# What is SaaS Security?

> Software as a service (SaaS) security is the practice of protecting an organization’s data, identities, configurations, integrations, and business processes in provider-operated applications.

- Canonical URL: https://yellowcube.eu/glossary/saas-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

The provider runs the application and underlying platform, while the customer controls tenant settings, user access, data sharing, connected applications, and aspects of retention and monitoring. Exact responsibilities depend on the service and contract.

The term covers both provider and customer perspectives; this definition emphasizes customer use. With little access to underlying systems, customers depend on provider assurance, supported settings, audit data, incident coordination, portability, and exit arrangements.

### Key points

- **Service governance:** Approve services and use cases, classify permitted data, assess provider and subprocessor responsibilities, assign an owner, and maintain renewal and exit decisions.
- **Identity and configuration:** Federate authentication where appropriate, enforce strong administration and least privilege, govern sharing and guest access, review defaults, and protect recovery and emergency accounts.
- **Data and integrations:** Control application consent, API tokens, automation, imports, exports, retention, deletion, and backups; collect useful events without assuming the provider records every relevant action.
- **Important limitation:** A secure provider does not make a tenant’s permissions, sharing, integrations, endpoints, or data handling safe, while careful tenant configuration cannot remove provider compromise or outage risk. SaaS APIs, logs, encryption choices, recovery options, and administrative controls may also be limited by the service or subscription tier.

### Related terms

[SaaS security posture management (SSPM)](<https://yellowcube.eu/glossary/saas-security-posture-management/>) · [Cloud access security broker (CASB)](<https://yellowcube.eu/glossary/cloud-access-security-broker/>) · [Cloud security](<https://yellowcube.eu/glossary/cloud-security/>) · [Data loss prevention (DLP)](<https://yellowcube.eu/glossary/data-loss-prevention/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Cloud application security](<https://yellowcube.eu/glossary/cloud-application-security/>)

### Sources

[NIST SP 800-210: General Access Control Guidance for Cloud Systems](https://csrc.nist.gov/pubs/sp/800/210/final) · [CISA Secure Cloud Business Applications (SCuBA)](https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project) · [Cloud Security Alliance: Cloud Controls Matrix v4.1](https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

