P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Cloud and subscribed services

Supplier-run application (SaaS): what it is and how it is attacked

An application a supplier runs entirely, which the organisation subscribes to and puts its data into.

Also known as

  • SaaS
  • software as a service
  • cloud application
  • business application

Typing any of them into the editor finds this object.

Why it matters on a security diagram

You cannot patch it, scan it, or sign in to the machine it runs on. The only controls you hold are who has an account, what those accounts may do, and what you choose to put in it. What you can find out afterwards usually depends on a subscription tier chosen on price.

How it gets attacked, and what reduces it

How it gets attacked

  • Sign-in reachable from anywhere, with the organisation's own network controls not applying to it
  • Sharing settings that make documents readable by anyone holding a link
  • Administrative accounts far more numerous than anyone intended

What reduces it

  • Route sign-in through your own identity provider so your rules apply
  • Audit sharing links and expire them, because they outlive the reason they were made
  • Check the audit tier at purchase, not during the incident

Where it sits

Group
Cloud and subscribed services · Things that only exist because somebody else runs the platform underneath them.
Whose side, by default
Ours · Belongs to the organisation the diagram is about.
Catalogue identifier
saas-app

Reviewed . CC BY 4.0.

Others in cloud and subscribed services

The cloud and subscribed services group lists all 12 of them side by side.

Supplier-run application on your own diagram

Open the editor, press N, and type SaaS. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.

Open the diagram maker