The cloud security acronyms, explained.
CSPM, CNAPP, CWPP, CIEM, DSPM, SSPM. Six acronyms, heavily overlapping marketing, and very little agreement on what any of them mean. These are vendor-neutral explanations of what each category actually covers — and, more usefully, what it does not.
CSPM vs CNAPP vs CWPP vs CIEM vs DSPM vs SSPM
The short version: five of these are components, and one is the umbrella.
| Acronym | Stands for | Question it answers |
|---|---|---|
| CSPM | Cloud Security Posture Management | Is the cloud infrastructure configured correctly? |
| CWPP | Cloud Workload Protection Platform | Are the running workloads patched and hardened? |
| CIEM | Cloud Infrastructure Entitlement Management | Who can actually do what, and do they still need it? |
| DSPM | Data Security Posture Management | Where is the sensitive data and who can reach it? |
| SSPM | SaaS Security Posture Management | Are M365, Workspace, GitHub and Snowflake locked down? |
| CNAPP | Cloud-Native Application Protection Platform | All of the above, correlated on one data model. |
All explainers
What is CSPM (Cloud Security Posture Management)?
CSPM continuously checks cloud infrastructure for misconfigurations and compliance drift. A plain-English explanation of how it works, what it catches, what it misses, and how it differs from CNAPP, CWPP and CIEM.
What is CNAPP (Cloud-Native Application Protection Platform)?
CNAPP unifies CSPM, CWPP, CIEM and DSPM on one data model instead of four consoles. What the category actually means, why it emerged, and how to tell a real CNAPP from a bundle of acquisitions.
What is CWPP (Cloud Workload Protection Platform)?
CWPP secures the workloads themselves — VMs, containers, serverless functions and hosts — rather than the cloud configuration around them. How it works, agent vs agentless, and how it differs from CSPM.
What is CIEM (Cloud Infrastructure Entitlement Management)?
CIEM resolves what identities can actually do in a cloud environment — after role chaining, SCPs and permission boundaries — and compares it against what they actually used. How it works and why policy review is not enough.
What is DSPM (Data Security Posture Management)?
DSPM finds where sensitive data lives across cloud storage, classifies it, and works out who can reach it. How classification works, why encryption-at-rest is not the answer, and how DSPM differs from CSPM and DLP.
What is SSPM (SaaS Security Posture Management)?
SSPM secures the SaaS platforms your company runs on — Microsoft 365, Google Workspace, GitHub, Snowflake — which cloud CSPM tools never scan. What it covers and why SaaS admin accounts are the softest target you own.
What is a cloud attack path?
An attack path is the chain of individually-minor findings that together reach something valuable. Why severity-ranked lists bury real risk, what a toxic combination is, and how choke points cut hundreds of paths at once.
What is agentless cloud security?
Agentless cloud security assesses infrastructure and workloads without installing software on them. How snapshot scanning works, what it can and cannot see, and an honest comparison with agent-based tooling.
Stop reading. Start scanning.
Every category on this page is one engine on the Onam platform. Connect a read-only role and see all of them against your own cloud.