Skip to main content

Pro audit program · v1.0

SaaS Security Posture

How well is your SaaS estate protected — SSO, MFA enforcement, offboarding, third-party app review?

  • General target area
  • CIS Controls framework
  • 6 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

How well is your SaaS estate protected — SSO, MFA enforcement, offboarding, third-party app review?

Risks addressed

  • High Ungoverned SaaS sprawl exposes corporate data
  • High Leavers retain access to SaaS post-departure
  • High Malicious OAuth apps exfiltrate mailbox / Drive data
  • Medium No central log of SaaS activity for IR

Controls (6)

  1. SaaS inventory maintained

    High

    This control ensures the organization maintains a current, comprehensive inventory of all Software-as-a-Service (SaaS) applications in use across the enterprise, including sanctioned and shadow IT applications. The inventory typically includes application names, owners, business purposes, user counts, data classifications, vendor…

    How to test + evidence

    Testing procedure: List every SaaS in use (CASB/SSPM or finance export). Confirm owners + tier.

    Evidence to collect: SaaS register.

  2. SSO enforced on all SaaS where supported

    High

    This control mandates that Single Sign-On (SSO) integration is configured and enforced for all Software-as-a-Service (SaaS) applications that offer SSO capabilities, typically via SAML 2.0, OAuth 2.0/OIDC, or other federated identity protocols. By centralizing authentication through an identity provider (IdP),…

    How to test + evidence

    Testing procedure: For each Tier-1/2 SaaS, confirm SSO is the only sign-in option.

    Evidence to collect: SSO config screenshots per app.

  3. MFA enforced on every SaaS account

    High

    This control requires that multi-factor authentication (MFA) is configured and enforced for all user accounts across every Software-as-a-Service (SaaS) application used by the organization. Enforcement means users cannot access the SaaS application without completing MFA, eliminating the option to bypass…

    How to test + evidence

    Testing procedure: Verify MFA is enforced at the app or IdP layer for every SaaS user.

    Evidence to collect: IdP / app reports.

  4. Joiner-mover-leaver wired into IdP

    High

    This control ensures that joiners (new hires), movers (role changes), and leavers (terminations) are automatically provisioned, updated, and deprovisioned in all connected systems through integration with the organization's Identity Provider (IdP). The IdP acts as the authoritative source of truth…

    How to test + evidence

    Testing procedure: Confirm HR-driven provisioning + deprovisioning across Tier-1 SaaS.

    Evidence to collect: JML workflow doc + SCIM logs.

  5. Third-party app review process

    Medium

    A third-party app review process evaluates external applications before they are granted access to organizational systems, data, or APIs. This control involves formal vetting procedures to assess permissions requested, vendor security posture, data handling practices, and compliance with organizational policies.…

    How to test + evidence

    Testing procedure: OAuth grants reviewed before approval; periodic re-review of installed marketplace apps.

    Evidence to collect: App-review register.

  6. Audit logs streamed to SIEM

    Medium

    This control ensures that security-relevant audit logs from critical systems, applications, and infrastructure are continuously forwarded in near real-time to a centralized Security Information and Event Management (SIEM) platform. Log streaming enables correlation, alerting, and retention independent of source systems,…

    How to test + evidence

    Testing procedure: Tier-1 SaaS audit logs flow to SIEM / log warehouse.

    Evidence to collect: SIEM source inventory.