Download Publication

Who it's for:
- Application developers
- Application Architects
- Cybersecurity professionals
- Cloud security practitioners
- IT professionals
- Auditors
- Compliance managers
SaaS Governance Best Practices for Cloud Customers
Release Date: 10/10/2022
Working Group: SaaS Governance
In the context of cloud security, the focus is almost always on securing Infrastructure-as-a-Service (IaaS) environments. This is despite the reality that while organizations tend to consume 2-3 IaaS providers, they are often consuming tens to hundreds of SaaS Offerings. The SaaS Governance Best Practice for Cloud Customers is a baseline set of fundamental governance practices for SaaS environments. It enumerates and considers risks during all stages of the SaaS lifecycle, including Evaluation, Adoption, Usage, and Termination.
The SaaS environment ultimately presents a shift in the way organizations handle cybersecurity that introduces a shared responsibility between producers and consumers. Failing to adjust accordingly can have devastating consequences such as disclosing sensitive data, loss of revenue, customer trust, and regulatory consequences.
Key Takeaways:
- Provides a baseline set of SaaS governance best practices for protecting data within SaaS environments;
- Enumerates and considers risks according to the SaaS adoption and usage lifecycles, and
- Provides potential mitigation measures from the SaaS customer’s perspective.
Download this Resource
Related Resources
Interested in helping develop research with CSA?
Related Certificates & Training
.png)
Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more
Learn more

.jpeg)
.jpeg)
.jpeg)
.jpeg)