Supplier-run application (SaaS): what it is and how it is attacked
An application a supplier runs entirely, which the organisation subscribes to and puts its data into.
Also known as
- SaaS
- software as a service
- cloud application
- business application
Typing any of them into the editor finds this object.
Why it matters on a security diagram
You cannot patch it, scan it, or sign in to the machine it runs on. The only controls you hold are who has an account, what those accounts may do, and what you choose to put in it. What you can find out afterwards usually depends on a subscription tier chosen on price.
How it gets attacked, and what reduces it
How it gets attacked
- Sign-in reachable from anywhere, with the organisation's own network controls not applying to it
- Sharing settings that make documents readable by anyone holding a link
- Administrative accounts far more numerous than anyone intended
What reduces it
- Route sign-in through your own identity provider so your rules apply
- Audit sharing links and expire them, because they outlive the reason they were made
- Check the audit tier at purchase, not during the incident
Where it sits
- Group
- Cloud and subscribed services · Things that only exist because somebody else runs the platform underneath them.
- Whose side, by default
- Ours · Belongs to the organisation the diagram is about.
- Catalogue identifier
- saas-app
Reviewed . CC BY 4.0.
Others in cloud and subscribed services
- Cloud platformAWS · Azure · GCP · Google Cloud · public cloud · hyperscaler · IaaSA supplier's computing platform, rented by the hour, where a setting made on a website creates or removes a whole system.
- AI model endpointLLM API · inference endpoint · model service · AI serviceWhere an application sends a question, along with documents, images or data, to an AI model and gets an answer back.
- Cloud accountsubscription · project · AWS account · Azure subscription · Google Cloud project · cloud environmentOne named compartment of a cloud platform, with its own bill and its own list of who may change what.
- Cloud account groupmanagement group · AWS Organizations · GCP folder · landing zone · account structureThe parent that owns all of an organisation's cloud accounts and can set rules over every one of them.
- Cloud control panelcontrol plane · management console · cloud portal · cloud API · management planeThe website and commands used to configure the cloud itself, as opposed to the systems running inside it.
- Connected appOAuth application · app registration · enterprise application · app consent · add-inAn outside program that somebody has allowed to reach company data on their behalf.
- Managed databaseRDS · Azure SQL · Cloud SQL · database as a service · DBaaSA database the cloud provider runs, where the data and the settings are yours but the machine is never touched.
- On-demand functionserverless · Lambda · Azure Functions · Cloud Run · FaaSA small piece of code that runs only when something asks for it, with no server to look after.
- Container platformKubernetes · K8s · cluster · EKS · AKS · GKE · OpenShiftThe system that decides where each packaged application runs, and starts it again when it stops.
- Container image storecontainer registry · image registry · ECR · ACR · artefact storeThe library of packaged applications that machines fetch from whenever they start something.
- Infrastructure blueprintinfrastructure as code · IaC · Terraform · state file · CloudFormation · BicepThe written description of what the cloud should contain, together with the record of what was actually built.
The cloud and subscribed services group lists all 12 of them side by side.
Supplier-run application on your own diagram
Open the editor, press N, and type SaaS. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.
Open the diagram maker