ChaptersEventsBlog

Download Publication

SaaS Security and Misconfigurations Report
SaaS Security and Misconfigurations Report
Who it's for:
cybersecurity professionals

SaaS Security and Misconfigurations Report

Release Date: 04/11/2022

Working Group: SaaS Governance

Many recent breaches and data leaks have been tied back to misconfigurations causing it to be a top concern for many organizations. Most research related to misconfigurations has focused strictly on the IaaS layers and ignores the SaaS stack entirely. Yet, SaaS security and misconfigurations are equally crucial to the organization's overall security. For these reasons, CSA developed and distributed a survey to better understand the use of SaaS applications, timeline and tools for SaaS security assessments, a timeframe for misconfiguration detection and remediation, and awareness of security tools for SaaS applications.

The goal of this survey was to understand the current state of SaaS security and misconfigurations. Key areas of interest include:

  • Use of SaaS applications with organizations
  • Methods, policies, and tools for assessing SaaS app security
  • Timeline for detecting and remediating misconfigurations in SaaS app security
  • Awareness of new SaaS security related products
Download this Resource

Bookmark
Share
View translations
Related resources

Sponsor

Beyond the Hype: A Benchmark Study of AI Agents in the SOC
Beyond the Hype: A Benchmark Study of AI Agents...
SaaS Security Capability Framework (SSCF)
SaaS Security Capability Framework (SSCF)
Zero Trust Guidance for Small and Medium Size Businesses (SMBs) - Korean Translation
Zero Trust Guidance for Small and Medium Size B...
SSCF v1.0: The Standard That Simplifies SaaS Security
SSCF v1.0: The Standard That Simplifies SaaS Security
Published: 11/19/2025
When Simple DNS Mistakes Lead to Big Attacks: Lessons from the MikroTik Botnet
When Simple DNS Mistakes Lead to Big Attacks: Lessons from the Mikr...
Published: 10/21/2025
Cyber Defense Cannot Be Democratized
Cyber Defense Cannot Be Democratized
Published: 10/17/2025
5 Reasons Disconnected Apps Are An Enterprise Risk You Can No Longer Ignore
5 Reasons Disconnected Apps Are An Enterprise Risk You Can No Longe...
Published: 10/15/2025

Interested in helping develop research with CSA?

Related Certificates & Training