<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://stage-community-sophos-comv11.telligenthosting.net/cfs-file/__key/system/syndication/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">Release Notes &amp;amp; News</title><subtitle type="html">Sophos Cloud Optix Blog</subtitle><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/atom</id><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog" /><link rel="self" type="application/atom+xml" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/atom" /><generator uri="http://telligent.com" version="12.1.9.35025">Telligent Community (Build: 12.1.9.35025)</generator><updated>2020-02-07T14:08:00Z</updated><entry><title>Changes to Sophos Cloud Optix Standard</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/changes-to-sophos-cloud-optix-standard" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/changes-to-sophos-cloud-optix-standard</id><published>2022-05-01T22:59:00Z</published><updated>2022-05-01T22:59:00Z</updated><content type="html">Sophos Cloud Optix is available in two licenses, Cloud Optix Advanced and Cloud Optix Standard. Cloud Optix Standard is included in the following Intercept X Advanced for Server licenses:

Intercept X Advanced for Server
Intercept X Advanced for Serv...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/changes-to-sophos-cloud-optix-standard"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=1193&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author></entry><entry><title>Cloud Optix Now Available in the EU</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-now-available-in-the-eu" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-now-available-in-the-eu</id><published>2022-04-22T09:07:00Z</published><updated>2022-04-22T09:07:00Z</updated><content type="html">We&amp;rsquo;re delighted to announce that Sophos Cloud Optix is now available from our Sophos Central EU data center in Germany.
New customers who choose Germany or Ireland as their hosting region for Sophos Central will now benefit from Cloud Optix in ...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-now-available-in-the-eu"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=1195&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author></entry><entry><title>Google Cloud Platform and Microsoft Azure Support for Sophos XDR now available</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/google-cloud-platform-and-microsoft-azure-support-for-sophos-xdr-now-available" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/google-cloud-platform-and-microsoft-azure-support-for-sophos-xdr-now-available</id><published>2021-12-14T14:50:00Z</published><updated>2021-12-14T14:50:00Z</updated><content type="html">Sophos Extended Detection and Response (XDR) now goes even further in the public cloud, adding Microsoft Azure (Azure) and Google Cloud Platform (GCP) activity logs alongside &lt;a href="https://news.sophos.com/en-us/2021/09/28/improving-threat-detection-and-response-in-aws-with-sophos-xdr/"&gt;Amazon Web Services (AWS)&lt;/a&gt; &amp;ndash; helping your security teams see the bigge...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/google-cloud-platform-and-microsoft-azure-support-for-sophos-xdr-now-available"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=1081&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Cloud Workload Protection" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bWorkload%2bProtection" /><category term="Cloud Security Posture Management" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bSecurity%2bPosture%2bManagement" /><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="CSPM" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/CSPM" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry><entry><title>Expansion of Sophos Cloud Workload Protection</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/expansion-of-sophos-cloud-workload-protection" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/expansion-of-sophos-cloud-workload-protection</id><published>2021-05-07T08:36:00Z</published><updated>2021-05-07T08:36:00Z</updated><content type="html">This release brings an exciting expansion to Sophos Cloud Workload Protection that sees Intercept X Advanced for Server incorporate CSPM with new Cloud Optix Standard capabilities. This addition extends protection beyond server workloads running in A...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/expansion-of-sophos-cloud-workload-protection"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=887&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Cloud Workload Protection" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bWorkload%2bProtection" /><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /><category term="Intercept X Advanced for Server" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Intercept%2bX%2bAdvanced%2bfor%2bServer" /></entry><entry><title>Cloud Optix Container Security</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-container-security" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-container-security</id><published>2021-03-08T10:07:00Z</published><updated>2021-03-08T10:07:00Z</updated><content type="html">The latest release for Sophos Cloud Optix features a range of exciting enhancements, including container image scanning to prevent&amp;nbsp;off-the-shelf container images from public registries&amp;nbsp;introducing Operating System vulnerabilities&amp;nbsp;into ...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-container-security"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=844&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry><entry><title>Cloud Optix Latest IAM Security Controls and More</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-latest-iam-security-controls-and-more" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-latest-iam-security-controls-and-more</id><published>2021-01-25T15:30:00Z</published><updated>2021-01-25T15:30:00Z</updated><content type="html">Now identify and correct over-privileged AWS IAM users, groups and roles with Cloud Optix, plus much more with the latest Sophos Cloud Optix updates.

January 2021

Azure inventory enhancement: App Service Plans:&amp;nbsp;The Cloud Optix inventory now pr...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-latest-iam-security-controls-and-more"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=805&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry><entry><title>Identify Sophos Firewalls and workload protection on AWS</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/identify-sophos-firewalls-and-workload-protection-on-aws" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/identify-sophos-firewalls-and-workload-protection-on-aws</id><published>2020-12-07T11:04:00Z</published><updated>2020-12-07T11:04:00Z</updated><content type="html">Monitor Sophos cloud security Amazon Web Services deployments is now easier than ever with the latest enhancements to Sophos Cloud Optix cloud security posture management service.

Sophos Firewalls
Sophos XG Firewall and Sophos UTM provide web applic...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/identify-sophos-firewalls-and-workload-protection-on-aws"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=770&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry><entry><title>Free Tool: Cloud Security Posture Management</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/free-tool-cloud-security-posture-management" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/free-tool-cloud-security-posture-management</id><published>2020-10-07T07:14:00Z</published><updated>2020-10-07T07:14:00Z</updated><content type="html">Cloud Optix, the Sophos Cloud Security Posture Management tool protects Amazon Web Services, Microsoft Azure, and Google Cloud Platform environments. Continually monitoring cloud service configurations, detecting suspicious activity, insecure deploym...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/free-tool-cloud-security-posture-management"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=738&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /></entry><entry><title>Optimize AWS and Azure Spend with Cloud Optix</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/optimize-aws-and-azure-spend-with-cloud-optix" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/optimize-aws-and-azure-spend-with-cloud-optix</id><published>2020-10-07T06:43:00Z</published><updated>2020-10-07T06:43:00Z</updated><content type="html">The latest release for Cloud Optix, cost optimization now allows customers to efficiently monitor Amazon Web Services and Microsoft Azure cloud costs in a single console. Providing organizations with the ability to manage security, compliance, and sp...(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/optimize-aws-and-azure-spend-with-cloud-optix"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=736&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry><entry><title>AWS On-boarding: New Quick-start Setup</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/aws-on-boarding-new-quick-start-setup" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/aws-on-boarding-new-quick-start-setup</id><published>2020-07-27T10:34:00Z</published><updated>2020-07-27T10:34:00Z</updated><content type="html">&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Cloud Optix Quick-start is the new, and easiest way to get started with the core CSPM features of Cloud Optix to see value in just a few clicks.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;a href="https://docs.sophos.com/pcg/optix/help/en-us/pcg/optix/tasks/AWSQuickStart.html"&gt;This Quick-start setup&lt;/a&gt; is a partial deployment option to get you up and running with Cloud Optix quickly, without needing to run scripts or create additional resources in your AWS environment. Launching the new Quick-start CloudFormation template customers simply create a read-only IAM role to authorize Cloud Optix to pull data using AWS APIs.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&lt;a href="/cfs-file/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-40/Cloud-Optix-Quick-Start-Setup.PNG"&gt;&lt;img src="/resized-image/__size/520x240/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-40/Cloud-Optix-Quick-Start-Setup.PNG" alt=" " /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Advanced features that require Cloud Optix to collect VPC Flow Logs and CloudTrail logs for analysis, are not supported by the Quick-start setup. To enable all features, use one of the full setup options available.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;"&gt;Learn more in the &lt;a href="https://docs.sophos.com/pcg/optix/help/en-us/pcg/optix/tasks/AWSQuickStart.html"&gt;setup guide for Cloud Optix Quick-start for Amazon Web Services&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=689&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry><entry><title>Cloud Optix new advanced search</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-new-advanced-search-1323837617" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-new-advanced-search-1323837617</id><published>2020-06-22T10:38:00Z</published><updated>2020-06-22T10:38:00Z</updated><content type="html">Search across Cloud Optix inventory data for hosts, containers, networks, storage services, IAM roles, and serverless functions, to investigate suspicious activity and insecure deployments, like never before.(&lt;a href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-new-advanced-search-1323837617"&gt;read more&lt;/a&gt;)&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=668&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>PaulMurray</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/paulmurray</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry><entry><title>Cloud Optix new asset inventory and threat investigation updates</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-new-asset-inventory-and-threat-investigation-updates" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-new-asset-inventory-and-threat-investigation-updates</id><published>2020-06-08T12:31:00Z</published><updated>2020-06-08T12:31:00Z</updated><content type="html">&lt;p&gt;Over the second quarter of 2020, a host of great enhancements have been added to the Cloud Optix service to enable organizations to harden their cloud security posture for AWS, Azure and Google Cloud platform. Check out these latest updates below &amp;ndash; all included with your existing Cloud Optix license.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong style="font-size:150%;"&gt;Inventory and topology visualization&amp;nbsp;&lt;/strong&gt;&lt;strong style="font-size:150%;"&gt;updates&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AWS Activity Logs visualization&lt;br /&gt;&lt;/strong&gt;In the Activity Logs section of the Inventory, for AWS, new activity logs visualizations allow you to easily analyse CloudTrail logs by geographic location to help investigate high risk events. The new graph views help to&amp;nbsp;visualize pertinent information to help customers identify potential abnormalities:
&lt;ul&gt;
&lt;li&gt;Geolocation of IP addresses from which&amp;nbsp;CloudTrail events have been generated&lt;/li&gt;
&lt;li&gt;Geolocation of IP addresses that are trusted in Security Group rules&lt;/li&gt;
&lt;li&gt;Number of Public S3 buckets&amp;nbsp;over time&lt;/li&gt;
&lt;li&gt;Number of EC2 instances (and Public EC2 instances) over time&lt;/li&gt;
&lt;li&gt;Number of EC2 instances in each AWS region (map view)&lt;/li&gt;
&lt;li&gt;Most active (top 10) IAM Users by number of CloudTrail events&lt;/li&gt;
&lt;li&gt;Top error types and top sources of errors&lt;br /&gt;&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;IAM Visualization enhancement (Lambda service)&lt;br /&gt;&lt;/strong&gt;IAM Visualization now include the AWS Lambda service to show IAM users, groups, and roles that have access to the Lambda service.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Visibility of NACLs from Topology Visualization&lt;/strong&gt;&amp;nbsp;&lt;br /&gt;From the AWS Topology Visualization, customers can now see details of NACL rules for a sub-net. Click on the route-table icon for a sub-net, this will show a new Network ACL section in the right-hand panel. Click on the NACL ID link to open a modal with the NACL rule details.&lt;br /&gt;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Inventory Azure IoT Hubs&lt;br /&gt;&lt;/strong&gt;New &amp;quot;IoT Hub&amp;quot; tab now available in the Network section of the Azure inventory. This provides details of the customer&amp;#39;s IoT Hubs&amp;nbsp;and identifies any hubs that are using legacy TLS 1.0/1.1&amp;nbsp;encryption (soon to be deprecated by Azure).&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Inventory of Azure Logic Apps&lt;br /&gt;&lt;/strong&gt;New &amp;quot;Logic Apps&amp;quot; tab now available in the Serverless section of the Azure inventory. This provides details of the customer&amp;#39;s Logic Apps and identifies any in public mode.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;strong&gt;Management and alerts&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;New email alerts&lt;br /&gt;&lt;/strong&gt;Customers can optionally choose to have Cloud Optix alerts sent via emails. This new capability is presented at&amp;nbsp;the bottom of the &amp;#39;Integrations&amp;#39; page. Email Alerts are off by default and can be configured by Super Admin users only.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Brandable reports for MSPs&lt;br /&gt;&lt;/strong&gt;Sophos Managed Service Provider Partners may now co-brand exportable PDF compliance reports for customers. This can be enabled for other types of account on-request.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;strong&gt;Cloud Optix API enhancements&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cloud Optix Inventory API additions&lt;br /&gt;&lt;/strong&gt;Cloud Optix API now includes the ability to pull inventory information for serverless functions and containers&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Multiple API keys for a single Cloud Optix account&lt;/strong&gt;&amp;nbsp;&lt;br /&gt;Cloud Optix Super Admin users can now create multiple keys for the Cloud Optix API (previously one key per customer account).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;strong&gt;Integration enhancements&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Amazon SNS integration&amp;nbsp;&lt;br /&gt;&lt;/strong&gt;Cloud Optix Amazon SNS integration now provides the environment&amp;#39;s account name and ID as &amp;#39;MessageAttributes&amp;#39; with each alert. This enables downstream filtering of alerts based on the environment (e.g. route alerts for a specific AWS account to a specific ticketing system).&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Jira integration (test button)&lt;br /&gt;&lt;/strong&gt;The Jira integration page now provides a &amp;#39;Test configuration&amp;#39; button to enable customers to test that their settings are correct, without having to wait for security alerts to generate new tickets to determine if the integration is configured correctly.&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=647&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry><entry><title>Cloud Optix April 2020 Feature Round-up</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-april-2020-feature-round-up" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/cloud-optix-april-2020-feature-round-up</id><published>2020-04-02T15:06:00Z</published><updated>2020-04-02T15:06:00Z</updated><content type="html">&lt;p&gt;Over the first quarter of 2020, a host of great enhancements have been added to the Cloud Optix service to enable organizations to harden their cloud security posture for AWS, Azure and Google Cloud platform. Check out these latest updates below &amp;ndash; all included with your existing Cloud Optix license.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;color:#055bb5;"&gt;&lt;strong&gt;Container Security&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Azure AKS support&lt;/strong&gt;&lt;br /&gt; Support for Azure Kubernetes Service (AKS) has now landed, &lt;a href="/products/sophos-cloud-optix/b/blog/posts/sophos-cloud-opitx-release-iam-visualization-and-much-more"&gt;adding to recent launches&lt;/a&gt; of Google&amp;rsquo;s managed Kubernetes Engine (GKE) in late 2019, and Amazon&amp;rsquo;s managed Elastic Kubernetes Service (EKS) in February 2020. This allows organizations to track container inventory and view complete topology visualizations.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="color:#055bb5;"&gt;&amp;nbsp;&lt;span style="font-size:150%;"&gt;&lt;strong&gt;CIS Certification &lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CIS Benchmarks certification for AWS, Azure, and GCP&lt;/strong&gt;&lt;br /&gt; Sophos Cloud Optix has now been &lt;a href="/products/sophos-cloud-optix/b/blog/posts/sophos-cloud-optix-awarded-cis-benchmarks-certification-for-aws-azure-and-gcp-1491645622"&gt;certified by CIS&lt;/a&gt; (Center for Internet Security) to accurately assess AWS, Azure and GCP environments based on best practices for secure configuration.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:150%;color:#055bb5;"&gt;&lt;strong&gt;Cloud Optix API Enhancements&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;New GET APIs for environments,&amp;nbsp;hosts and&amp;nbsp;user inventory&lt;/strong&gt; &lt;br /&gt; The Cloud Optix REST API can now be used to fetch inventory information (Environments, Hosts and Users) for AWS, Azure and GCP Platforms. View &lt;a href="https://optix.sophos.com/apiDocumentation"&gt;Cloud Optix API documentation here&lt;br /&gt;&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-size:150%;color:#055bb5;"&gt;&lt;strong&gt;AWS and Azure Integrations&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Amazon Inspector integration&lt;/strong&gt;&lt;br /&gt; Now view Amazon EC2 security findings detected by Amazon Inspector from Cloud Optix, including CVEs.&lt;br /&gt;&lt;br /&gt;Starting on the Cloud Optix Host Inventory, a new &amp;ldquo;Amazon Inspector&amp;rdquo; filter is now available. This will filter the inventory list to show EC2 instances for which there are Amazon Inspector findings. Click the Inspector icon in the &amp;quot;Actions&amp;quot; column to view findings for the last assessment run for that EC2 instance.&lt;br /&gt;&lt;br /&gt;While from the Network Topology Visualization page, a new &amp;quot;CVEs&amp;quot; filter allows customers to highlight EC2 instances that have CVEs discovered by Amazon Inspector, based on severity. Further details are presented in the right-hand column i.e. number of CVEs of each severity level, with links to see details of the CVEs on the findings page for the EC2 instance.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AWS IAM Access Analyzer integration&lt;br /&gt;&lt;/strong&gt;Visibility of cross-account and external access to AWS resources such as S3 buckets is now available via the cloud Optix console thanks to a new integration with the free AWS IAM Access Analyzer service. Go to Inventory &amp;gt; IAM &amp;gt; External Access (new tab). &lt;a href="/products/sophos-cloud-optix/b/blog/posts/sophos-cloud-opitx-release-iam-visualization-and-much-more"&gt;This further extends Cloud Optix IAM security monitoring announced earlier in 2020&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Change the default region for Azure on-boarding&lt;/strong&gt;&lt;br /&gt; Cloud Optix creates resources (e.g. Azure Function App) in the customer&amp;#39;s&amp;nbsp;default Azure region. Now, within &amp;#39;Custom Settings&amp;#39; on the &amp;#39;Add your cloud environment&amp;#39; page,&amp;nbsp;customers can choose to use a different Azure region if they&amp;nbsp;prefer.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="color:#055bb5;"&gt;&lt;strong&gt;&lt;span style="font-size:150%;"&gt;Cloud Optix Management Enhancements&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Search for instances with outbound traffic to a specified IP or port&amp;nbsp;&lt;/strong&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Now use the Cloud Optix global search bar to find virtual machines that Cloud Optix has monitored communicating outbound to a specified IP address or port.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Configurable tables&amp;nbsp;&lt;/strong&gt;&lt;br /&gt; Key lists and tables in the Cloud Optix console can now be configured by the customer to hide/show columns. Look for the &amp;#39;cogs&amp;#39; icon at the top of the table.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Partner ability to&amp;nbsp;hide Spend Monitoring&lt;br /&gt; &lt;/strong&gt;Partners now can now hide the Spend Monitor from selected accounts if required. This is a manual setting that should be requested via your Sophos account contact.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Lastly, a change to Admin roles for non-Central accounts&lt;/strong&gt;&lt;br /&gt; Customers with Cloud Optix accounts not yet managed via Sophos Central previously had &amp;#39;Admin&amp;#39; and &amp;#39;Read-only&amp;#39; administrator roles in the&amp;nbsp;Cloud Optix console. Consistent&amp;nbsp;with Sophos Central, we have added a new &amp;#39;Super Admin&amp;#39; role for these non-Central accounts.&lt;/p&gt;
&lt;p&gt;Now, only an administrator with the &amp;#39;Super Admin&amp;#39; role can invite&amp;nbsp;new users to the account and assign roles to users. All existing users with the &amp;#39;Admin&amp;#39; role previously, have been promoted to the &amp;#39;Super Admin&amp;#39; role to avoid any loss of functionality for existing administrators.&lt;/p&gt;
&lt;p&gt;In addition, when a new user is invited to join an account, the default role selected&amp;nbsp;is now &amp;#39;Read only&amp;#39;. However, the administrator (with Super Admin role) can choose to change this to &amp;#39;Admin&amp;#39; or &amp;#39;Super Admin&amp;#39; when inviting the user.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;color:#055bb5;"&gt;&lt;strong&gt;Coming Soon!&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;There&amp;rsquo;s plenty to get excited about next quarter (spoiler alert!). Here are just a few examples of exciting new features up our sleeve:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Sophos MSPs can soon co-brand Cloud Optix exportable compliance reports with their own company logo. &lt;span style="color:#055bb5;"&gt;Now in Preview.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;IaC scanning detection of secrets in templates. New policies will check for static secrets/credentials in Terraform templates for AWS and Azure. &lt;span style="color:#055bb5;"&gt;Now in Preview.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;Azure Logic Apps in the Serverless area of the inventory for Azure. Details will include: Name, Resource Group, Region, Last Modified, Trigger type, and State. &lt;span style="color:#055bb5;"&gt;Now in Preview.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=609&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry><entry><title>Sophos Cloud Optix Awarded CIS Benchmarks Certification for AWS, Azure, and GCP</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/sophos-cloud-optix-awarded-cis-benchmarks-certification-for-aws-azure-and-gcp-1491645622" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/sophos-cloud-optix-awarded-cis-benchmarks-certification-for-aws-azure-and-gcp-1491645622</id><published>2020-03-26T11:14:00Z</published><updated>2020-03-26T11:14:00Z</updated><content type="html">&lt;p&gt;&lt;a href="/cfs-file/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-40/7230.CIS_5F00_Benchmarks_5F00_Certified_5F00_RGB_5F00_TM.png"&gt;&lt;img src="/resized-image/__size/620x240/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-40/7230.CIS_5F00_Benchmarks_5F00_Certified_5F00_RGB_5F00_TM.png" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Sophos &lt;a href="https://www.cisecurity.org/partner/sophos/"&gt;Cloud Optix has now been certified by CIS&lt;/a&gt; (Center for Internet Security) to accurately assess AWS, Azure and GCP environments based on best practices for secure configuration.&lt;/p&gt;
&lt;p&gt;Developed through a unique consensus-based process comprised of cybersecurity professionals and subject matter experts around the world, CIS Benchmarks are recommended as industry-accepted system hardening standards and are used by organizations in meeting compliance requirements for Federal Information Security Management Act, PCI, Health Insurance Portability Accountability Act and other security requirements.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.cisecurity.org/benchmark/amazon_web_services/"&gt;Amazon Web Services CIS Benchmarks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cisecurity.org/benchmark/azure/"&gt;Microsoft Azure CIS Benchmarks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.cisecurity.org/benchmark/google_cloud_computing_platform/"&gt;Google Cloud Platform CIS Benchmarks&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;By certifying Cloud Optix with CIS, Sophos has demonstrated commitment to actively solve the foundational problem of ensuring secure configurations are used throughout AWS, Azure and GCP environments.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;"&gt;&lt;strong&gt;Not all certifications are equal&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;CIS Benchmark Certification is awarded on two profile levels. The intent of the Level 1 profile is to lower the attack surface of your organization while keeping machines usable and not hindering business functionality. The Level 2 profile is considered &amp;quot;defense in depth&amp;quot; and is intended for environments where security is paramount.&lt;/p&gt;
&lt;p&gt;Organizations should investigate whether a vendor offers the level of certification required for their industry, or compliance standard. Sophos has provided evidence that Cloud Optix can accurately report security recommendations in both level 1 and level 2 CIS Benchmark profiles.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=591&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry><entry><title>Sophos Cloud Optix Release: IAM Visualization and Much More</title><link rel="alternate" type="text/html" href="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/sophos-cloud-opitx-release-iam-visualization-and-much-more" /><id>https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/posts/sophos-cloud-opitx-release-iam-visualization-and-much-more</id><published>2020-02-07T14:08:00Z</published><updated>2020-02-07T14:08:00Z</updated><content type="html">&lt;p&gt;Today&amp;rsquo;s Cloud Optix release is packed with several new features to increase security and compliance of customer environments, including a breakthrough in IAM visualization.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;a href="/cfs-file/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-40/IAM-Visualization-Gif.gif"&gt;&lt;img src="/resized-image/__size/520x440/__key/communityserver-blogs-components-weblogfiles/00-00-00-00-40/IAM-Visualization-Gif.gif" alt=" " /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;background-color:#ffffff;color:#055bb5;"&gt;&lt;strong&gt;Improving security for anyone running workloads on public cloud&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Managing user roles, permissions, and role-based access to AWS services is an enormous challenge. The scale and interwoven nature of individual and group access to services means that organizations often a) simply can&amp;rsquo;t accurately see how their services can be accessed, and b) don&amp;rsquo;t proactively manage it &amp;ndash; creating an endless loop to a).&lt;/p&gt;
&lt;p&gt;And here&amp;rsquo;s the obvious punch line &amp;ndash; attackers will exploit that gap in security. &lt;a href="https://news.sophos.com/en-us/2019/11/08/exposed-private-amazon-s3-bucket-exposure/"&gt;We saw this happen in a recent high-profile public cloud attack&lt;/a&gt; that exploited overprivileged user access to access 40,000 Social Security numbers and 80,000 bank account numbers.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:inherit;color:#000000;"&gt;&lt;strong&gt;Breakthrough in IAM visualization&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Cloud Optix IAM Visualization is a breakthrough for organizations managing infrastructure on AWS. It enables customers to easily visualize the relationships between IAM roles, IAM users, and services. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;This innovative and differentiated new feature will allow customers to identify high risk users who have access to multiple services they rarely or never need. It helps answer questions like: Which IAM users in my AWS account have access to the S3 service, which might contain sensitive data? (either via assuming an IAM role, or directly with an in-line policy)? Which EC2 server instances can access the RDS service &amp;ndash; your customer database? And much more. This helps organizations reduce their attack surface in the cloud dramatically.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vimeo.com/390561810"&gt;https://vimeo.com/390561810&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#055bb5;font-size:150%;"&gt;&lt;strong&gt;Addressing a range of new threats&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;The latest security enhancements to Sophos Cloud Optix go even further to provide more depth than ever.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Detecting AWS, Azure, and GCP spend anomalies &lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Sophos Cloud Optix security-focused spend monitoring now makes daily and monthly cloud spend monitoring a breeze, identifying unusual activity indicative of abuse such as cryptojacking in AWS, Azure, and GCP cloud accounts. It highlights top services contributing to spend, allowing for faster decisions on whether increased spend equals malicious activity, and providing customizable spend threshold alerts for visibility.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://vimeo.com/388250873"&gt;https://vimeo.com/388250873&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Extending container security with Amazon EKS &amp;ndash; Managed Kubernetes Service&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Cloud Optix has provided automatic discovery of an organization&amp;rsquo;s assets across AWS, Microsoft Azure and Google Cloud Platform, and Infrastructure as Code environments for some time and added support for Native Kubernetes and Google&amp;rsquo;s managed Kubernetes Engine (GKE) in late 2019.&lt;/p&gt;
&lt;p&gt;And now support for Amazon&amp;rsquo;s managed Elastic Kubernetes Service (EKS) has landed. Azure AKS managed Kubernetes service hot on its heels and coming soon&lt;/p&gt;
&lt;p&gt;Amazon EKS nodes are now included in the topology visualization, as well as real-time inventory views of clusters, node groups, nodes, pods, containers, services, and more. While also enabling organizations to perform additional security benchmark checks on these container environments.&lt;/p&gt;
&lt;p&gt;Additional security benchmark checks now included in Sophos Cloud Optix best practice policy for AWS:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AR-1500:&amp;nbsp;Ensure private access is enabled for EKS Cluster&lt;/li&gt;
&lt;li&gt;AR-1501: Ensure public access is disabled from EKS Cluster&lt;/li&gt;
&lt;li&gt;AR-1502: Ensure EKS cluster Control Plane Security Group is only open to instances in its VPC&amp;nbsp;on port 443&lt;/li&gt;
&lt;li&gt;AR-1503: Ensure no two cluster Control Planes share a Security Group&lt;/li&gt;
&lt;li&gt;AR-1504: Ensure logging is enabled for Cluster Api Server&lt;/li&gt;
&lt;li&gt;AR-1505: Ensure logging is enabled for Cluster Audit&lt;/li&gt;
&lt;li&gt;AR-1506: Ensure logging is enabled for Authenticator&lt;/li&gt;
&lt;li&gt;AR-1507 Ensure logging is enabled for Controller Manager&lt;/li&gt;
&lt;li&gt;AR-1508: Ensure logging is enabled for Cluster Scheduler&amp;nbsp;&lt;/li&gt;
&lt;li&gt;AR-1509: Ensure EKS cluster Control Plane Security Group is not open to internet on any port&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="padding-left:30px;"&gt;&lt;strong&gt;Important notes:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;EKS clusters must be on-boarded to Cloud Optix &lt;strong&gt;after &lt;/strong&gt;the parent AWS account, using a separate on-boarding script. This script is available on the Add Environment &amp;gt; AWS page. Separate on-boarding is required because the standard permissions required to add an AWS account to Cloud Optix&amp;nbsp;do not apply to EKS clusters.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;The inventory will show partial information for EKS clusters before the EKS cluster is on-boarded. This is because certain information (i.e. cluster information) is retrieved using the existing API sync. The EKS cluster needs to be on-boarded using the separate script, to complete the population of the EKS inventory.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size:150%;color:#055bb5;"&gt;&lt;strong&gt;Additional updates&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;In addition to the headline updates, today&amp;rsquo;s Cloud Optix release is packed with several new features to increase security and compliance of customer environments:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Sophos Cloud&amp;nbsp;Optix has been certified by Center for Internet Security (CIS)&lt;/strong&gt; to accurately assess AWS and GCP system conformance with the security recommendations of the CIS Benchmark profile. By certifying Cloud Optix with CIS, Sophos has demonstrated its commitment to actively solve the foundational problem of ensuring secure standard configurations are used by customers. CIS Certified Security Software Products demonstrate a strong commitment to provide customers with the ability to ensure their assets are secured according to consensus-based best practice standards.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Superior public cloud traffic analysis&lt;/strong&gt;, helping organizations to analyze outbound traffic anomalies with visibility of destination IP addresses including ISP, organization, country, and region. &lt;a href="https://vimeo.com/387761014"&gt;Watch the video&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Azure VM Scale Sets inventory&lt;/strong&gt;, enabling customers to see that hosts are part of Scale Sets, and filter to see hosts within a specific VM Scale Set.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Add AWS environments using AWS CloudFormation (in preview)&lt;/strong&gt;, as an alternative to running a script using the AWS CLI, or Terraform.&lt;/li&gt;
&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="https://stage-community-sophos-comv11.telligenthosting.net/aggbug?PostID=553&amp;AppID=40&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</content><author><name>Rich Beckett</name><uri>https://stage-community-sophos-comV11.telligenthosting.net/members/rich-beckett</uri></author><category term="Public Cloud Security" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Public%2bCloud%2bSecurity" /><category term="Cloud Optix" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/Cloud%2bOptix" /><category term="release notes" scheme="https://stage-community-sophos-comv11.telligenthosting.net/sophos-cloud-optix/b/blog/archive/tags/release%2bnotes" /></entry></feed>