User Tools

Site Tools


corpgov:saasapp

SaaS Application Controls

Control Satisfaction Matrix

Framework Standard CategoryControls Satisfied 800-53r4 Controls ISO/SEC 27001 Audit Controls
DLZP Internal None None None None None

Major Document History

Date Comment Who
8/16/2019 Added SaaS Matrix, Quarterly Rpt Matrix Tharp
8/19/2019 Updated Quarterly Rpt Matrix Tharp
8/29/2019 Copied Content For IS-1 SOC submission Tharp
10/6/2021 Policy's Reviewed for Audit Tharp

SaaS Compliance Mapping Matrix

A-lign Ref: IS-36, IS-37, IS-38, IS-39, IS-40, IS-41, IS-42, IS-43, IS-44, IS-45, IS-46, IS-47, COB-1, COB-2, COB-3, COB-4, COB-5, COB-6, COB-7, COB-8

ApplicationBusiness UseApp TypeApp OwnerRecovery CapabilityAdmin RightsUser RightsPassWord (Req)Auth Settings (Std; MFA; Other)Lockout PolicyLogging PolicyAlert of suspicious activityAccess review by Mgt.Logs (Network; O/S; DB; App; VPN)? Review by management?Backup policy and proceduresBackup encryptionBackup Restore ApprovalDisater RecoveryUpdates/Patches (O/S; Security; Bugs)
AWS Command Line Manage Cloud InfrastructureCloud Service ProviderDave BrunetAlternate RegionAccount AdminIAM RoleComplex - ConfigurableMFA - AvailableN/ACloudWatchAvailableYesAd-hocN/AN/AN/AN/AN/A
AWS Console Manage Cloud InfrastructureCloud Service ProviderDave BrunetAlternate RegionAccount AdminIAM RoleComplex - ConfigurableMFA - AvailableN/ACloudWatchAvailableYesAd-hocN/AN/AN/AN/AN/A
AWS Object Storage S3Cloud Object StorageCloud Service ProviderDave BrunetAlternate RegionAccount AdminIAM RoleComplex - ConfigurableMFA - AvailableN/ACloudWatchAvailableYesAd-hocN/AN/AN/AN/AN/A
DLZP Wiki Internal Policies and Operations DataSaaSDave BrunetAutoRestore with 15 Min of Data Loss Potential Account Admin Wiki ACLComplex - ConfigurableStandardNoCloudWatchYesYesYesEvery 4 hoursYesYesAuto Recover < 15 Data LossYes
DropBox Business File SharingSaaSLisa BrunetInherited from providerAccount AdminRole BasedComplex - ConfigurableMFA - AvailableNot PublishedInherited from providerInherited from providerYesYesInherited - Default 120 DaysInheritedN/AN/AN/A
Email Amazon WorkMailSaaSDave BrunetInherited from providerAccount AdminUser Access Complex - ConfigurableScreen Lock - Enabled - Mobile Email - Encryption Required10 Attempts Inherited from providerInherited from providerYesNoInherited from providerInherited from providerN/AN/AN/A
Google AppsInterative File SharingSaaSDave BrunetInherited from providerAccount AdminUser Access Complex - ConfigurableMFA - Available4 Login AttemptsInherited from providerInherited from providerYesAd-hocInherited from providerInherited from providerN/AN/AN/A
Instant Messaging Apps (Google Hangouts; Slack; SMS Text)SaaSDave BrunetInherited from providerAccount AdminUser Access Complex - ConfigurableVariousInherited from providerInherited from providerInherited from providerYesNoInherited from providerInherited from providerN/AN/AN/A
PriTunl VPNSystems Admin SoftVPNCOTSDave BrunetAutorestore with no Data LossAccount AdminUser Access N/AMFA - Enabled3 Login attemptsCloudWatchNoYesAd-hocDailyYesYesN/AYes
Trend MicroWorkstation Intrusion DetectionSaaSLisa BrunetInherited from providerAccount AdminNo AccessN/AN/AInherited from providerInherited from providerInherited from providerYesNoInherited from providerInherited from providerN/AN/AYes
Voice Phone - CellularSaaSLisa BrunetInherited from providerAccount AdminUser Access PINScreen Lock - Enabled - Encryption Required Inherited from providerInherited from providerNoYesPhone BillInherited from providerInherited from providerN/AN/AN/A
Zoho CRMSales Client ActivitySaaSLisa BrunetInherited from providerAccount AdminUser Access Complex - ConfigurableMFA - EnabledInherited from providerInherited from providerInherited from providerYesNoInherited from providerInherited from providerN/AN/AN/A
Zoho Project Project Management; Change Management; Issue Management (client tickets)SaaSLisa BrunetInherited from providerAccount AdminUser Access Complex - ConfigurableMFA - AvailableInherited from providerInherited from providerInherited from providerYesNoInherited from providerInherited from providerN/AN/AN/A
ZoomTeleconferencing SaaSLisa BrunetInherited from providerAccount AdminUser Access Complex - ConfigurableMFA - AvailableInherited from providerInherited from providerInherited from providerYesNoInherited from providerInherited from providerN/AN/AN/A

SaaS Quarterly Reports Matrix

QTR ReportsApp Admin Rpt/TaskApp User Rpt/TaskLog Review RPT/TaskVPN Access Logs/TaskAntivirus Settings RPT/TaskUpdates-Patches/TaskCode Changes/Task
AWS Command Line Yes/M5-T36Yes/M5-T36Yes/M5-T36NoNoNoNo
AWS Console Yes/M5-T36Yes/M5-T36Yes/M5-T36NoNoNoNo
AWS Object Storage S3Yes/M5-T36Yes/M5-T36Yes/M5-T36NoNoNoNo
DLZP Wiki Yes/M5-T30Yes/M5-T30Yes/M5-T30NoNoYesYes/M5-T30
DropBox Yes/M5-T37Yes/M5-T37Yes/M5-T37NoNoNoNo
Email Yes/M5-T37Yes/M5-T37Yes/M5-T37NoNoNoNo
Google DocsYes/M5-T38Yes/M5-T38Yes/M5-T38NoNoNoNo
Instant Messaging Apps N/AN/AN/ANoNoNoNo
PriTunl VPNYes/M5-T27Yes/M5-T27Yes/M5-T27Yes/M5-T27NoYesNo
Trend MicroYes/M5-T37Yes/M5-T37Yes/M5-T37NoYes/M5-T37YesNo
Voice N/AN/AN/ANoNoNoNo
Zoho CRMYes/M5-T37Yes/M5-T37Yes/M5-T37NoNoNoNo
Zoho Project Yes/M5-T37Yes/M5-T37Yes/M5-T37NoNoNoNo
ZoomYes/M5-T37Yes/M5-T37Yes/M5-T37NoNoNoNo
/opt/bitnami/dokuwiki/data/pages/corpgov/saasapp.txt · Last modified: 2021/10/06 21:48 by brian.tharp