Skip to main content
Guidance

Cloud security guidance

How to choose, configure and use cloud services securely.

Page 10 of 29

Using Software as a Service (SaaS) securely

Guidance on how to configure and use your SaaS application securely.

This guidance provides advice for how to configure and maintain your use of an application to mitigate the risks posed by common attacks we’ve seen against Software as a Service (SaaS) applications. It is designed to be used by customers setting up your new tenancy of a SaaS application or when reviewing your use of one you’re already using.

No matter whether you’ve gone through our lightweight approach or the full 14 Cloud Security Principles, the actions in this guidance should be achievable using security controls offered by the SaaS application and its provider.

For each action, we have provided:

  • an introduction to explain why it is important
  • a set of security goals that describe the important outcomes from taking the action
  • some context for suggested considerations that you can take to achieve the goals
  • recommended further reading for that section

Note:

Once you have picked a SaaS application, you should ensure that your tenancy of it is configured and consumed securely. Even though you cede more responsibility to your provider when using SaaS, you are still responsible for the configuration that is specific to your use of the application. A good provider should make it easy for you to configure the application to meet your users' needs, and your organisation’s security goals.














Published

Publish date

Reviewed

Version

2.1