Tenable Security Center vs VMware Aria Automation comparison

Cancel
You must select at least 2 products to compare!
Wiz Logo
Read 11 Wiz reviews
15,070 views|11,203 comparisons
100% willing to recommend
Tenable Logo
1,033 views|743 comparisons
95% willing to recommend
VMware Logo
142 views|113 comparisons
93% willing to recommend
Comparison Buyer's Guide
Executive Summary
Updated on Jun 21, 2023

We performed a comparison between Tenable.sc and VMware Aria Automation based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.

  • Features: Tenable.sc excels in vulnerability detection, prioritization, and risk-based approach, while VMware Aria Automation stands out for its automation capabilities, DevOps features, and customizable user frontend experience. Tenable.sc could enhance its penetration testing, ticketing systems, GUI, reporting, vendor training, and user interface. Pricing is also a concern. VMware Aria Automation could benefit from simplification in areas such as multitenancy management, migration, API, vRealize Orchestrator Automation, automation, licensing, orchestration workflow, and reporting customization.

  • Service and Support: Tenable.sc's customer service has varying opinions, while some customers rate it positively, others believe it requires improvement. In contrast, VMware Aria Automation's customer service is generally viewed as good, with some customers citing the need for additional research for complex implementations. 

  • Ease of Deployment: Tenable.sc has a simple and easy initial setup, taking only a day to complete. In contrast, VMware Aria Automation's setup is more complicated and can take anywhere from an hour to several months, depending on the version and environment. 

  • Pricing: Tenable.sc offers pricing based on IP addresses scanned, while VMware Aria Automation has complex licensing options. Tenable.sc's cost is viewed as reasonable by some, but expensive by others. VMware Aria Automation is costly, but offers features such as workload management and auto-scaling suggestions that can result in cost savings.

  • ROI: Tenable.sc is a cost-effective solution that delivers a positive ROI by minimizing manpower costs. On the other hand, VMware Aria Automation saves time and provides greater visibility but ROI can be variable and indirect.

Comparison Results: Tenable.sc is the preferred choice over VMware Aria Automation for vulnerability management, as it offers more comprehensive features such as accurate detection and compliance scans, risk-based approach, accurate reports, and fewer false positives. While VMware Aria Automation has extensive automation capabilities for virtual machine deployment and feature customization, Tenable.sc is better suited for vulnerability management.

To learn more, read our detailed Tenable Security Center vs. VMware Aria Automation Report (Updated: March 2024).
769,662 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"Our most important features are those around entitlement, external exposure, vulnerabilities, and container security.""The CSPM module has been the most effective. It was easy to deploy and covered all our accounts through APIs, requiring no agents. Wiz provides instant visibility into high-level risks that we need to address.""With Wiz, we get timely alerts for leaked data or any vulnerabilities already existing in our environment.""The solution is very user-friendly.""The security baseline and vulnerability assessments is the valuable feature.""The vulnerability management modules and the discovery and inventory are the most valuable features. Before using Wiz, it was a very manual process for both. After implementing it, we're able to get all of the analytics into a single platform that gives us visibility across all the systems in our cloud. We're able to correspond and understand what the vulnerability landscape looks like a lot faster.""Out of all the features, the one item that has been most valuable is the fact that Wiz puts into context all the pieces that create an issue, and applies a particular risk evaluation that helps us prioritize when we need to address a misconfiguration, vulnerability, or any issue that would put our environment into risk.""The first thing that stood out was the ease of installation and the quick value we got out of the solution."

More Wiz Pros →

"The most important features are the dashboard and reporting. The dashboard provides statistics with graphs and bar charts for our management.""The Auto-Remediate feature is good.""It basically reviews our threat landscape vulnerability.""One of the most valuable features is their distributed scan model for allotting engines to work together as a pool and handle multiple scans at once, across multiple environments. Automatic scanning distribution is a distinguishing feature of their toolset.""The most valuable features of Tenable SC are scanning, reporting, dashboards, and automation.""The solution is one of the most, if not the most, stable product available.""We really love the Security Center dashboard. It basically performs vulnerability scanning and then outputs a vulnerability data.""Tenable.sc's best features are the availability model, accident management, and scoring."

More Tenable Security Center Pros →

"The automation of the redundant tasks and the implementation of ServiceNow are huge for us...""The extensibility of it and the customization of a lot of the Blueprints, that you can customize, and the community as a whole. There's a ton of community-generated Blueprints that might be (helpful) to set up a design for your automation needs, that you can use as a base and go on from there and make changes to it.""The most valued feature is the streamlining of the DevOps process, automation and orchestration. It provides the ability for the entire Dev lifecycle to actually be incorporated into a single stream.""The solution is user-friendly and intuitive.""One of the most valuable features is lifecycle management. It allows my teams to create, manage, and retire all of our infrastructure objects in the data center.""vRealize automation stability is pretty good. They are always fixing bugs. The product team is doing a great job of addressing any issues that we might have.""The operations manager does a fantastic job on the front end because it includes on-premises and cloud use cases.""It is very stable, especially for high availability features."

More VMware Aria Automation Pros →

Cons
"The only thing that needs to be improved is the number of scans per day.""The reporting isn't that great. They have executive summaries, but it's only a compliance report that maps all current issues to specific controls. Whether you look at one subscription or project, regardless of the size, you will get a multipage report on how the issues in that account map to that control. Our CSO isn't going to read through that. He won't filter that out or show that to his leadership and say, "Here's what we're doing." It isn't a helpful report. They're working on it, but it's a poor executive summary.""One significant issue is that the searches are case-sensitive, so finding a misconfigured resource can become very challenging.""The solution's container security could be improved.""The only small pain point has been around some of the logging integrations. Some of the complexities of the script integrations aren't supported with some of the more automated infrastructure components. So, it's not as universal. For example, they have great support for cloud formation and other services, but if you're using another type of management utility or governance language for your infrastructure-as-code automation components, it becomes a little bit trickier to navigate that.""We would like to see improvements to executive-level reporting and data reporting in general, which we understand is being rolled out to the platform.""Wiz's reporting capabilities could be refined a bit. They are making headway on that, but more executive-style dashboards would be nice. They just implemented a community aspect where you can share documents and feedback. This was something users had been requesting for a while. They are listening to customer feedback and making changes.""We wish there were a way, beyond providing visibility and automated remediation, to wait on a given remediation, due to a critical aspect, such as the cost associated with a particular upgrade... We would like to see preventive controls that can be applied through Wiz to protect against vulnerabilities that we're not going to be able to remediate immediately."

More Wiz Cons →

"At times we have had the typical bugs.""Certain aspects require manual effort, such as exporting and analyzing data for our dashboards. The built-in components of the Tenable solution are somewhat clumsy that require external tools. So, this is an area of improvement.""There's a lot of information being streamed out of the reports. What would be nice, and maybe we just haven't found it, would be more of an executive-type view. We still expect it to collect all this information, but we would like a feature that would allow us to show it to an executive or a director or someone like that and give them some type of high-level overview but not get into the nitty-gritty.""The pricing is reasonable, but this could be brought down more aggressively, such as we see with Rapid7, Tenable SC's main competitor.""The solution needs to improve the vulnerability assessment because we have experienced some challenges with accuracy.""Tenable SC can improve by making it easier to create complicated reports and have more effectiveness in the remediation area for comparison between the scans.""The GUI could be improved to have all concerns and priorities use the same GUI, allowing them to see all tickets, assign vulnerabilities, and assign variation failures to each member of their team.""The product could be user-friendly, and they could enhance the web application's security features."

More Tenable Security Center Cons →

"They should concentrate on navigation and service improvements.""In terms of additional features, I would like it to be able to poll my vCenter infrastructure more rapidly and adapt to changes quickly. It should alert me and let me know when there are broken components, as a result of underlying infrastructure changes. It needs to be more stringent.""It has some limitations for scalability, especially for remote data center management. For some components, everything need to be centralized.""The initial setup was not straightforward. It was not simple, and we had a PoC. We had VMware help us deploy it, and it took them an exorbitant amount of time.""I don't think it's intuitive or user-friendly. I think it's a good tool. Any automation tool, these days, the learning curve is kind of high. You're teaching sysadmins who never developed stuff. Maybe they modified a little bit of code and now you tell them, "Hey, here's the tool, use it." But you have to know a little bit of DevOps. So you have to train them how to do the scripting.""I have not found this solution to be user-friendly. It's really complicated. The demo shows that you can automate anything but they only show basic scenarios. If you want to do anything more complicated than that, it becomes very complicated to set up.""The basic support is not there for Google Cloud and Azure. They are unable to provision nor do cost controls. Google is still left out. It is great that they have done AWS, but we are a retailer which means nothing to us because it is a competitor. Azure is good, but Google is where a lot of our development environments are.""Upgrades are always a pain."

More VMware Aria Automation Cons →

Pricing and Cost Advice
  • "The pricing seems pretty simple. We don't have to do a lot of calculations to figure out what the components are. They do it by enabling specific features, either basics or advanced, which makes it easy to select."
  • "The pricing is fair. Some of the more advanced features and functionalities and how the tiers are split can be somewhat confusing."
  • "The pricing is fair and comparable to their competitors. The cost seems to be going up, which is a concern. There are potential savings from consolidating tools, but we're uncertain how Wiz's pricing will change over time."
  • "I wish the pricing was more transparent."
  • "The cost of the other solutions is comparable to Wiz."
  • "Wiz is a moderately priced solution, where it is neither cheap nor costly."
  • More Wiz Pricing and Cost Advice →

  • "It is slightly more expensive than other solutions in the same sphere."
  • "We're able to save because we don't have to employ more staff members to help wit ht he scheduling of the scans, running the reports or sending them out to the systems owners. That alone is a big ROI for us."
  • "The licensing costs for this solution are approximately $100,000 US, and I think that covers everything."
  • "The pricing is more than Nexpose."
  • "Costing is pretty reasonable compared to the competition."
  • "We're a Fortune 500 company... our licensing costs [are] in the seven figures."
  • "We pay around 60,000 on a yearly basis."
  • "The price can start at €10,000 ($13,000 USD) for between 500 and 1,000 assets, and the price can climb into the millions as more assets are added."
  • More Tenable Security Center Pricing and Cost Advice →

  • "From the customer perspective, the value was worth it."
  • "I'm very interested in the integration with Puppet. However, my organization doesn't have the funding for something like Puppet right now. If VMware would integrate that feature set (Puppet) into vRA. That would be very awesome."
  • "Better pricing is always handy, but I feel it's at the right price point."
  • "We have seen significant ROI. We used to have physical servers, it took 90 days to get a server, order it, buy it, and get it in. We have it down to 10 minutes, building a server with virtualization, and now that's too slow. So, we let the customer do it at their speed. Therefore, it is pretty much up in a couple of minutes and they have a server."
  • "The solution has helped to increase infrastructure, agility, speed, and provisioning in the time to market."
  • "There is confusion between licensing levels. There are three different licensed versions of vRealize Automation, and there are different things which can happen in each of them."
  • "vRealize automation really should be a front door to the whole VMware suite of products."
  • "As far as value is concerned, it has been essential to our environment. We have been able to deploy VMs quickly and the developers have their own sandbox, so they can spin up and destroy VMs at their own will."
  • More VMware Aria Automation Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Cloud Security Posture Management (CSPM) solutions are best for your needs.
    769,662 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:Wiz and Lacework sucks... Buy Orca. 
    Top Answer:Whether or not the cost of third-party Cloud Security tools is justified would depend on your specific needs and budget… more »
    Top Answer:With Wiz, we get timely alerts for leaked data or any vulnerabilities already existing in our environment.
    Top Answer:The tool's dashboard and reporting capabilities match our company's needs since we are able to modify the basic view to… more »
    Top Answer:I rate the solution's price as seven on a scale of one to ten, where one is cheap and ten is expensive. The tool is… more »
    Top Answer:The tool's initial configuration is not so easy. The hardware requirements related to the tool need to be better because… more »
    Top Answer:vROP is a virtualization management solution from VMWare. It is efficient and easy to manage. You can find anything you… more »
    Top Answer:When it comes to VMware Aria Automation, you have three choices for free runs Hands-on Lab (HOL) Advanced lab A free… more »
    Top Answer:I was looking at VMware Aria Automation case studies recently and I got the impression that three main kinds of… more »
    Comparisons
    Also Known As
    Tenable.sc, Tenable Unified Security, Tenable SecurityCenter
    VMware vRealize Automation, vRA, VMware DynamicOps Cloud Suite
    Learn More
    Overview

    Wiz is a highly efficient solution for data security posture management (DSPM), with a 100% API-based approach that provides quick connectivity and comprehensive scans of platform configurations and workloads. The solution allows companies to automatically correlate sensitive data with relevant cloud context, such as public exposure, user identities, entitlements, and vulnerabilities.This integration enables them to understand data accessibility, configuration, usage, and movement within their internal environments.

    Wiz's Security Graph delivers automated alerts whenever risks emerge, allowing teams to prioritize and address the most critical issues before they escalate into breaches. Furthermore, Wiz ensures rapid and agentless visibility into critical data across various repositories, enabling organizations to easily determine the location of their data assets.

    Wiz Features

    Wiz provides various features in the following categories:

    • Agentless Scanning: The solution can scan every layer of a cloud environment without requiring agents, managing the entire process and providing comprehensive visibility.

    • Workflow Integration: Users can create customized workflows within Wiz to identify and assign actions based on urgency, integrating them with ticketing systems for quick and efficient remediation.

    • Vulnerability Management: Wiz's vulnerability management modules provide detailed analytics and visibility across cloud systems, streamlining the manual process of vulnerability discovery. The automated attack path analysis helps identify risks and trace potential points of exposure, allowing users to understand and mitigate them effectively and proactively.

    • CSPM (Cloud Security Posture Management): Wiz's CSPM module offers instant visibility into high-level risks to an enterprise’s cloud environment, covering all accounts without the need for agents.

    • Out-of-the-Box Reporting and Custom Queries: The service supports comprehensive reporting with asset context, allowing users to perform complex custom queries on the solution’s user-friendly interface.

    • Automation Roles and Dashboards: The solution facilitates automation by providing essential roles and dedicated dashboards that enable teams to understand security information quickly, even those with limited expertise.

    • Contextual Risk Evaluation: The service contextualizes the various components contributing to an issue, providing a risk evaluation framework that helps prioritize remediation efforts.

    • Security Graph and Visibility: Wiz's security graph offers visibility across the entire organization, even with multiple accounts, enabling users to understand their environment and assets effectively.

    The Benefits of Wiz

    Wiz offers the following benefits:


    • Comprehensive agentless scanning

    • Effective identification and mitigation of vulnerabilities

    • Streamlined vulnerability management

    • Robust reporting capabilities and customizable queries

    • Enhanced automation and role-based access control

    • Prioritized risk evaluation for efficient remediation

    • Security posture across multiple accounts

    Reviews from Real Users

    Kamran Siddique, VP Information Security at boxed.com, remarks his company has seen a ROI while using Wiz, as it simplifies the process by integrating multiple useful tools into one solution.

    According to a Senior Security Architect at Deliveroo, Wiz has given their company a fresh approach to vulnerability management, as Wiz's native integrations are extremely useful and paramount to the operational success of their platform.



    Get a demo | Wiz

    Get a risk-based view of your IT, security and compliance posture so you can quickly identify, investigate and prioritize your most critical assets and vulnerabilities.

    Managed on-premises and powered by Nessus technology, the Tenable Security Center (formerly Tenable.sc) suite of products provides the industry’s most comprehensive vulnerability coverage with real-time continuous assessment of your network. It’s your complete end-to-end vulnerability management solution.

    VMware Aria Automation is a cloud management tool that allows companies to simplify their cloud experience through a modern automation platform. The solution is designed to deliver self-service clouds, multi-cloud automation with governance, and DevOps-based security and infrastructure management. It helps organizations improve IT agility, efficiency, and productivity through its various features. 

    VMware Aria Automation has multiple use cases that include the following:

    • Self-service multi-cloud: VMware Aria Automation can be used to deliver consistent self-service consumption. Another use case in this area is for delivering infrastructure across VMware Clouds as well as public clouds.

    • Multi-cloud governance: The solution can be used to manage cost, performance, networking, configuration, and security at scale for multi-cloud environments. VMware Aria Automation offers all this with an everything-as-code approach.

    • DevOps for infrastructure: Through VMware Aria Automation, companies can enable a powerful infrastructure as code platform with support for iterative development and infrastructure pipelining.

    • Kubernetes automation: Users can utilize VMware Aria Automation to automate the management of Kubernetes clusters and namespaces with support for vSphere with Tanzu.

    • Security operations: VMware Aria Automation facilitates event-driven automation to deliver full-service IT system compliance enforcement and vulnerability remediation.

    VMware Aria Automation Features

    VMware Aria Automation has various features that allow users to easily perform operations. Some of the solution's capacities include:

    • VMware Cloud agnostic template: This feature allows organizations to use a single cloud template to deploy with Infrastructure as a Code. Deployment options include VMware Cloud as well as major public cloud platforms such as Amazon AWS, Microsoft Azure, Google Cloud, and more.

    • Extensibility and customization: This VMware Aria Automation feature allows users to get full extensibility and customization. This can be achieved through Aria Automation Orchestrator, Action-Based Extensibility (ABX), and built-in integrations with common third-party tools.

    • Self-service multi-cloud: This feature enables users to request and provision infrastructure resources. It can be done across clouds using a unified and consistent Infrastructure as a Service (IaaS) consumption layer, idempotent REST API, and self-service catalog.

    • Centralized policies and governance: VMware Aria Automation offers a feature for users to manage multiple clouds with templatized cloud and policy definition, automated remediation, and cloud environment visibility.

    • Configuration management: Through this feature of the product, day 1 and 2 control can be achieved for virtualized and cloud environments. This can be done with intuitive configuration automation, compliance enforcement, and vulnerability remediation.

    • Infrastructure pipelining: Through this feature, organizations can access user-friendly release automation pipelines. They can be specifically tailored for CI/CD in infrastructure use cases.

    VMware Aria Automation Benefits

    VMware Aria Automation offers its users various benefits. Some of the biggest advantages that the solution brings to companies that utilize it include:

    • VMware Aria Automation provides faster time to market for companies through offloading manual tasks with advanced workflows and agile templating.

    • The solution offers high levels of security and control.

    • This product is suitable for beginners, as it offers a self-service consumption experience for users.

    • VMware Aria Automation accelerates innovation through Infrastructure as Code and DevOps principles.

    • The product provides users with flexibility, as it is compatible with the most popular public cloud solutions.

    • The solution offers fast deployment because of all natively integrated functions.

    Reviews from Real Users

    Awais J., CTO/CEO at a tech services company, likes VMware Aria Automation because it saves a lot of time, provides more visibility, and has extensive automation capabilities.

    An IT consultant at a government rates VMware Aria Automation highly because the product gives you flexibility to analyze and consume resources.

    Sample Customers
    Wiz is the fastest growing software company ever - $100M ARR in 18 months: Wiz becomes the fastest-growing software company ever | Wiz Blog  Discover why companies, including Salesforce, Morgan Stanley, Fox, and Bridgewater choose Wiz as their cloud security partner. Read their success stories here: Customers | Wiz
    IBM, Sempra Energy, Microsoft, Apple, Adidas, Union Pacific
    Rent-a-Center, Amway, Vistra Energy, Liberty Mutual
    Top Industries
    REVIEWERS
    Computer Software Company38%
    Retailer13%
    Outsourcing Company13%
    Manufacturing Company13%
    VISITORS READING REVIEWS
    Computer Software Company16%
    Financial Services Firm14%
    Manufacturing Company9%
    Government6%
    REVIEWERS
    Financial Services Firm31%
    Comms Service Provider15%
    Manufacturing Company15%
    Computer Software Company12%
    VISITORS READING REVIEWS
    Educational Organization16%
    Government12%
    Computer Software Company12%
    Financial Services Firm10%
    REVIEWERS
    Financial Services Firm18%
    Healthcare Company15%
    Comms Service Provider11%
    Government9%
    VISITORS READING REVIEWS
    Financial Services Firm15%
    Computer Software Company14%
    Government9%
    Manufacturing Company8%
    Company Size
    REVIEWERS
    Small Business17%
    Midsize Enterprise25%
    Large Enterprise58%
    VISITORS READING REVIEWS
    Small Business21%
    Midsize Enterprise15%
    Large Enterprise65%
    REVIEWERS
    Small Business35%
    Midsize Enterprise18%
    Large Enterprise47%
    VISITORS READING REVIEWS
    Small Business19%
    Midsize Enterprise27%
    Large Enterprise54%
    REVIEWERS
    Small Business12%
    Midsize Enterprise9%
    Large Enterprise79%
    VISITORS READING REVIEWS
    Small Business18%
    Midsize Enterprise13%
    Large Enterprise69%
    Buyer's Guide
    Tenable Security Center vs. VMware Aria Automation
    March 2024
    Find out what your peers are saying about Tenable Security Center vs. VMware Aria Automation and other solutions. Updated: March 2024.
    769,662 professionals have used our research since 2012.

    Tenable Security Center is ranked 10th in Cloud Security Posture Management (CSPM) with 48 reviews while VMware Aria Automation is ranked 15th in Cloud Security Posture Management (CSPM) with 133 reviews. Tenable Security Center is rated 8.2, while VMware Aria Automation is rated 8.0. The top reviewer of Tenable Security Center writes "A security solution for vulnerability assessment with automated scans". On the other hand, the top reviewer of VMware Aria Automation writes "Allows for a lot of orchestration or customization within our environment to suit our customers". Tenable Security Center is most compared with Tenable Vulnerability Management, Qualys VMDR, Tenable Nessus, Rapid7 InsightVM and Forescout Platform, whereas VMware Aria Automation is most compared with Red Hat Ansible Automation Platform, VMware Aria Operations, vCloud Director, Morpheus and vCenter Orchestrator. See our Tenable Security Center vs. VMware Aria Automation report.

    See our list of best Cloud Security Posture Management (CSPM) vendors.

    We monitor all Cloud Security Posture Management (CSPM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.