Assessing SaaS Risk Proportionately
Reviewing every application to the same depth guarantees that nothing gets reviewed. Tiering by data and access makes the process fast enough to actually run.
Procedure · 714 words
Reviewing everything to the same depth guarantees nothing gets reviewed. Plus the layer nobody reviews at all: the access your applications have to each other.
7 records · 4,961 words
Reviewing every application to the same depth guarantees that nothing gets reviewed. Tiering by data and access makes the process fast enough to actually run.
Procedure · 714 words
Your applications have accounts with each other. This layer is invisible to user access reviews and it is where data moves without anyone watching.
Analysis · 746 words
Where your data physically sits, who can reach it, and why the answer is more complicated than the region you selected at sign-up.
Reference · 732 words
What to ask, what evidence to require, and how to tell a vendor with a security programme from one with a security page.
Checklist · 728 words
Auditors ask the same questions every year. A maintained register answers most of them in minutes rather than launching a three-week exercise.
Procedure · 684 words
The questions asked in the first hour of an incident are asset questions, and organisations without a register spend that hour building one.
Reference · 666 words
The register field that drives every other decision, and the one most often left blank or filled in once and never revisited.
Procedure · 691 words