发表机构
Virginia Tech(弗吉尼亚理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对受管制企业SaaS引入难题,提出控制驱动的端到端框架,集成多领域到统一生命周期模型,采用阶段式方法,有结构化生命周期、跨域控制映射和实用设计模式等贡献,可助企业减少引入摩擦、提升安全性。
AI 中文摘要
随着企业越来越多地将软件即服务(SaaS)平台用于关键任务功能,引入这些服务已成为一项复杂挑战,远超采购和基本安全审查。在受管制环境中,SaaS引入必须应对多个相互依存的控制领域,常孤立执行,导致上线延迟、评估重复等问题。本文提出一个控制驱动的端到端SaaS引入框架,将第三方风险管理、网络安全等集成到统一生命周期模型。该框架采用基于阶段的方法,涵盖多个阶段。关键贡献包括结构化生命周期、跨域控制映射及实用设计模式。由企业级实施经验和参考治理清单支持,此框架能帮助组织减少引入摩擦等。
英文摘要
As enterprises increasingly adopt Software-as-a-Service (SaaS) platforms for mission-critical functions, onboarding these services has emerged as a complex governance challenge. In regulated environments, SaaS onboarding must address multiple interdependent control domains, including Third-Party Risk Management (TPRM), cybersecurity assessment, Identity and Access Management (IAM), and disaster recovery (DR). These domains are often executed in isolation, resulting in delayed go-lives, duplicated assessments, unclear ownership, and residual operational risk. This paper proposes a control-driven, end-to-end SaaS onboarding framework that integrates TPRM, cybersecurity, IAM, and DR into a unified lifecycle model spanning intake and risk scoping, architecture validation, identity design, resilience assessment, and post-production governance. Key contributions include: (1) a structured onboarding lifecycle emphasizing sequencing and dependency management across control domains; (2) a cross-domain control mapping that highlights failure modes caused by siloed reviews; and (3) practical design patterns for secure connectivity, federated identity, least-privilege access, and shared-responsibility disaster recovery. Unlike prior frameworks that treat these domains independently, this work introduces a formally gate-sequenced, cross-domain lifecycle, the first integrated model that encodes mandatory dependency ordering across all four control domains with traceable evidence artifacts at each stage, directly addressing structural gap responsible for enterprise-owned SaaS failures such as the 2024 Ticketmaster-Snowflake breach.