fechar
fechar
Sua Rede do Amanhã
Sua Rede do Amanhã
Planeje seu caminho rumo a uma rede mais rápida, segura e resiliente projetada para os aplicativos e usuários aos quais você oferece suporte.
          Experimente a Netskope
          Get Hands-on With the Netskope Platform
          Here's your chance to experience the Netskope One single-cloud platform first-hand. Sign up for self-paced, hands-on labs, join us for monthly live product demos, take a free test drive of Netskope Private Access, or join us for a live, instructor-led workshops.
            Líder em SSE. Agora é líder em SASE de fornecedor único.
            Líder em SSE. Agora é líder em SASE de fornecedor único.
            A Netskope estreia como líder no Quadrante Mágico™ do Gartner® para Single-Vendor SASE
              Protegendo a IA generativa para leigos
              Protegendo a IA generativa para leigos
              Learn how your organization can balance the innovative potential of generative AI with robust data security practices.
                Modern data loss prevention (DLP) for Dummies eBook
                Prevenção Contra Perda de Dados (DLP) Moderna para Leigos
                Get tips and tricks for transitioning to a cloud-delivered DLP.
                  Livro SD-WAN moderno para SASE Dummies
                  Modern SD-WAN for SASE Dummies
                  Pare de brincar com sua arquitetura de rede
                    Compreendendo onde estão os riscos
                    Advanced Analytics transforms the way security operations teams apply data-driven insights to implement better policies. With Advanced Analytics, you can identify trends, zero in on areas of concern and use the data to take action.
                        Os 6 casos de uso mais atraentes para substituição completa de VPN herdada
                        Os 6 casos de uso mais atraentes para substituição completa de VPN herdada
                        Netskope One Private Access is the only solution that allows you to retire your VPN for good.
                          A Colgate-Palmolive protege sua “propriedade intelectual "” com proteção de dados inteligente e adaptável
                          A Colgate-Palmolive protege sua “propriedade intelectual "” com proteção de dados inteligente e adaptável
                            Netskope GovCloud
                            Netskope obtém alta autorização do FedRAMP
                            Escolha o Netskope GovCloud para acelerar a transformação de sua agência.
                              Let's Do Great Things Together
                              A estratégia de comercialização da Netskope, focada em Parcerias, permite que nossos Parceiros maximizem seu crescimento e lucratividade enquanto transformam a segurança corporativa.
                                Netskope solutions
                                Netskope Cloud Exchange
                                Netskope Cloud Exchange (CE) provides customers with powerful integration tools to leverage investments across their security posture.
                                  Suporte Técnico Netskope
                                  Suporte Técnico Netskope
                                  Nossos engenheiros de suporte qualificados estão localizados em todo o mundo e têm diversas experiências em segurança de nuvem, rede, virtualização, fornecimento de conteúdo e desenvolvimento de software, garantindo assistência técnica de qualidade e em tempo hábil.
                                    Vídeo da Netskope
                                    Treinamento Netskope
                                    Os treinamentos da Netskope vão ajudar você a ser um especialista em segurança na nuvem. Conte conosco para ajudá-lo a proteger a sua jornada de transformação digital e aproveitar ao máximo as suas aplicações na nuvem, na web e privadas.

                                      How Graph-powered SSPM Adds the Right Context

                                      Nov 30 2022

                                      SaaS apps have become the “easy button” for organizations seeking a fast and simple way to make foundational business apps available to their employees. According to Gartner, “SaaS remains the largest public cloud services market segment, forecasted to reach $176.6 billion in end-user spending in 2022,” growing 14% over 2021. And according to research by Netskope, the average company with 500–2,000 employees had 805 distinct apps and cloud services in use during the first half of 2021.

                                      The growing SaaS app security challenge

                                      Cloud access security brokers (CASBs) can be used to protect SaaS apps and often have both API-based and inline protections that can be used to control access, protect data, and even block threats and malware. However, when it comes to governance and compliance issues, CASBs were not designed for continuous monitoring of SaaS app configurations and security settings. Each SaaS app is unique and can have tens or hundreds of global settings to monitor and manage, and compliance admins can be quickly overwhelmed when responsible for monitoring a large number of SaaS apps. Often, they’re forced to increase the time between manual configuration checks or stop monitoring certain apps altogether.

                                      These are the challenges that first generation SaaS security posture management (SSPM) solutions were designed to address. For example, Netskope SSPM was initially built to consolidate and monitor an array of SaaS app configuration and security settings from within a single console, and excels at helping security practitioners minimize risky configurations, prevent configuration drift, and ensure compliance. It’s also great for configuration hardening, tracking public compliance metrics, user management, and automating common security tasks.

                                      However, as organizations become evermore reliant on SaaS apps, security analysts are increasingly being tasked with protecting them and the growing amount of sensitive information they store. Security analysts understand that your environment is constantly changing, and that all connected resources form a complex topography that needs to be shielded against ever-evolving threats, both external and internal. What’s more, the collaborative SaaS apps that organizations rely on often extend data, permissions, and privileges outside of their walled gardens—exposing sensitive information beyond the managed security perimeter and expanding the attack surface. Of particular concern are the large number of popular SaaS apps that allow the use of extensions and plugins via OAuth, or Open Authorization. SSPM tools can’t see unmanaged OAuth extensions and so connections to them are invisible, creating covert security vulnerabilities. Because of security gaps like this, Netskope believes that better, more comprehensive protections are needed to secure today’s sprawling SaaS app ecosystems, and now we are proud to unveil new capabilities that we believe will set the standard for the next generation of SSPM tools.

                                      Netskope Next Generation SaaS Security Posture Management (SSPM)

                                      Netskope has been rethinking how to best secure SaaS apps and has now added new features that go beyond what’s possible with traditional “asset list”-based configuration management tools. Netskope’s new, graph-powered SSPM regards SaaS apps as extensions of your business and maps their contextual information, including data models and all resource connections, into a single graph. Monitored assets and attributes are placed on the graph structure according to application-native data models and their related object hierarchies. Connections between elements and apps are drawn as graph edges, allowing security practitioners to accurately visualize and secure all connected resources.

                                      Netskope’s intuitive SSPM console helps security analysts to navigate and mine this rich trove of assets and contextual data. The graph structure enables more granular and accurate logic to be used when defining basic posture management policies such as continuous monitoring of security settings to prevent configuration drift, real-time incident investigations, asset inventory management, and threat surface and impact modeling. Security administrators gain detailed visibility into SaaS apps and their related assets so they can quickly determine how they’re connected and structured, what their security models look like, and what resources and data are directly or indirectly exposed by the asset.

                                      Graph-powered SSPM enables new SaaS security use cases

                                      Netskope’s graph-powered SSPM provides broader and deeper monitoring of SaaS apps, opening up some powerful new use cases for security analysts:

                                      • More granular search options expose hidden risks: Netskope graph-powered SSPM enables security analysts to evolve from basic searches, such as “Find all Salesforce users who do not have multi-factor authentication enabled,” to validating complex relationships like “Discover everyone who is using internet-connected Microsoft 365 plugins which have read and write access to our documents.” 
                                      • Graph-based visualization simplifies security analysis: The single graph allows administrators to create connections and enforce rules between apps, such as “List users who have their Azure AD account disabled but can still access Salesforce,” and also “Get me their active session tokens.”
                                      • Convert risky findings into monitoring policies with one click: The discovered anomalies and violations of company policies become continuous monitoring rules with a single click, alerting you immediately to any configuration drift.
                                      • Easily deploy uniform security policies: Graph-based security monitoring makes it easy to deploy uniform security policies across hundreds or thousands of SaaS apps.
                                      • Apply security models developed for advanced apps to less advanced apps, for example:
                                        • Apply identity provider group policies to an app that does not have native integration capabilities (e.g., extend Azure AD domain controls developed for an app that supports them natively to an app that doesn’t).
                                        • Ensure that all members of a sensitive chat room carry appropriate authorization.
                                        • Evaluate privileges and trustworthiness of suspected bot accounts which are accessing sensitive spaces.

                                      Conclusion

                                      Demand for SaaS apps will continue to grow along with their complexity, interconnectivity, and security challenges. As you work to transform your business critical workflows and security models to support new cloud-based apps and infrastructure, Netskope graph-powered SSPM is ready to help with the tools you need. A single interface and single graph reduce the effort and complexity of securing dozens of high-risk SaaS apps. Netskope helps you manage multiple security environments and enables you to connect and extend security capabilities to additional platforms, strengthening your overall security posture and reducing risk. Find more information at Netskope SSPM or contact us directly.

                                      author image
                                      Eetu Korhonen
                                      Eetu Korhonen is a Security Researcher on Netskope's Security Posture Management team. He has set his mission to elevate the standard of cloud defensive tools.
                                      Eetu Korhonen is a Security Researcher on Netskope's Security Posture Management team. He has set his mission to elevate the standard of cloud defensive tools.
                                      author image
                                      Dan Frey
                                      Dan Frey is the Product Marketing Director for Netskope Cloud Security products including CSPM, SSPM, CASB API, and CASB Inline.
                                      Dan Frey is the Product Marketing Director for Netskope Cloud Security products including CSPM, SSPM, CASB API, and CASB Inline.

                                      Mantenha-se informado!

                                      Assine para receber as últimas novidades do Blog da Netskope