Lab 2 โ SaaS Security Posture & Third-Party Application Governance
Explore available filters, tabs, and drill-downs beyond the examples. Dashboard values and application lists may vary.
Task 1 โ SaaS Security Posture Management (SSPM)โ
Step 1 โ Navigate to the SSPM Portalโ
- In the Experience Center, enable Switch to Existing Reports and open Analytics โ SaaS Security Report.
- Select Posture Management.
- Click Posture Management โ to launch the SSPM portal at
apptotal.zscaler.com.

Step 2 โ Review the SSPM Dashboardโ
Review:
- Enabled Controls โ active controls and severity breakdown.
- Status Summary โ Fail, Pass, Partial, Pending, and Disabled.
- Controls by Platform โ compare findings across SaaS platforms.
- Failed Controls Remediation Matrix โ compare severity and remediation effort.

Select a control and explore Remediation, Compliance, Assets, Audit log, and Notes. Identify what failed, which assets are affected, and the recommended remediation.

Step 3 โ Prioritize Failed Controlsโ
Review the Failed Controls Remediation Matrix. Start with High Severity / Low Effort findings, then compare other cells to understand the trade-off between risk and remediation effort.

Step 4 โ Review Compliance Mappingโ
Select Compliance in the left navigation.
- Frameworks: expand a framework to review its controls and pass/fail results.
- Platforms: compare compliance findings across SaaS platforms.
- Review the mapping table's Framework, Control ID, Security Check count, Status, and Tenant.

Consider which failed control would be most useful to address first, based on severity, effort, and compliance relevance.
Task 2 โ Third-Party Application Governanceโ
Step 5 โ Review the App Dashboardโ
Select App Dashboard in the SSPM portal.
Review Active Apps, Risky Apps, Affected Users, and Deactivated Apps. Then explore:
- Apps by Classification โ Sanctioned, Unsanctioned, Reviewing, and Unclassified.
- Apps by Finding Type โ Potentially Harmful, Dormant, and Overprivileged.
- Top Apps by Risk Score and Highlights โ identify apps worth investigating.

Step 6 โ Review Active Apps and App Detailโ
Select Apps โ Active Apps (App Status: Enabled). Compare each app's Publisher, Platform, Users, Risk Score, and Access Type.
Open an app, such as Keeperยฎ Password, and review:
| Tab | What to examine |
|---|---|
| Overview | Classification, risk score, connection graph, and usage timeline |
| Access | Permission scopes and OAuth grants |
| Activities | Recent app activity |
| Details | Publisher, marketplace metadata, and findings |
| Notes | Existing review history |

Compare the permissions granted with the app's business purpose. OAuth integrations can access SaaS data directly, making this an important view alongside inline traffic inspection.
Key Takeawaysโ
- SSPM: identify SaaS misconfigurations and affected assets.
- Remediation and compliance: prioritize findings using severity, effort, and framework mappings.
- App Governance: review third-party permissions, activity, and risk.
What comes next: Lab 3 moves to endpoint data, user activity, applications, and connected-device inventory.