Skip to main content

Lab 2 โ€“ SaaS Security Posture & Third-Party Application Governance

Lab 2โฑ 15 min๐Ÿข Enterprise Tenant ยท Read-Only๐Ÿ‘ค Alex
SaaS Security Posture & Third-Party Application Governance
As Alex, review SaaS misconfigurations, compliance gaps, and third-party applications with access to Dataparity's data.

Explore available filters, tabs, and drill-downs beyond the examples. Dashboard values and application lists may vary.

Task 1 โ€” SaaS Security Posture Management (SSPM)โ€‹

Step 1 โ€” Navigate to the SSPM Portalโ€‹

  1. In the Experience Center, enable Switch to Existing Reports and open Analytics โ†’ SaaS Security Report.
  2. Select Posture Management.
  3. Click Posture Management โ†— to launch the SSPM portal at apptotal.zscaler.com.

Navigate to the Posture Management portal

Step 2 โ€” Review the SSPM Dashboardโ€‹

Review:

  • Enabled Controls โ€” active controls and severity breakdown.
  • Status Summary โ€” Fail, Pass, Partial, Pending, and Disabled.
  • Controls by Platform โ€” compare findings across SaaS platforms.
  • Failed Controls Remediation Matrix โ€” compare severity and remediation effort.

SSPM dashboard โ€” controls, status, platforms, and remediation matrix

Select a control and explore Remediation, Compliance, Assets, Audit log, and Notes. Identify what failed, which assets are affected, and the recommended remediation.

Control detail โ€” Remediation, Compliance, Assets, Audit log, and Notes

Step 3 โ€” Prioritize Failed Controlsโ€‹

Review the Failed Controls Remediation Matrix. Start with High Severity / Low Effort findings, then compare other cells to understand the trade-off between risk and remediation effort.

Failed Controls Remediation Matrix โ€” Severity ร— Effort

Step 4 โ€” Review Compliance Mappingโ€‹

Select Compliance in the left navigation.

  • Frameworks: expand a framework to review its controls and pass/fail results.
  • Platforms: compare compliance findings across SaaS platforms.
  • Review the mapping table's Framework, Control ID, Security Check count, Status, and Tenant.

Compliance โ€” Frameworks, Platforms, and control mappings

Consider which failed control would be most useful to address first, based on severity, effort, and compliance relevance.

Task 2 โ€” Third-Party Application Governanceโ€‹

Step 5 โ€” Review the App Dashboardโ€‹

Select App Dashboard in the SSPM portal.

Review Active Apps, Risky Apps, Affected Users, and Deactivated Apps. Then explore:

  • Apps by Classification โ€” Sanctioned, Unsanctioned, Reviewing, and Unclassified.
  • Apps by Finding Type โ€” Potentially Harmful, Dormant, and Overprivileged.
  • Top Apps by Risk Score and Highlights โ€” identify apps worth investigating.

App Dashboard โ€” metrics, classifications, findings, and risk scores

Step 6 โ€” Review Active Apps and App Detailโ€‹

Select Apps โ†’ Active Apps (App Status: Enabled). Compare each app's Publisher, Platform, Users, Risk Score, and Access Type.

Open an app, such as Keeperยฎ Password, and review:

TabWhat to examine
OverviewClassification, risk score, connection graph, and usage timeline
AccessPermission scopes and OAuth grants
ActivitiesRecent app activity
DetailsPublisher, marketplace metadata, and findings
NotesExisting review history

Active Apps and application detail tabs

Compare the permissions granted with the app's business purpose. OAuth integrations can access SaaS data directly, making this an important view alongside inline traffic inspection.

Key Takeawaysโ€‹

  • SSPM: identify SaaS misconfigurations and affected assets.
  • Remediation and compliance: prioritize findings using severity, effort, and framework mappings.
  • App Governance: review third-party permissions, activity, and risk.

What comes next: Lab 3 moves to endpoint data, user activity, applications, and connected-device inventory.

๐ŸŽ“
Lab Assistant
Zenith Live 2026 ยท Dataparity
Lab 2 โ€” SaaS Posture
Browse all topics