Onam Security
Learn

The cloud security acronyms, explained.

CSPM, CNAPP, CWPP, CIEM, DSPM, SSPM. Six acronyms, heavily overlapping marketing, and very little agreement on what any of them mean. These are vendor-neutral explanations of what each category actually covers — and, more usefully, what it does not.

CSPM vs CNAPP vs CWPP vs CIEM vs DSPM vs SSPM

The short version: five of these are components, and one is the umbrella.

AcronymStands forQuestion it answers
CSPMCloud Security Posture ManagementIs the cloud infrastructure configured correctly?
CWPPCloud Workload Protection PlatformAre the running workloads patched and hardened?
CIEMCloud Infrastructure Entitlement ManagementWho can actually do what, and do they still need it?
DSPMData Security Posture ManagementWhere is the sensitive data and who can reach it?
SSPMSaaS Security Posture ManagementAre M365, Workspace, GitHub and Snowflake locked down?
CNAPPCloud-Native Application Protection PlatformAll of the above, correlated on one data model.

All explainers

What is CSPM (Cloud Security Posture Management)?

CSPM continuously checks cloud infrastructure for misconfigurations and compliance drift. A plain-English explanation of how it works, what it catches, what it misses, and how it differs from CNAPP, CWPP and CIEM.

Read

What is CNAPP (Cloud-Native Application Protection Platform)?

CNAPP unifies CSPM, CWPP, CIEM and DSPM on one data model instead of four consoles. What the category actually means, why it emerged, and how to tell a real CNAPP from a bundle of acquisitions.

Read

What is CWPP (Cloud Workload Protection Platform)?

CWPP secures the workloads themselves — VMs, containers, serverless functions and hosts — rather than the cloud configuration around them. How it works, agent vs agentless, and how it differs from CSPM.

Read

What is CIEM (Cloud Infrastructure Entitlement Management)?

CIEM resolves what identities can actually do in a cloud environment — after role chaining, SCPs and permission boundaries — and compares it against what they actually used. How it works and why policy review is not enough.

Read

What is DSPM (Data Security Posture Management)?

DSPM finds where sensitive data lives across cloud storage, classifies it, and works out who can reach it. How classification works, why encryption-at-rest is not the answer, and how DSPM differs from CSPM and DLP.

Read

What is SSPM (SaaS Security Posture Management)?

SSPM secures the SaaS platforms your company runs on — Microsoft 365, Google Workspace, GitHub, Snowflake — which cloud CSPM tools never scan. What it covers and why SaaS admin accounts are the softest target you own.

Read

What is a cloud attack path?

An attack path is the chain of individually-minor findings that together reach something valuable. Why severity-ranked lists bury real risk, what a toxic combination is, and how choke points cut hundreds of paths at once.

Read

What is agentless cloud security?

Agentless cloud security assesses infrastructure and workloads without installing software on them. How snapshot scanning works, what it can and cannot see, and an honest comparison with agent-based tooling.

Read

Stop reading. Start scanning.

Every category on this page is one engine on the Onam platform. Connect a read-only role and see all of them against your own cloud.