Try our new research platform with insights from 80,000+ expert users

BMC Helix Cloud Security vs VMware Aria Automation comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

BMC Helix Cloud Security
Ranking in Cloud Security Posture Management (CSPM)
31st
Average Rating
8.0
Reviews Sentiment
7.5
Number of Reviews
5
Ranking in other categories
Cloud Workload Protection Platforms (CWPP) (24th)
VMware Aria Automation
Ranking in Cloud Security Posture Management (CSPM)
16th
Average Rating
8.0
Reviews Sentiment
7.8
Number of Reviews
169
Ranking in other categories
Cloud Management (1st), Configuration Management (7th), Network Automation (3rd), Cloud Infrastructure Entitlement Management (CIEM) (5th)
 

Mindshare comparison

As of November 2024, in the Cloud Security Posture Management (CSPM) category, the mindshare of BMC Helix Cloud Security is 0.2%, down from 0.3% compared to the previous year. The mindshare of VMware Aria Automation is 0.3%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Security Posture Management (CSPM)
 

Featured Reviews

GregoireSoukiassian - PeerSpot reviewer
Effectively addresses security concerns but could use enhancement in terms of integration
BMC Helix Cloud Security has room for improvement in terms of integrating its various features. It currently consists of separate point solutions that don't flow together as seamlessly as they could. This lack of integration, unlike platforms like ServiceNow, may be due to historical factors. Enhancing this integration would make it a more compelling choice from a business perspective and offer a smoother user experience. In the next release of BMC Helix Cloud Security, I would like to see additional features, particularly AI integration, which has already been announced. AI integration could bring more precision to the platform, making it even more interesting and effective.
NiteshKumar1 - PeerSpot reviewer
Good stability, supports a hybrid model and easy to use
There is an area of improvement. For example, you are migrating from a customer's existing data center to a new target data center. To facilitate this transition, you'll initially need to evaluate the customer's aging hardware hosting VMware, which is nearing the end of its operational life. The customer expresses the intention to upgrade to a newer version, necessitating an overhaul of everything in the new data center. As a Systems Integrator (SI), consultant, or architect, your recommendation would be to acquire the latest hardware with a specified configuration and then install VMware on top of it. However, there's a crucial aspect related to the infrastructure requirements for VMware to run seamlessly on that hardware. If there's an opportunity to potentially reduce these infrastructure prerequisites, it would be highly beneficial. This is because a higher number of VMware licenses requires more infrastructure capacity from Original Equipment Manufacturers (OEMs) or Colocation partners. Consequently, when discussing the operation of this virtualized environment from VMware over a contractual period of five years, the overall cost to the customer is influenced by the infrastructure requirements. If there's a feasible way to decrease these prerequisites for the infrastructure supporting the virtualization layer, it would be advantageous in terms of cost for the customer. Any customer in today's world exists or wants to exist in a hybrid model, so in future releases, we would like to see this. So, going forward, if this virtualized environment would exist, it has to be a combination of on-premise plus public cloud Azure/AWS. It should be more seamless when your interface or when you are interacting with workloads running on-premise VMware/AWS VMware. So it is only there in some capacity and space, and I'm aware of it. And Azure and VMware already have a tie-up on the same lines, but at the same time, if it is more seamless, if it is more interchangeable, if you could move your workloads, or if you can access your workloads or your virtual machines irrespective of whatever platform it is running, whether it is on-premises, or cloud or public cloud, it'll be a lot more comfortable for a user than the user to consume that infrastructure. Firstly, it needs to have a combination of deployment and be more seamless for the customers. Secondly, more software-defined features, more in terms of managing the infrastructure pool in a software-defined way. Managing the infrastructure pool in a more optimized fashion is going to be the key in the upcoming times. It's not just on-premise, but at the same time, it should also be the public cloud as well. Probably because when I meet my customers, this is one thing that I always tell them. I have seen people moving from on-premise public cloud only to realize at the end of the month that they end up paying a higher bill compared to what they were paying when they were running their business on-premise. The reason is that they do not understand or do not realize the full potential of the public cloud, and the way it should be consumed, the way it should be used, and the way it should be scheduled to ensure that the billing at the end of the month is very optimal. You pay for what exactly you need, not everything that you have from the cloud. That's not a way to use the cloud, whether it is on-premise or from the cloud. For example, an enterprise has over 100 applications. Out of that 100 applications, only 25 applications are running the production instances, and the remaining 75 are running non-production instances. It can be a development environment, a test environment, a sandbox, etc. In this case, you need to run only the 25 applications on the public cloud 24/7. You do not need to run your remaining 75 applications 24/7. Because, eventually, your developers, testers, quality managers, and whoever will use the non-production environment only when they're in the office and working on those applications. Then why do we need to have those applications, which are non-production in nature, lower environments? So we're running on the public cloud all the time because, for a cloud provider, it is a virtual machine; whether you are consuming it for production work or non-production work, it is going to charge you the same bill. And if you are not optimizing, if you're not scheduling workloads, you are actually wasting money. You're wasting your money, and your bills, which you are going to pay with the public cloud provider provided, are going to be bad. It's going to be crazy. And then customers do not know what to do in this situation. And you cannot fight with the public cloud provider because they would say, "I had given you all the possibilities, all the opportunities to learn about it, the way you should be functioning it, the way you should be utilizing it. If you are not using it the way it should be used, That's not my problem."

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The cool feature of Helix Cloud Security is that you can do all that — understand and remediate issues — in one dashboard, based on the different policies that are available for security, out-of-the-box."
"The most valuable aspects of BMC Helix Cloud Security are its security features and regulatory compliance capabilities."
"It's also multi-cloud. You can look at several cloud providers: AWS, Azure, or GCP."
"The features that I've found most valuable are its container security aspect. I also like its vulnerability management tools."
"The best feature is time to value. With very minimal effort, you are able to have a cohesive view into your security posture on one or multiple cloud accounts, particularly if you are dealing with multicloud. If you have Azure and AWS deployments, you might have multiple subscriptions in Azure and usually multiple accounts in AWS. You may even be doing some GCP work (around Google Cloud Platform). It's very difficult to manage a common set of policies, even less reporting, across multiple subscriptions, accounts, and cloud environments. What BMC Helix Cloud Security does is provide a unified view or single pane of glass as to your baseline. Then, it also facilitates the ability for Level 1 or 2 operations support to take action and report on security vulnerabilities."
"Role-based security is a valuable feature."
"The initial setup is straightforward. It's not that difficult."
"We provided the ability to request virtual machines to our end users. Before, this was a very manual process, which took engineers to do. Now, it's an automated process."
"vRA helps automate deployment for developers. We do a lot of orchestration or customization within our environment so it will suit each of our customers. So, we have different business units who have their own templates."
"The ability to programmatically describe the desired state of a single, or an entire fleet of servers, on-premises, and in a cloud environment."
"I personally spend a lot of time in vRealize Orchestrator, so being able to directly tie into the back end on the APIs, I find that to be what really is the most advantageous thing for me."
"The automation part is most valuable. Because it is a VMware product, the automation capabilities that come with vRA are pretty extensive. We can integrate and build a lot of features on top of it, which makes it extremely useful for us."
"vRA has enabled us to derive value from the cloud faster. It is five to six times faster than traditional solutions."
"The blueprint functionality of the product is intuitive and user-friendly. The concept of the blueprints is visual and easy to use."
 

Cons

"Every organization out there doesn't rely on just one control body. They use FISMA control. They may use HIPAA, CIS, PCI, or SOX, then blend them. One of the things that is now in big demand for BMC Helix Cloud Security is content. That's the next journey in its lifespan, making it easier for the community to share and collaborate on content for security controls that can be measured and remediated."
"We've had some with issues connectors. The connectors have seemed to have caused a little bit of trouble, perhaps with the APIs trying to scan the environment. The only time I've had to reach out to tech support was for that. It seems it may not have been scanning correctly or I wasn't seeing data within a specific time. But we've set up a couple of connectors in the past couple of weeks and they actually scanned the AWS environment and we had data within about 10 minutes. It's working a lot faster and I think they're making improvements as they go."
"The UI could be more user-friendly."
"BMC Helix Cloud Security has room for improvement in terms of integrating its various features."
"I want the role-based security feature to be improved."
"The upgrade experience is horrible. It's not straightforward, there are a lot of failures, a lot of support interactions. It's not something that we are able to pull off ourselves. I've been with vRA since it was termed vCSA. We've gone through multiple rounds, and it has never been easy."
"It is not super-intuitive. It does require some skills to understand how to use it. I had no problem, but I had spent a lot of time already learning this product ahead of moving it to an operational status. But as we did so, we had a hard time bringing some people from other groups into the fold, to script and work against this environment. So, the ability to build workflows within that automation needs to be streamlined."
"The initial setup is very complex because we have a bunch of customization workflows. They were built-in features that we had to program as code with Orchestration."
"It has a learning curve."
"The stability is okay, but could be improved. We sometimes receive strange errors, which can only be solved with specialists."
"The solution could include more integrations and supportability around the container space."
"We are migrating from vRA version 7 to 8, but the migration is really hectic and time-consuming. There are no straightforward paths to migrate. We are doing an entirely new deployment to go to vRA version 8.0, then somehow get all of the VMs to vRA 8.0. Therefore, it would have been great if VMware had some solutions to upgrade from vRA 7 to 8 seamlessly. This includes the management of all the objects or VMs from the older version. Unfortunately, it is not there."
"VMware should go the way of vROps, with everything in one machine, the ability to scale out, and a more distributed environment instead of having the usual centralized SQL database."
 

Pricing and Cost Advice

"It is a subscription model with term licensing that is usually yearly. This includes, not only the product, but support and maintenance. It is based on cloud assets. Therefore, if you have 100 cloud assets, those cloud assets are measured based on evaluation or transactions. For example, if I'm evaluating that cloud asset for CIS compliance, PCI compliance, and AWS best practices, that asset gets evaluated three times, as those are three transactions. However, the license model is based on peak asset usage. So, over a year, if you deploy 100, 1000, 500, and then 2000 assets, you will be charged for the 2000 peak of assets managed by Helix Cloud Security."
"The pricing is based on an annual subscription, upfront, and it's based on cloud assets. Whether your assets are in Azure and AWS combined, the tool tells you how many assets are being scanned and that's the number used for pricing."
"VMware Aria Automation is expensive."
"We do plan to see ROI with any new implementation of new technologies being implemented within our environment."
"Customers say this solution is costlier compared to its competitors."
"From the customer perspective, the value was worth it."
"vRealize automation really should be a front door to the whole VMware suite of products."
"There is confusion between licensing levels. There are three different licensed versions of vRealize Automation, and there are different things which can happen in each of them."
"The cost of the solution is reasonable for us. Although it is relatively high, we prioritize stability and integration over cost."
"I'm very interested in the integration with Puppet. However, my organization doesn't have the funding for something like Puppet right now. If VMware would integrate that feature set (Puppet) into vRA. That would be very awesome."
report
Use our free recommendation engine to learn which Cloud Security Posture Management (CSPM) solutions are best for your needs.
816,816 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
26%
Computer Software Company
18%
Real Estate/Law Firm
8%
Manufacturing Company
7%
Computer Software Company
14%
Financial Services Firm
14%
Manufacturing Company
9%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about BMC Helix Cloud Security?
The most valuable aspects of BMC Helix Cloud Security are its security features and regulatory compliance capabilities.
What is your experience regarding pricing and costs for BMC Helix Cloud Security?
I would rate the price of BMC Helix Cloud Security as a seven in terms of costliness. It is not the cheapest option available, as it tends to be more expensive than some competitors, but it offers ...
What needs improvement with BMC Helix Cloud Security?
BMC Helix Cloud Security has room for improvement in terms of integrating its various features. It currently consists of separate point solutions that don't flow together as seamlessly as they coul...
What's the difference between VMware vRA (automation) and vROps (operations)?
vROP is a virtualization management solution from VMWare. It is efficient and easy to manage. You can find anything you need from the software interface. It provides complete visibility over applic...
Is there any way to try VMware Aria Automation for free?
When it comes to VMware Aria Automation, you have three choices for free runs: Hands-on Lab (HOL) Advanced lab A free trial I cannot describe in detail the second and third options as my company ...
Which sectors can benefit the most from VMware Aria Automation?
I was looking at VMware Aria Automation case studies recently and I got the impression that three main kinds of companies were using it most often: Social organizations Financial institutions and ...
 

Also Known As

TrueSight Cloud Security, SecOps Policy Service
VMware vRealize Automation, vRA, VMware DynamicOps Cloud Suite, SaltStack
 

Learn More

 

Overview

 

Sample Customers

NHS, Vodafone, Kansas City Life, SKY Italia, Cybera
Rent-a-Center, Amway, Vistra Energy, Liberty Mutual
Find out what your peers are saying about BMC Helix Cloud Security vs. VMware Aria Automation and other solutions. Updated: October 2024.
816,816 professionals have used our research since 2012.