Because of the rapid pace of SaaS adoption, many security practitioners have found themselves scrambling to ensure the security of the specific technologies their enterprises want to employ. However, the dynamics of SaaS can make this a challenging exercise. This is because most of the options for specific security controls are, by necessity, of the contractual or procedural variety — e.g., audit controls, contractual language about breach notification, etc. Also, security teams often discover SaaS systems only after they are already in use.
4 Quick and Dirty SaaS Technical Controls
Posted by: Ed Moyle September 3, 2013 05:00 AMBecause of the rapid pace of SaaS adoption, many security practitioners have found themselves scrambling to ensure the security of the specific technologies their enterprises want to employ. However, the dynamics of SaaS can make this a challenging exercise. This is because most of the options for specific security controls are, by necessity, of the contractual or procedural variety — e.g., audit controls, contractual language about breach notification, etc. Also, security teams often discover SaaS systems only after they are already in use.