The cloud security acronyms, explained.
CSPM, CNAPP, CWPP, CIEM, DSPM, SSPM. Six acronyms, heavily overlapping marketing, and very little agreement on what any of them mean. These are vendor-neutral explanations of what each category actually covers — and, more usefully, what it does not.
CSPM vs CNAPP vs CWPP vs CIEM vs DSPM vs SSPM
The short version: five of these are components, and one is the umbrella.
| Acronym | Stands for | Question it answers |
|---|---|---|
| CSPM | Cloud Security Posture Management | Is the cloud infrastructure configured correctly? |
| CWPP | Cloud Workload Protection Platform | Are the running workloads patched and hardened? |
| CIEM | Cloud Infrastructure Entitlement Management | Who can actually do what, and do they still need it? |
| DSPM | Data Security Posture Management | Where is the sensitive data and who can reach it? |
| SSPM | SaaS Security Posture Management | Are M365, Workspace, GitHub and Snowflake locked down? |
| CNAPP | Cloud-Native Application Protection Platform | All of the above, correlated on one data model. |
All explainers
What is CSPM (Cloud Security Posture Management)?
CSPM continuously checks cloud infrastructure for misconfigurations and compliance drift. A plain-English explanation of how it works, what it catches, what it misses, and how it differs from CNAPP, CWPP and CIEM.
What is CNAPP (Cloud-Native Application Protection Platform)?
CNAPP unifies CSPM, CWPP, CIEM and DSPM on one data model instead of four consoles. What the category actually means, why it emerged, and how to tell a real CNAPP from a bundle of acquisitions.
What is CWPP (Cloud Workload Protection Platform)?
CWPP secures the workloads themselves — VMs, containers, serverless functions and hosts — rather than the cloud configuration around them. How it works, agent vs agentless, and how it differs from CSPM.
What is CIEM (Cloud Infrastructure Entitlement Management)?
CIEM resolves what identities can actually do in a cloud environment — after role chaining, SCPs and permission boundaries — and compares it against what they actually used. How it works and why policy review is not enough.
What is DSPM (Data Security Posture Management)?
DSPM finds where sensitive data lives across cloud storage, classifies it, and works out who can reach it. How classification works, why encryption-at-rest is not the answer, and how DSPM differs from CSPM and DLP.
What is SSPM (SaaS Security Posture Management)?
SSPM secures the SaaS platforms your company runs on — Microsoft 365, Google Workspace, GitHub, Snowflake — which cloud CSPM tools never scan. What it covers and why SaaS admin accounts are the softest target you own.
What is a cloud attack path?
An attack path is the chain of individually-minor findings that together reach something valuable. Why severity-ranked lists bury real risk, what a toxic combination is, and how choke points cut hundreds of paths at once.
What is agentless cloud security?
Agentless cloud security assesses infrastructure and workloads without installing software on them. How snapshot scanning works, what it can and cannot see, and an honest comparison with agent-based tooling.
What is cloud risk quantification?
Cloud risk quantification expresses security exposure as a probable dollar loss instead of a severity score. How the FAIR model works, what inputs it needs, and why a priced risk is what a board can actually act on.
What is a choke point in cloud security?
A choke point is a single resource that sits on many attack paths, so fixing it severs the most routes at once. How choke points are found, why they are the highest-leverage fix, and how they turn a huge backlog into a short list.
What is KSPM (Kubernetes Security Posture Management)?
KSPM continuously checks Kubernetes clusters for misconfiguration, unsafe RBAC and workload risk. How it works, what it catches that CSPM misses, and how it differs from container scanning and CWPP.
What is code security in the cloud?
Code security covers SAST, DAST, SCA, IaC and secret scanning. What each one catches, why fixing findings in the console alone makes them return, and how code and runtime connect.
What is cloud secrets management?
Cloud secrets management covers how credentials, keys and tokens are stored, accessed, rotated and audited. What goes wrong, why hardcoded secrets persist, and how key management differs from secrets management.
Stop reading. Start scanning.
Every category on this page is one engine on the Onam platform. Connect a read-only role and see all of them against your own cloud.