Cloud Detection and Response (CDR)
Cloud Detection and Response (CDR) is the set of security functions for detecting and responding to threats in cloud environments in the sense of modern cloud security. The focus is not only on workloads, but also on control plane activities, identities, APIs and misconfigurations. CDR is important because attacks in the cloud often proceed differently than in classic data center environments and can only be captured incompletely with conventional tools. Typical use cases are suspicious access, privilege escalation, misuse of service accounts or unusual changes to cloud resources.
Good CDR approaches work in real time, correlate signals from several layers and support fast response measures. Especially in multi-cloud strategies, the importance of this term is growing, because visibility across different platforms is required. For organizations, CDR therefore means a complement to classic cloud security and posture management approaches. Ultimately, the term stands for operational Cloud Security instead of mere static configuration checks. Operationally, automated attack detection helps to separate relevant signals from less critical events more quickly.
See also: Extended Detection and Response and SaaS Security.