perform write operations for IAM, such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

Okta User with org write access level

This policy identifies org write access that is defined as risky permissions. Ensure that the Okta Users in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS Okta User with AWS Organization management permissions

This policy identifies IAM permissions that allow Okta users to manage AWS Organizations, such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

ECS Task Definition with IAM permissions management access level

This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS ECS Task Definition instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS ECS Task Definition with IAM policy management permissions

This policy identifies IAM permissions that allow ECS task definitions to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

ECS Task Definition with IAM write access level

This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS ECS Task Definition instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks

AWS ECS Task Definition with IAM write permissions

This policy identifies IAM permissions that allow ECS task definitions to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

ECS Task Definition with org write access level

This policy identifies org write access that is defined as risky permissions. Ensure that the AWS ECS Task Definition instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS ECS Task Definition with AWS Organization management permissions

This policy identifies IAM permissions that allow ECS task definitions to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

IAM User with IAM permissions management access level

This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the IAM Users in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS IAM User with IAM policy management permissions

This policy identifies IAM permissions that allow IAM users to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

IAM User with IAM write access level

This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the IAM Users in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS IAM User with IAM write permissions

This policy identifies IAM permissions that allow IAM users to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

IAM User with org write access level

This policy identifies org write access that is defined as risky permissions. Ensure that the IAM Users in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS IAM User with AWS Organization management permissions

This policy identifies IAM permissions that allow IAM users to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

Elasticbeanstalk Platform with IAM permissions management access level

This policy identifies IAM permissions management access that is defined as risky permissions. Ensure that the AWS Elasticbeanstalk Platform instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS Elastic Beanstalk Platform with IAM policy management permissions

This policy identifies IAM permissions that allows an Elastic Beanstalk Platform to manage IAM policies, such as creating, deleting, or attaching IAM policies to identities, roles, or groups. IAM policy management permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

Elasticbeanstalk Platform with IAM write access level

This policy identifies IAM write permissions that are defined as risky permissions. Ensure that the AWS Elasticbeanstalk Platform instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS Elastic Beanstalk Platform with IAM write permissions

This policy identifies IAM permissions that allows an Elastic Beanstalk Platform to perform write operations for IAM. such as creating, deleting, updating access keys, users, groups, and roles. IAM write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

Elasticbeanstalk Platform with org write access level

This policy identifies org write access that is defined as risky permissions. Ensure that the AWS Elasticbeanstalk Platform instances provisioned in your AWS account don’t have a risky set of write permissions to minimize security risks.

AWS Elastic Beanstalk Platform with AWS Organization management permissions

This policy identifies IAM permissions that allows an Elastic Beanstalk Platform to manage AWS Organizations such as creating, deleting, updating AWS Organizations, accounts and Org level policies, features, and services. AWS Organization write permissions are very risky and should only be used under very strict controls. Unnecessary usage of these permissions can significantly increase your attack surface and make it easier for attackers to compromise your AWS environment.

New Compliance Benchmarks and Updates

Compliance Benchmark

Description

Support for RBI Compliance Standard

24.1.2

Prisma Cloud now supports the Reserve Bank of India (RBI) compliance standard. This comprehensive framework mandates a proactive stance on cybersecurity, ensuring secure networks and databases, constant protection of customer information, and immediate response plans for security incidents.

You can now view this built-in standard and the associated policies on Compliance > Standards. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.

Support for SEBI Compliance Standard

24.1.2

Prisma Cloud now supports the Securities and Exchange Board of India (SEBI) compliance standard. This regulation lays down the listing obligations of companies that have listed their securities on stock exchanges in India. It also provides for the disclosure requirements that these companies must comply with.

You can now view this built-in standard and the associated policies on Compliance > Standards. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.

Update Policy Mappings for Azure CIS 2.0

24.1.2

The following compliance requirements in Azure CIS 2.0 Level 1 and Azure CIS 2.0 Level 2 are updated with new mappings:

  • Azure CIS 2.0 Level 1

  • Database Services

  • Microsoft Defender

  • Storage Accounts

  • Azure CIS 2.0 Level 2

  • Database Services

  • Microsoft Defender

Impact— Compliance score can vary as new mappings are introduced.

REST API Updates

Change

Description

New Alerts API

24.1.2

A new Create On Demand Notification endpoint is now available. It allows you to configure and share alert notifications through Email, Jira, or Slack.

New Widget APIs

24.1.2

The following new APIs are added to get the data from some of the widgets used to create custom dashboards:

Unified Vulnerability Explorer API

24.1.2

A new Get Prioritized Vulnerabilities V2 API is now available. It allows to view the top priority vulnerabilities along with the number of assets in which they occur.

Update Policy APIs

24.1.2

The policy APIs now support the following types and subtypes:

  • Policy types - malware and grayware

  • Policy subtypes - host and container_image

IAM APIs

24.1.1

New versions of IAM endpoints are now available to get permissions, access details, and query suggestions. A few other new endpoints are also added to the IAM category to get the least privilege access details and remediation command.

Widget APIs

24.1.1

The following new APIs are added to get the data from some of the widgets used to create custom dashboards:

Unified Vulnerability Explorer APIs

24.1.1

New APIs are available in the Unified Vulnerability Explorer category to get the list of vulnerabilities based on CVE, priority, stage, RQL, and so on. In addition, you have endpoints to get the remediation status and create a remediation request.

Background Job APIs

24.1.1

The following new endpoints are available to get background job reports:

Add a New Collection

24.1.1

Collections that were added using the Add a New Collection did not display as expected in the Console. This issue has been resolved by making all request body fields, except name, optional. Any field that is not provided will default to the wildcard value '*'.

Deprecation Notices

Change

Description

End of Life (EOL) for Prisma Cloud Microsegmentation in 24.1.2

24.1.2

EOL was first announced in 23.9.2

The Prisma Cloud Microsegmentation module was announced as End-of-Sale effective 31 August, 2022. As of the 24.1.2 release, the Microsegmentation solution is disconnected and any active agents will no longer work.

Make sure to uninstall all instances of the Enforcer (the Microsegmentation agent) deployed in your environment, as these agents will no longer enforce any security policies on traffic on or across your hosts.

app.sg Stack Decommissioned for Prisma Cloud Data Security

Secure the Infrastructure

24.1.1

You will no longer be able to use the app.sg stack for Data Security since it’s being decommissioned. If you want to use Data Security, contact your Prisma Cloud customer support representative.

Support for BridgecrewCLI

Secure the Source

24.1.1

BridgecrewCLI including GitHub Action, CircleCI Orb, and container have been deprecated. You can continue using Checkov and its compatible plugins without any disruptions.

Alerts

Secure the Runtime

24.1.1

Deprecated the AccountID and Cluster macros used in alerts. This removes the AccountID and Cluster fields in the following alerts using the macros.

  • Webhook

  • AWS SQS

  • Prisma Cortex Alert

  • Splunk

Last updated

Was this helpful?