What you are evaluating
Confirm the current FortiCNAPP edition and the modules retained in any existing Lacework deployment. Agentless control-plane collection and workload agents have different visibility; a shared platform name does not mean every runtime or development function is enabled.
A useful evaluation context
A Fortinet-aligned team can evaluate posture and behavioral workflows while checking the actual modules and workload requirements in its deployment.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Cloud, Kubernetes and entitlement posture functions assess documented configuration and permission risks.
- Workload and cloud detection capabilities include behavioral context associated with the Polygraph approach.
- Development-related functions include infrastructure-as-code and software-analysis capabilities where the corresponding modules are selected.
Where it fits in the work
- Map existing Lacework or Fortinet integrations to the current product configuration and select a small cloud lab.
- Compare collected control-plane activity with known resource changes, then document which additional agent supplies workload behavior.
- Trace one synthetic finding to its owner and verify a reversible correction, keeping development and runtime evidence distinct.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
Perform a benign, authorized role change in a lab and a separate documented event on an instrumented workload.
Evidence to look for
The evaluation records each signal’s source and timing, and the operator can reverse the configuration change without confusing it with a runtime response.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which current SKU and support path correspond to the existing Lacework configuration?
- Does a behavioral finding come from cloud activity records or a workload agent?
- Which development integrations can identify the responsible repository without requiring unnecessary access to unrelated code?
Names you may encounter: Lacework · Lacework FortiCNAPP. Historical names do not establish current availability or feature equivalence.