As SaaS applications became more popular, it was unclear who was responsible for protecting the data. Nowadays, most security and IT teams understand the shared responsibility model, where the SaaS vendor is responsible for the application's security, while the organization is responsible for their data. It is more difficult to determine who is responsible for the data on the organization's side. This is especially true for larger organizations that store large amounts of customer, employee, financial, strategic, and other sensitive data online. If there is a SaaS data breach or ransomware attack, this data could be exposed or lost, and depending on the industry, the business could face serious regulatory penalties. Before deploying any type of SSPM or other SaaS security solution, it is important to find the right security model. There are several different groups involved in the SaaS security ecosystem. SaaS App Owners understand the need for data security, but it is not their responsibility or something they know much about. Central IT is responsible for infrastructure, hardware, and passwords, but SaaS applications are not usually in their domain. Security Teams are the natural fit for implementing security controls and oversight, but they may not be aware of all the SaaS applications being used by the company. GRC Teams are in charge of making sure all IT meets security standards, but they do not have a direct role in securing corporate assets. The SaaS Vendor is not responsible for securing the data, but they are the ones who built the security apparatus for the SaaS application. To protect the data, all of these teams must work together and use a SaaS Security platform that facilitates communication between the security team and app owners. This platform should provide alerts when misconfigurations occur, threats are detected, and should include remediation steps. App owners and Central IT should have visibility and access to the apps they are responsible for, and the ability to dismiss security alerts.
This Cyber News was published on thehackernews.com. Publication date: Mon, 06 Feb 2023 12:45:03 +0000