閉める
閉める
明日に向けたネットワーク
明日に向けたネットワーク
サポートするアプリケーションとユーザー向けに設計された、より高速で、より安全で、回復力のあるネットワークへの道を計画します。
          Netskopeを体験しませんか?
          Netskopeプラットフォームを実際に体験する
          Netskope Oneのシングルクラウドプラットフォームを直接体験するチャンスです。自分のペースで進められるハンズオンラボにサインアップしたり、毎月のライブ製品デモに参加したり、Netskope Private Accessの無料試乗に参加したり、インストラクター主導のライブワークショップに参加したりできます。
            SSEのリーダー。 現在、シングルベンダーSASEのリーダーです。
            SSEのリーダー。 現在、シングルベンダーSASEのリーダーです。
            Netskope、2024年ガートナー、シングルベンダーSASEのマジック・クアドラントでリーダーの1社の位置付けと評価された理由をご確認ください。
              ダミーのためのジェネレーティブAIの保護
              ダミーのためのジェネレーティブAIの保護
              ジェネレーティブ AI の革新的な可能性と堅牢なデータ セキュリティ プラクティスのバランスを取る方法をご覧ください。
                ダミーのための最新のデータ損失防止(DLP)eBook
                最新の情報漏えい対策(DLP)for Dummies
                クラウド配信型 DLP に移行するためのヒントとコツをご紹介します。
                  SASEダミーのための最新のSD-WAN ブック
                  SASEダミーのための最新のSD-WAN
                  遊ぶのをやめる ネットワークアーキテクチャに追いつく
                    リスクがどこにあるかを理解する
                    Advanced Analytics は、セキュリティ運用チームがデータ主導のインサイトを適用してより優れたポリシーを実装する方法を変革します。 Advanced Analyticsを使用すると、傾向を特定し、懸念事項に的を絞って、データを使用してアクションを実行できます。
                        レガシーVPNを完全に置き換えるための6つの最も説得力のあるユースケース
                        レガシーVPNを完全に置き換えるための6つの最も説得力のあるユースケース
                        Netskope One Private Accessは、VPNを永久に廃止できる唯一のソリューションです。
                          Colgate-Palmoliveは、スマートで適応性のあるデータ保護により「知的財産」を保護します
                          Colgate-Palmoliveは、スマートで適応性のあるデータ保護により「知的財産」を保護します
                            Netskope GovCloud
                            NetskopeがFedRAMPの高認証を達成
                            政府機関の変革を加速するには、Netskope GovCloud を選択してください。
                              一緒に素晴らしいことをしましょう
                              Netskopeのパートナー中心の市場開拓戦略により、パートナーは企業のセキュリティを変革しながら、成長と収益性を最大化できます。
                                Netskopeソリューション
                                Netskope Cloud Exchange
                                Netskope Cloud Exchange(CE)は、セキュリティ体制全体で投資を活用するための強力な統合ツールをお客様に提供します。
                                  Netskopeテクニカルサポート
                                  Netskopeテクニカルサポート
                                  クラウドセキュリティ、ネットワーキング、仮想化、コンテンツ配信、ソフトウェア開発など、多様なバックグラウンドを持つ全世界にいる有資格のサポートエンジニアが、タイムリーで質の高い技術支援を行っています。
                                    Netskopeの動画
                                    Netskopeトレーニング
                                    Netskopeのトレーニングは、クラウドセキュリティのエキスパートになるためのステップアップに活用できます。Netskopeは、お客様のデジタルトランスフォーメーションの取り組みにおける安全確保、そしてクラウド、Web、プライベートアプリケーションを最大限に活用するためのお手伝いをいたします。

                                      How Graph-powered SSPM Adds the Right Context

                                      Nov 30 2022

                                      SaaS apps have become the “easy button” for organizations seeking a fast and simple way to make foundational business apps available to their employees. According to Gartner, “SaaS remains the largest public cloud services market segment, forecasted to reach $176.6 billion in end-user spending in 2022,” growing 14% over 2021. And according to research by Netskope, the average company with 500–2,000 employees had 805 distinct apps and cloud services in use during the first half of 2021.

                                      The growing SaaS app security challenge

                                      Cloud access security brokers (CASBs) can be used to protect SaaS apps and often have both API-based and inline protections that can be used to control access, protect data, and even block threats and malware. However, when it comes to governance and compliance issues, CASBs were not designed for continuous monitoring of SaaS app configurations and security settings. Each SaaS app is unique and can have tens or hundreds of global settings to monitor and manage, and compliance admins can be quickly overwhelmed when responsible for monitoring a large number of SaaS apps. Often, they’re forced to increase the time between manual configuration checks or stop monitoring certain apps altogether.

                                      These are the challenges that first generation SaaS security posture management (SSPM) solutions were designed to address. For example, Netskope SSPM was initially built to consolidate and monitor an array of SaaS app configuration and security settings from within a single console, and excels at helping security practitioners minimize risky configurations, prevent configuration drift, and ensure compliance. It’s also great for configuration hardening, tracking public compliance metrics, user management, and automating common security tasks.

                                      However, as organizations become evermore reliant on SaaS apps, security analysts are increasingly being tasked with protecting them and the growing amount of sensitive information they store. Security analysts understand that your environment is constantly changing, and that all connected resources form a complex topography that needs to be shielded against ever-evolving threats, both external and internal. What’s more, the collaborative SaaS apps that organizations rely on often extend data, permissions, and privileges outside of their walled gardens—exposing sensitive information beyond the managed security perimeter and expanding the attack surface. Of particular concern are the large number of popular SaaS apps that allow the use of extensions and plugins via OAuth, or Open Authorization. SSPM tools can’t see unmanaged OAuth extensions and so connections to them are invisible, creating covert security vulnerabilities. Because of security gaps like this, Netskope believes that better, more comprehensive protections are needed to secure today’s sprawling SaaS app ecosystems, and now we are proud to unveil new capabilities that we believe will set the standard for the next generation of SSPM tools.

                                      Netskope Next Generation SaaS Security Posture Management (SSPM)

                                      Netskope has been rethinking how to best secure SaaS apps and has now added new features that go beyond what’s possible with traditional “asset list”-based configuration management tools. Netskope’s new, graph-powered SSPM regards SaaS apps as extensions of your business and maps their contextual information, including data models and all resource connections, into a single graph. Monitored assets and attributes are placed on the graph structure according to application-native data models and their related object hierarchies. Connections between elements and apps are drawn as graph edges, allowing security practitioners to accurately visualize and secure all connected resources.

                                      Netskope’s intuitive SSPM console helps security analysts to navigate and mine this rich trove of assets and contextual data. The graph structure enables more granular and accurate logic to be used when defining basic posture management policies such as continuous monitoring of security settings to prevent configuration drift, real-time incident investigations, asset inventory management, and threat surface and impact modeling. Security administrators gain detailed visibility into SaaS apps and their related assets so they can quickly determine how they’re connected and structured, what their security models look like, and what resources and data are directly or indirectly exposed by the asset.

                                      Graph-powered SSPM enables new SaaS security use cases

                                      Netskope’s graph-powered SSPM provides broader and deeper monitoring of SaaS apps, opening up some powerful new use cases for security analysts:

                                      • More granular search options expose hidden risks: Netskope graph-powered SSPM enables security analysts to evolve from basic searches, such as “Find all Salesforce users who do not have multi-factor authentication enabled,” to validating complex relationships like “Discover everyone who is using internet-connected Microsoft 365 plugins which have read and write access to our documents.” 
                                      • Graph-based visualization simplifies security analysis: The single graph allows administrators to create connections and enforce rules between apps, such as “List users who have their Azure AD account disabled but can still access Salesforce,” and also “Get me their active session tokens.”
                                      • Convert risky findings into monitoring policies with one click: The discovered anomalies and violations of company policies become continuous monitoring rules with a single click, alerting you immediately to any configuration drift.
                                      • Easily deploy uniform security policies: Graph-based security monitoring makes it easy to deploy uniform security policies across hundreds or thousands of SaaS apps.
                                      • Apply security models developed for advanced apps to less advanced apps, for example:
                                        • Apply identity provider group policies to an app that does not have native integration capabilities (e.g., extend Azure AD domain controls developed for an app that supports them natively to an app that doesn’t).
                                        • Ensure that all members of a sensitive chat room carry appropriate authorization.
                                        • Evaluate privileges and trustworthiness of suspected bot accounts which are accessing sensitive spaces.

                                      Conclusion

                                      Demand for SaaS apps will continue to grow along with their complexity, interconnectivity, and security challenges. As you work to transform your business critical workflows and security models to support new cloud-based apps and infrastructure, Netskope graph-powered SSPM is ready to help with the tools you need. A single interface and single graph reduce the effort and complexity of securing dozens of high-risk SaaS apps. Netskope helps you manage multiple security environments and enables you to connect and extend security capabilities to additional platforms, strengthening your overall security posture and reducing risk. Find more information at Netskope SSPM or contact us directly.

                                      author image
                                      Eetu Korhonen
                                      Eetu Korhonen is a Security Researcher on Netskope's Security Posture Management team. He has set his mission to elevate the standard of cloud defensive tools.
                                      Eetu Korhonen is a Security Researcher on Netskope's Security Posture Management team. He has set his mission to elevate the standard of cloud defensive tools.
                                      author image
                                      Dan Frey
                                      Dan Frey is the Product Marketing Director for Netskope Cloud Security products including CSPM, SSPM, CASB API, and CASB Inline.
                                      Dan Frey is the Product Marketing Director for Netskope Cloud Security products including CSPM, SSPM, CASB API, and CASB Inline.

                                      Stay informed!

                                      Subscribe for the latest from the Netskope Blog