HomeSecurityCloud Security Alliance introduces new framework for SaaS

Cloud Security Alliance introduces new framework for SaaS

The Cloud Security Alliance (CSA) presented the new SaaS Security Capability Framework (SSCF), establishing a new security standard. The SSCF aims to help SaaS providers incorporate zero-trust principles into their environments and provide more consistent security controls to customers, amid increasing risks from third parties.

The publication of the guidelines follows recent attacks on Salesforce applications, which have drawn the security industry's attention.

See also: CISA warns of suspected broader SaaS attacks

SaaS

The new framework serves as an industry standard that defines the technical minimum requirements for the security of SaaS applications, especially those that fall under the so‑called Shared Responsibility Model. The SSCF defines controls in six security domains:

– Change control and configuration management
– ​​Data security and privacy lifecycle management
– ​​Identity and access management
– ​​Interoperability and portability
– Logging and monitoring
– Security incident management, e-discovery and forensics in the cloud

These domains are designed to translate generic business requirements into specific SaaS security functions that customers can actually configure and rely on. They include, for example, log forwarding, SSO enforcement, policies for secure configurations and incident notifications.

This approach complements business-oriented security frameworks such as ISO 27001, without replacing them.

See also: JPMorgan urges redefinition of SaaS security

Cloud Security Alliance introduces new framework for SaaS

Brian Soby, co-founder and CTO of SaaS security company AppOmni and lead author of the SSCF, called the Security Capabilities Framework a significant advancement for the industry. “It provides a clear, unified, and essential standard that helps companies move beyond outdated risk assessments and truly embed zero-trust principles into their environments.”

David Brown, SVP of International Business at firewall policy management company FireMon, also speaks of progress but points out: “A framework only reduces risk when it is translated into operational controls, specifically continuous visibility of network policies, strict outbound controls and automated compliance checks.”

Brown adds: “Companies that combine SSCF requirements with a real review of network configuration can demonstrate that controls are working and significantly reduce the risks associated with SaaS.”

See also: What you need to know about Ransomware-as-a-Service (RaaS)

Cloud Security Alliance introduces new framework for SaaS

A growing percentage of internet traffic is generated by non-human agents: bots, agents, and automated systems that interact with SaaS applications in ways that are often overlooked by traditional monitoring methods.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS