Cloud Security Compare

Glossary

CNAPP buying glossary: 36 terms for comparing cloud security platforms

Cloud Security Compare editors · Matchups reviewed September 2026 · Editorial assessment

The short version

These are the terms that come up when two cloud security platforms are compared side by side: the product modules, the evidence behind a score, and the words used in quotes and contracts. Each definition is short and says why the term matters in a comparison.

Admission controller
A Kubernetes component that checks requests to the cluster API before objects such as pods are created, and can reject them. Security tools use one to stop noncompliant images from being deployed; Upwind lists a container admission controller among its modules.

Source: Kubernetes: admission controllers

Agentless scanning
Assessing cloud workloads without installing software on them, usually by reading cloud APIs or copies of disk storage. Vendors reach different resource types this way, so compare the lists rather than the label. More: Agentless vs agent-based.
AI-BOM
An AI bill of materials: a list of the models, AI services, datasets and packages an organization uses, kept so they can be secured and governed. Wiz and Upwind both use the term on their AI security pages.
AI-SPM
AI security posture management: checks aimed at AI workloads, covering which models and AI services exist, how they are configured, what data they can reach and who can call them. It is what our AI workload security criterion mostly measures. More: AI workload security in CNAPPs.
ASPM
Application security posture management: a combined view of findings from code scanners and the applications they belong to, used to decide which application risks to fix first. Wiz Code and CrowdStrike Falcon Cloud Security both list ASPM.
Attack path
A chain of weaknesses, such as an exposed workload, a vulnerable package and an over-permitted identity, that together let an attacker reach something valuable. A tool that shows paths lets a team fix the one link that breaks the chain instead of every finding on it. More: How CNAPPs rank risk.
Billable unit
What a vendor counts to set its price: hosts, workloads, resources or cloud accounts. Put two quotes on the same unit before comparing them. Microsoft Defender for Cloud counts some resources in groups; eight AWS Lambda functions make one billable unit.

Source: Microsoft Learn: Defender CSPM

CDR
Cloud detection and response: spotting threats in cloud activity, such as control-plane logs, identity events and workload behavior, with tools to investigate and contain them. Runtime-first vendors tend to lead here.
CIEM
Cloud infrastructure entitlement management: analysis of which people, services and machines can do what in your cloud accounts, aimed at removing permissions nobody uses.
CNAPP
Cloud-native application protection platform: one product that combines posture, workload, identity, data and code security for cloud estates. All nine platforms on this site are sold as CNAPPs, but each started from a different module, which is why their scores differ by criterion.
Code-to-cloud tracing
Linking a problem found in a running cloud resource back to the repository, file and owner that produced it, so the fix is made in code rather than in the console.
Container image scanning
Checking the layers of a container image for vulnerable packages, secrets and misconfigurations. Scanning in the build pipeline catches problems before they run; scanning in the registry or cluster catches images built earlier.
CSPM
Cloud security posture management: continuous checks of cloud account settings against security good practice and compliance frameworks. Often the first module a team buys, and the one where the free tiers sit.
CVE
Common Vulnerabilities and Exposures: the public program that gives each disclosed vulnerability an identifier in the form CVE, year, number. Nearly every vulnerability finding in a CNAPP refers to one, and scoring systems such as EPSS are keyed to it.

Source: CVE Program

CWPP
Cloud workload protection platform: protection for the workloads themselves, covering vulnerabilities, malware and suspicious behavior inside VMs, containers and serverless functions.
DAST
Dynamic application security testing: testing a running application from the outside by sending it requests, rather than reading its code. Upwind lists DAST among its modules.
DSPM
Data security posture management: finding and classifying sensitive data in cloud storage and databases, with a view of who and what can reach it.
eBPF
A Linux kernel technology that lets approved programs watch and act on system events without changing the kernel. Most runtime sensors in this category, including those from Wiz, Orca and Upwind, are built on it.
Editorial assessment
How scores on this site are produced: desk research from public vendor material, scored against a published rubric, with no hands-on testing. More: How to read these comparisons.
EPSS
The Exploit Prediction Scoring System, run by a special interest group at FIRST, estimates the probability that a published CVE will be exploited in the wild in the next 30 days. Some vendors use it to rank vulnerabilities; Aqua names it on its platform page.

Source: FIRST: EPSS

Falco
An open-source runtime detection project for hosts, containers and Kubernetes, created by Sysdig and now a CNCF graduated project. Sysdig Secure's runtime detection is built on it. Version 0.45.0 was released on 21 September 2026.

Source: Falco

FedRAMP
The US federal government's authorization program for cloud services. The authorization level matters if you are, or sell to, a US federal agency. Aqua lists FedRAMP High authorization.

Source: Aqua platform

GovRAMP
An authorization program for cloud services sold to US state and local government. Wiz says Wiz for Gov achieved GovRAMP High authorization on 10 September 2026, validated against NIST SP 800-53r5 controls.

Source: Wiz: GovRAMP High

Head-to-head
A comparison of two vendors on the same criteria, showing who is stronger on each one and by how much. On this site each head-to-head draws one tug-of-war bar per criterion. Example: Wiz vs Orca.
IaC scanning
Checking infrastructure-as-code templates, such as Terraform or CloudFormation files, for misconfigurations before they are applied, so a problem is fixed once in code rather than in every account it would reach.
MCP server
A service that exposes data or tools to AI applications through the Model Context Protocol, an open-source standard for connecting AI applications to external systems. Because MCP servers can act for a user, several CNAPPs now inventory and monitor them.

Source: Model Context Protocol

NIST SP 800-53
The catalog of security and privacy controls for information systems published by the US National Institute of Standards and Technology. Authorization programs for cloud services assess against it; Wiz says Wiz for Gov was validated against revision 5 controls for its GovRAMP High authorization.

Source: NIST SP 800-53 Rev. 5

Proof of concept (POC)
A time-boxed trial of a product in your own environment, scored against criteria agreed before it starts. More: How to run a CNAPP proof of concept.
Runtime sensor
Software installed on hosts or clusters that watches running workloads and can alert on or block malicious activity. Optional in agentless-first platforms and central in runtime-first ones. More: Rolling out a runtime sensor.
SAST
Static application security testing: analysing source code for security flaws without running it. Orca Security lists SAST among its application security scanners; SAST is not among Upwind's listed modules.
SBOM
A software bill of materials. CISA describes it as a nested inventory of the ingredients that make up software components. CNAPP code modules produce or read SBOMs to find vulnerable dependencies.

Source: CISA: SBOM

SCA
Software composition analysis: identifying the open-source and third-party packages an application uses and flagging those with known vulnerabilities or license issues. Its output is often recorded as an SBOM.
Secrets scanning
Searching code, images and disks for credentials such as API keys, tokens and passwords that should not be stored there. SentinelOne says its scanning validates 850+ secret types.
Shadow AI
AI models, services or applications in use without the security team's knowledge. How well a product finds them is one of the clearest differences between AI-SPM offerings.
Trivy
An open-source security scanner for container images, file systems, code repositories and infrastructure-as-code, maintained by Aqua Security under the Apache-2.0 license.

Source: Trivy

Weighted total
One score made by multiplying each criterion score by its weight and adding the results. Good for ranking; less useful for a decision than the criterion gaps it averages out. See the comparison matrix. Try your own weights on the score calculator.