tencent cloud

Cloud Security Center

Editions and Applicable Scenarios

Baixar
Modo Foco
Tamanho da Fonte
Última atualização: 2026-09-11 16:57:23
Traduzido por IA

Feature Set Positioning Overview

Feature Set
Core Positioning
Price
Suitable Enterprise Type
CWPP (Professional Edition)
Basic host security hardening
12 USD per host per month
SMBs primarily using CVM and requiring basic protection
CWPP (Flagship Edition)
Complete CWPP protection + compliance
27 USD per host per month
Medium and large enterprises with international security standard compliance requirements
Container security
Cluster (node + cluster) hardening + compliance
Node security: 27 USD per host per month
Cluster security: 6.75 USD per core per month
Medium and large enterprises that have adopted containers/K8s at scale and need node hardening+cluster runtime protection+compliance baselines
Container image risk
Image security risk governance
USD 0.1/image
Medium and large enterprises with CI/CD image build processes that need to block image-layer security risks before launch
The following modules can be purchased separately and additively across all paid editions, with no edition restrictions:
Module
Benefit
Recommended Use Case
Cloud Product Configuration Check
Check for misconfigurations in cloud products such as databases, buckets, and security groups.
Enterprises with a wide variety of cloud products and high configuration risks
Data Security Posture
Sort out sensitive data distribution and data compliance risks.
Enterprises with Data Security Law/Personal Information Protection Law compliance requirements
Log Analysis
Retain raw logs, perform deep search, and conduct compliance audit.
Enterprises with compliance log retention requirements or in-depth traceability needs
Application Protection
Web application layer security protection
Scenarios with intense security confrontation, and enterprise businesses requiring application-layer protection
TencentCloud API Risk Governance
Manage API exposure surface and perform deep checking for authentication risks
Enterprises with numerous APIs and complex services

Edition Feature Comparison Overview

Module
Free Edition
CWPP (Professional Edition)
CWPP (Flagship Edition)
Container Security Service (TCSS)
Asset Center (Hosts/Containers/Cloud Assets)
Emergency Vulnerability Detection
Alarm Center (Remote Login)
AI Workbench
One-Click Fix for Linux/Windows/Web-CMS Vulnerabilities
Baseline Detection of Weak Passwords
Alarm Center (Anti-Virus)
Virtual Patching for Vulnerabilities
Application Vulnerability Detection
Compliance baselines such as international security standards
Cloud Perimeter Analysis
Open beta
Open beta
AI Agent Security
Ransomware Detection
Core File Monitoring
Alarm Center (Advanced Host Threat Detection)
Container Runtime Threat Detection
K8S API Security Audit
IaC Risk Governance
Container Compliance Baseline Governance
Cloud Product Configuration Check
On-demand purchase
On-demand purchase
On-demand purchase
On-demand purchase
Data Security Posture
On-demand purchase
On-demand purchase
On-demand purchase
On-demand purchase
Log Analysis
On-demand purchase
On-demand purchase
On-demand purchase
On-demand purchase
Application Protection
On-demand purchase
On-demand purchase
On-demand purchase
On-demand purchase
TencentCloud API Risk Governance
On-demand purchase
On-demand purchase
On-demand purchase
On-demand purchase
Container image risk
On-demand purchase
On-demand purchase
On-demand purchase
On-demand purchase

Detailed Explanation of Editions

CWPP (Professional Edition)

Enterprise Characteristics

Cloud assets primarily consist of CVMs.
It faces basic intrusion threats such as brute-force attacks, trojans, and abnormal logins.
In the early stages of security construction, a core host protection baseline must be established at a reasonable cost.
Weak password management.

Core Capabilities Added Compared to the Free Edition

Capability
Specific Description
One-Click Vulnerability Fixing
Supports one-click fix for Linux / Windows / Web-CMS vulnerabilities.
Application Vulnerability Detection
Comprehensively checking for weak passwords in system services and vulnerabilities in application services.
Weak Password Baseline
Automatically discovering weak password configuration risks in the system.
Alarm Center (Anti-Virus)
Receiving core alarms for malicious samples, host intrusions, abnormal logins, malicious processes, and so on.

Capabilities Not Included in the Professional Edition and Available in the Ultimate Edition

International security standard compliance baseline checking.
Advanced threat detection capabilities (identification of complex attacks such as APTs).
Critical file monitoring, with tamper detection for key files.
Typical Scenario: An e-commerce company with 30 CVMs, which had previously suffered SSH brute-force attacks, selected the Professional Edition. This enabled one-click vulnerability fixing, weak password detection, and intrusion alarms, allowing the company to complete its host protection baseline construction at a reasonable cost.

CWPP (Flagship Edition)

Enterprise Characteristics

There are explicit international security standard compliance requirement check items.
The asset scale is large (more than 50 servers), and the security exposure surface is broad.
A dedicated security team exists, requiring comprehensive threat detection and response capabilities.
It has experienced advanced attacks such as APTs, or operates in an industry with high security risks.

Core Capabilities Added Compared to the Professional Edition

Capability
Specific Description
Compliance Baseline for International Security Standards
Built-in international security standards and Tencent Cloud baseline standards, with support for one-click compliance checking.
Cloud Perimeter Analysis
Sort out the internet-exposed attack surface and identify unnecessary port openings and missing access controls.
Advanced Threat Detection
The alarm center is upgraded to cover complex attack patterns such as APT.
Core File Monitoring
Real-time tamper-proof monitoring for critical system files and Web pages.
AI Agent Security
Security management and risk identification for AI agent assets

Container Security

Enterprise Characteristics

Docker/Kubernetes has been adopted at scale, with a large number of container nodes and clusters, and containers have become the core runtime environment for business.
You have encountered runtime security incidents such as container escapes, malicious mining, or abnormal process injection, or you have clear concerns about such risks.
There are international security standard compliance requirements, and the compliance scope has been extended to the container and K8s level.
You use multi-cloud or hybrid cloud K8s clusters but lack a unified means of visualizing cluster configurations and access risks.

Core Capabilities Added Compared to CWPP Ultimate Edition

Capability
Specific Description
Container Runtime Threat Detection
Detects abnormal processes, escape behaviors, malicious mining, reverse shells, and other runtime attack behaviors in containers
K8S API Security Audit
Audits Kubernetes API Server access behaviors and identifies risky operations such as unauthorized access and abnormal calls.
IaC Risk Governance
Scans infrastructure code such as Dockerfile, Helm Chart, and K8s YAML before deployment to identify configuration risks in advance.
Container Compliance Baseline Governance
Built-in container-specific compliance baselines such as international security standards, with support for one-click checking of cluster compliance status.
Capabilities that still need to be added on demand.
The image-layer security risks (including detection of vulnerabilities, malware, and sensitive information in the early CI/CD stages) require the separate purchase of the "container image risk" module.
If deep defense and attack protection is required for applications in containers, it is still recommended to add the "application protection" module.

Typical Scenario

Typical Scenario 1 (Compliance-Driven): A healthcare enterprise must pass international security standard baseline checks every year to reduce the workload of audit preparation.
Typical Scenario 2 (Advanced Threats): An enterprise security team discovered a suspicious process, but no record existed in the alarm center. Through log analysis and proactive investigation based on raw logs, the team successfully identified a covert APT attack that evaded rule-based detection.
Typical Scenario 3 (Container Security): An internet company has fully containerized its core business and manages 20 K8s clusters and 300+ nodes. Previously, CWPP alone could not adequately cover risks such as container escapes and K8s API abuse. After container security was added, runtime detection identified a mining program attempting to access host resources through a container escape and blocked it in time. Meanwhile, IaC risk governance intercepted multiple high-risk Dockerfile configuration errors before deployment.

FAQs

Q: When will the free edition be upgraded?
A: Immediate upgrade is recommended if any of the following occurs: ① A brute-force attack or intrusion event is encountered. ② There is a need for ransomware protection or file monitoring. ③ There are vulnerabilities that need to be fixed quickly. ④ There are international security standard compliance requirements.

Q: How do I select the most suitable module for on-demand procurement?
A: Add modules on demand based on actual business pain points:
If you have compliance log retention requirements, add the Log Analysis module.
If you have a wide variety of cloud products and high configuration risks, add the Cloud Product Configuration Check module.
If you have data security compliance requirements, add the DSPM module.
If you have intense security attack and defense scenarios, add the Application Protection module.
If you need protection but cannot install a client, add the Snapshot Detection module.

Q: What is the relationship between container security and container image risk? Do they have to be purchased together?
A: The two cover different stages of container security and are not mandatory to purchase together. Container Image Risk focuses on pre-deployment image-layer risk governance, including scanning for vulnerabilities, malicious files, and sensitive information. Container Security focuses on post-deployment node hardening, cluster protection, and runtime detection. If you only need to intercept risks during the build stage, you can purchase Container Image Risk separately. If you already have containerized production clusters, we recommend combining the two to achieve full lifecycle protection from image building to runtime.

Q: Can CWPP and Container Security share the same hosts?
A: The "Node Security" billing item in Container Security is essentially CWPP Ultimate Edition (USD 27/host/month), which protects the host machines that run containers. "Cluster Security" (USD 6.75/core/month) is a container-specific capability that provides cluster, K8s API, and runtime protection. The two must be used together, and you cannot purchase only Cluster Security while skipping node protection.

Ajuda e Suporte

Esta página foi útil?

comentários