SlideShare a Scribd company logo
2021 SecurityPlus
SaaS Security Assessment
(From a practical point of view)
이 찬 우
How to use cloud securely?
In short,
Customer should consider security in SDLC.
4
What’s wrong with this pictures?
5
Some things don’t change over time.
Not Special.
Source Link : https://www.information-age.com/public-cloud-revenue-to-grow-6-3-in-2020-gartner-123490499/
The SaaS market is growing rapidly
Source Link : https://www.bmc.com/blogs/saas-growth-trends/
What are the biggest companies?
Source Link : https://snazlan.wordpress.com/2016/12/09/topic-0020-assessment-vs-evaluation/
10
Preparation → Assessment → F/up → Evaluation
11
“Can refer to various references for SaaS security assessment.”
Preparation
2021 SecurityPlus
SaaS Security Assessment
✓ KISA, Cloud Service Information Security Guide(SaaS)
✓ KISA, Cloud Vulnerability Analysis Guide
✓ SK Infosec, Cloud Security Guide
✓ CIS Benchmark for Cloud Services
✓ Vendor, Reference Architecture Guide for SaaS
Copyright 2021. Chanwoo Lee All rights reserved.
“Must develop our own framework.”
Source Link : https://www.bettercloud.com/monitor/saas-operations-management/
SaaS Management Reference Architecture
13
“Can derive your requirements through a security assessment.”
Assessment
2021 SecurityPlus
SaaS Security Assessment
✓ Service : Business and background
✓ Data : Legal and Privacy
✓ Architecture : Design and Configuration
✓ Application : Vendor and Product
✓ Authority : Accounts and Authentication
✓ Security Control : Data Leakage and Malware
✓ Monitoring : Log feeding and Integration
✓ Stakeholder : Role and Responsibility
Copyright 2021. Chanwoo Lee All rights reserved.
“Must analyze various use cases.”
Source Link : https://securityboulevard.com/2019/04/penetration-testing-for-saas-companies/
SaaS Security Reference Architecture
15
“Must implement the requirements you have derived.”
F/up
2021 SecurityPlus
SaaS Security Assessment
[Data]
✓ Personal Information protection
✓ SSL/TLS Encryption
✓ Data and password Encryption
✓ Data Retention
✓ Tenant Restriction
✓ Sharing and Download permission disable
✓ Upload File Scanning
✓ Validation of file extension
Copyright 2021. Chanwoo Lee All rights reserved.
16
“Must implement the requirements you have derived.”
F/up
2021 SecurityPlus
SaaS Security Assessment
[Access]
✓ SSO/SAML Integration
✓ IP Restriction
✓ Multi-Factor Authentication
✓ Guest Access Control
✓ Session Timeout
✓ Concurrent-session Control
✓ Minimizing Pre-defined roles and permissions
Copyright 2021. Chanwoo Lee All rights reserved.
17
“Must implement the requirements you have derived.”
F/up
2021 SecurityPlus
SaaS Security Assessment
[Etc]
✓ Log management
✓ SIEM integration
✓ Management of API Key, Plug-in, Third-Party Program
✓ Application Configuration Analysis
Copyright 2021. Chanwoo Lee All rights reserved.
“Must discuss with stakeholders in advance.”
Source Link : https://www.hubspot.com/pricing/
SaaS Pricing Model(Subscription)
Source Link : https://www.atlassian.com/ko/software/jira
Issue Tracking system(Ex. JIRA)
20
“Must get visibility and evaluate periodically.”
Evaluation
2021 SecurityPlus
SaaS Security Assessment
✓ Is the Assessment process operating as designed?
✓ What are the ways to improve the Assessment process?
✓ Has the security level of our company increased through
the Assessment process?
✓ Did you miss anything in the Assessment process?
✓ What are the problems you are facing while Assessment
process?
✓ What can you create after solving those problems?
Copyright 2021. Chanwoo Lee All rights reserved.
“Must evaluate on a paper and evidence basis.”
Source Link : https://docs.servicenow.com/
Dashboard(Ex. ServiceNow)
Source Link : https://congruentagile.com/2020/03/16/less-sprint/
Review and Retrospective
Clear
Detail
24
Wrap-up
Customer should
consider security
in SDLC.
Customer Need to
develop their own
framework.
Changing people through technology
Chanwoo Lee | Richard
Blog blog.naver.com/jg706
Facebook www.facebook.com/jg706
Slideshare www.slideshare.net/jg706
Linkedin www.linkedin.com/in/jg706
Youtube www.youtube.com/channel/UC5Hs9p5_euXJbaf5E7Hx7Ag
jg719411@nate.com | 010-4772-0130

More Related Content

PDF
FUZZING & SOFTWARE SECURITY TESTING
PDF
Deep Dive Spider Engine
PDF
Performance testing with JMeter
PDF
Introduction to K6
PPT
IBM AppScan - the total software security solution
PPTX
WebSphere Application Server Family (Editions Comparison)
PDF
Configuration Management in Ansible
PDF
Web Assembly (on the server)
FUZZING & SOFTWARE SECURITY TESTING
Deep Dive Spider Engine
Performance testing with JMeter
Introduction to K6
IBM AppScan - the total software security solution
WebSphere Application Server Family (Editions Comparison)
Configuration Management in Ansible
Web Assembly (on the server)

What's hot (20)

PPTX
Security Testing Training With Examples
PDF
Robot framework 을 이용한 기능 테스트 자동화
PPTX
Cross browser testing
PDF
[144]mobile앱에서 효율적인 storage 접근 방법
PDF
[오픈소스컨설팅] 프로메테우스 모니터링 살펴보고 구성하기
PDF
Loadrunner vs Jmeter
PPT
Test Automation Framework Designs
PPTX
Apache JMeter - A brief introduction
PPT
PDF
Offensive (Web, etc) Testing Framework: My gift for the community - BerlinSid...
PDF
Arista: DevOps for Network Engineers
PDF
JMeter vs LoadRunner | Edureka
PPT
Performance Testing
PPTX
Service Discovery using etcd, Consul and Kubernetes
PDF
Automation - Apache JMeter
PPTX
Load Testing with k6 framework
PPTX
Mobile Application Security
PPTX
Performance Testing using LoadRunner
PPTX
Pulsar in the Lakehouse: Apache Pulsar™ with Apache Spark™ and Delta Lake - P...
Security Testing Training With Examples
Robot framework 을 이용한 기능 테스트 자동화
Cross browser testing
[144]mobile앱에서 효율적인 storage 접근 방법
[오픈소스컨설팅] 프로메테우스 모니터링 살펴보고 구성하기
Loadrunner vs Jmeter
Test Automation Framework Designs
Apache JMeter - A brief introduction
Offensive (Web, etc) Testing Framework: My gift for the community - BerlinSid...
Arista: DevOps for Network Engineers
JMeter vs LoadRunner | Edureka
Performance Testing
Service Discovery using etcd, Consul and Kubernetes
Automation - Apache JMeter
Load Testing with k6 framework
Mobile Application Security
Performance Testing using LoadRunner
Pulsar in the Lakehouse: Apache Pulsar™ with Apache Spark™ and Delta Lake - P...
Ad

Similar to [이찬우 강사] Security plus saas security assessment_2021.04 (20)

PDF
July 31, 2020 - CSA LA event slides
PPTX
Cloud computing elisheba wiggins
PDF
Finance Technologies: Buy or Rent
PPTX
Build a complete security operations and compliance program using a graph dat...
PPTX
Multi cloud governance best practices - AWS, Azure, GCP
PPT
Up 2011-ken huang
PPTX
Cloud Seeding
PPTX
Codeless Security for the Apps You Buy & Build on AWS
PDF
Comparing cloud-computing-providers-11-factors-to-consider-profit bricks-ebook
PPTX
Security that works with, not against, your SaaS business
PPTX
Secure development 2014
PPTX
Geting cloud architecture right the first time linthicum interop fall 2013
PDF
Lightning Workshop London
PDF
(SACON) Anant Shrivastava - cloud pentesting
PDF
Webinar–That is Not How This Works
PDF
Best Practices for Your CMP RFP or RFI
PDF
Migrating to Cloud? 5 motivations and 10 key security architecture considerat...
PDF
Spring Cloud Stream: What's New in 2.x—and What's Next?
PDF
Cloud Computing and Security - by KLC Consulting
PDF
Practical Guide to Platform-as-a-Service
July 31, 2020 - CSA LA event slides
Cloud computing elisheba wiggins
Finance Technologies: Buy or Rent
Build a complete security operations and compliance program using a graph dat...
Multi cloud governance best practices - AWS, Azure, GCP
Up 2011-ken huang
Cloud Seeding
Codeless Security for the Apps You Buy & Build on AWS
Comparing cloud-computing-providers-11-factors-to-consider-profit bricks-ebook
Security that works with, not against, your SaaS business
Secure development 2014
Geting cloud architecture right the first time linthicum interop fall 2013
Lightning Workshop London
(SACON) Anant Shrivastava - cloud pentesting
Webinar–That is Not How This Works
Best Practices for Your CMP RFP or RFI
Migrating to Cloud? 5 motivations and 10 key security architecture considerat...
Spring Cloud Stream: What's New in 2.x—and What's Next?
Cloud Computing and Security - by KLC Consulting
Practical Guide to Platform-as-a-Service
Ad

More from Lee Chanwoo (20)

PDF
AI_introduction and requirements(2024.05.12).pdf
PDF
[이찬우 강사] bithumb_Privacy_Lecture(2021.12)
PDF
[이찬우 강사] Information security and digital sex crime_lecture(2020.09)
PDF
[이찬우 강사] Hyundai hcn busan_4th_indusry(2020.02.13)
PDF
[이찬우 강사] Persons with disabilities education(2020.02.05)
PDF
[이찬우 강사] Study on isms-p integration issues and major defects(20181017)
PDF
[이찬우 강사] Osstem implant information security education_final version(20181011)
PDF
[이찬우 강사] Sua_mentoring_career war vs employment battle_final_version(20180901)
PDF
[이찬우 강사] Korea it information security academy public seminar presentation_st...
PDF
[이찬우 강사] Korea it information security academy dongyang mirae university job ...
PDF
[이찬우 강사] Hsp 4th industry innovation and financial security fn(20180721)
PDF
[이찬우 강사] Global convergence forum security of crypto currency exchange 20180714
PDF
[이찬우 강사] Ing life information security education 20180625 final version
PDF
[이찬우 강사] Gyeonggi Institute of Science & Technology Promotion_employee inform...
PDF
Cyber resilience 201705
PDF
사이버 보안 트렌드_이찬우_2018020309_최종발표버전
PDF
Isaca knowledge concert 금융보안 발표자료 이찬우(2017.07.17)_final
PPTX
2016 sua 발표스터디 이찬우
PDF
2016 레몬세미나 발표자료 이찬우 final
PDF
2016 산업보안 공모전 일반부 장려상
AI_introduction and requirements(2024.05.12).pdf
[이찬우 강사] bithumb_Privacy_Lecture(2021.12)
[이찬우 강사] Information security and digital sex crime_lecture(2020.09)
[이찬우 강사] Hyundai hcn busan_4th_indusry(2020.02.13)
[이찬우 강사] Persons with disabilities education(2020.02.05)
[이찬우 강사] Study on isms-p integration issues and major defects(20181017)
[이찬우 강사] Osstem implant information security education_final version(20181011)
[이찬우 강사] Sua_mentoring_career war vs employment battle_final_version(20180901)
[이찬우 강사] Korea it information security academy public seminar presentation_st...
[이찬우 강사] Korea it information security academy dongyang mirae university job ...
[이찬우 강사] Hsp 4th industry innovation and financial security fn(20180721)
[이찬우 강사] Global convergence forum security of crypto currency exchange 20180714
[이찬우 강사] Ing life information security education 20180625 final version
[이찬우 강사] Gyeonggi Institute of Science & Technology Promotion_employee inform...
Cyber resilience 201705
사이버 보안 트렌드_이찬우_2018020309_최종발표버전
Isaca knowledge concert 금융보안 발표자료 이찬우(2017.07.17)_final
2016 sua 발표스터디 이찬우
2016 레몬세미나 발표자료 이찬우 final
2016 산업보안 공모전 일반부 장려상

Recently uploaded (20)

PDF
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PPTX
Digital Literacy And Online Safety on internet
PDF
The New Creative Director: How AI Tools for Social Media Content Creation Are...
PPTX
SAP Ariba Sourcing PPT for learning material
PDF
Unit-1 introduction to cyber security discuss about how to secure a system
PDF
Sims 4 Historia para lo sims 4 para jugar
PPTX
newyork.pptxirantrafgshenepalchinachinane
PDF
Introduction to the IoT system, how the IoT system works
PPTX
E -tech empowerment technologies PowerPoint
PPT
Design_with_Watersergyerge45hrbgre4top (1).ppt
PPTX
Internet___Basics___Styled_ presentation
PPTX
innovation process that make everything different.pptx
PDF
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
PPTX
presentation_pfe-universite-molay-seltan.pptx
PPTX
Mathew Digital SEO Checklist Guidlines 2025
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
PPTX
artificialintelligenceai1-copy-210604123353.pptx
DOCX
Unit-3 cyber security network security of internet system
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
SASE Traffic Flow - ZTNA Connector-1.pdf
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
Digital Literacy And Online Safety on internet
The New Creative Director: How AI Tools for Social Media Content Creation Are...
SAP Ariba Sourcing PPT for learning material
Unit-1 introduction to cyber security discuss about how to secure a system
Sims 4 Historia para lo sims 4 para jugar
newyork.pptxirantrafgshenepalchinachinane
Introduction to the IoT system, how the IoT system works
E -tech empowerment technologies PowerPoint
Design_with_Watersergyerge45hrbgre4top (1).ppt
Internet___Basics___Styled_ presentation
innovation process that make everything different.pptx
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
presentation_pfe-universite-molay-seltan.pptx
Mathew Digital SEO Checklist Guidlines 2025
Job_Card_System_Styled_lorem_ipsum_.pptx
artificialintelligenceai1-copy-210604123353.pptx
Unit-3 cyber security network security of internet system

[이찬우 강사] Security plus saas security assessment_2021.04

  • 1. 2021 SecurityPlus SaaS Security Assessment (From a practical point of view) 이 찬 우
  • 2. How to use cloud securely?
  • 3. In short, Customer should consider security in SDLC.
  • 4. 4 What’s wrong with this pictures?
  • 5. 5 Some things don’t change over time.
  • 7. Source Link : https://www.information-age.com/public-cloud-revenue-to-grow-6-3-in-2020-gartner-123490499/ The SaaS market is growing rapidly
  • 8. Source Link : https://www.bmc.com/blogs/saas-growth-trends/ What are the biggest companies?
  • 9. Source Link : https://snazlan.wordpress.com/2016/12/09/topic-0020-assessment-vs-evaluation/
  • 10. 10 Preparation → Assessment → F/up → Evaluation
  • 11. 11 “Can refer to various references for SaaS security assessment.” Preparation 2021 SecurityPlus SaaS Security Assessment ✓ KISA, Cloud Service Information Security Guide(SaaS) ✓ KISA, Cloud Vulnerability Analysis Guide ✓ SK Infosec, Cloud Security Guide ✓ CIS Benchmark for Cloud Services ✓ Vendor, Reference Architecture Guide for SaaS Copyright 2021. Chanwoo Lee All rights reserved. “Must develop our own framework.”
  • 12. Source Link : https://www.bettercloud.com/monitor/saas-operations-management/ SaaS Management Reference Architecture
  • 13. 13 “Can derive your requirements through a security assessment.” Assessment 2021 SecurityPlus SaaS Security Assessment ✓ Service : Business and background ✓ Data : Legal and Privacy ✓ Architecture : Design and Configuration ✓ Application : Vendor and Product ✓ Authority : Accounts and Authentication ✓ Security Control : Data Leakage and Malware ✓ Monitoring : Log feeding and Integration ✓ Stakeholder : Role and Responsibility Copyright 2021. Chanwoo Lee All rights reserved. “Must analyze various use cases.”
  • 14. Source Link : https://securityboulevard.com/2019/04/penetration-testing-for-saas-companies/ SaaS Security Reference Architecture
  • 15. 15 “Must implement the requirements you have derived.” F/up 2021 SecurityPlus SaaS Security Assessment [Data] ✓ Personal Information protection ✓ SSL/TLS Encryption ✓ Data and password Encryption ✓ Data Retention ✓ Tenant Restriction ✓ Sharing and Download permission disable ✓ Upload File Scanning ✓ Validation of file extension Copyright 2021. Chanwoo Lee All rights reserved.
  • 16. 16 “Must implement the requirements you have derived.” F/up 2021 SecurityPlus SaaS Security Assessment [Access] ✓ SSO/SAML Integration ✓ IP Restriction ✓ Multi-Factor Authentication ✓ Guest Access Control ✓ Session Timeout ✓ Concurrent-session Control ✓ Minimizing Pre-defined roles and permissions Copyright 2021. Chanwoo Lee All rights reserved.
  • 17. 17 “Must implement the requirements you have derived.” F/up 2021 SecurityPlus SaaS Security Assessment [Etc] ✓ Log management ✓ SIEM integration ✓ Management of API Key, Plug-in, Third-Party Program ✓ Application Configuration Analysis Copyright 2021. Chanwoo Lee All rights reserved. “Must discuss with stakeholders in advance.”
  • 18. Source Link : https://www.hubspot.com/pricing/ SaaS Pricing Model(Subscription)
  • 19. Source Link : https://www.atlassian.com/ko/software/jira Issue Tracking system(Ex. JIRA)
  • 20. 20 “Must get visibility and evaluate periodically.” Evaluation 2021 SecurityPlus SaaS Security Assessment ✓ Is the Assessment process operating as designed? ✓ What are the ways to improve the Assessment process? ✓ Has the security level of our company increased through the Assessment process? ✓ Did you miss anything in the Assessment process? ✓ What are the problems you are facing while Assessment process? ✓ What can you create after solving those problems? Copyright 2021. Chanwoo Lee All rights reserved. “Must evaluate on a paper and evidence basis.”
  • 21. Source Link : https://docs.servicenow.com/ Dashboard(Ex. ServiceNow)
  • 22. Source Link : https://congruentagile.com/2020/03/16/less-sprint/ Review and Retrospective
  • 24. 24 Wrap-up Customer should consider security in SDLC. Customer Need to develop their own framework.
  • 25. Changing people through technology Chanwoo Lee | Richard Blog blog.naver.com/jg706 Facebook www.facebook.com/jg706 Slideshare www.slideshare.net/jg706 Linkedin www.linkedin.com/in/jg706 Youtube www.youtube.com/channel/UC5Hs9p5_euXJbaf5E7Hx7Ag jg719411@nate.com | 010-4772-0130