Open Access

An Author’s Taxonomy of Customer-Observable Security Controls in SaaS Platforms

4 Head of Department, Platform Cybersecurity Center, JSC Sberbank-Technologies, Moscow, Russia

Abstract

The software-as-a-service model places most technical security mechanisms in the provider's hands, while the customer remains accountable for data, identities, and regulatory outcomes. Certification reports describe what a provider has implemented, yet reveal little about what a tenant can monitor and verify on its own. This article introduces a taxonomy that classifies security controls for SaaS platforms by the degree to which they are observable to the tenant. The proposed scale contains four levels: directly observable controls, controls verifiable on request, attestation-only controls, and non-observable controls. The classification procedure draws on the SaaS Security Capability Framework of the Cloud Security Alliance, the Cloud Controls Matrix, NIST SP 800-53, and ISO/IEC 27001, and the scale is applied to three control domains: logging and monitoring, security incident management, together with e-discovery and cloud forensics, and identity and access management. The selection of domains mirrors the framework sections shaped through first-hand work within the Cloud Security Alliance working group. Observations from a corporate program that hardened seven SaaS platforms serving more than 100,000 active users illustrate how the scale behaves in practice. The taxonomy gives tenants a shared language for procurement, contractual negotiations, and continuous assurance, and gives providers a roadmap for increasing visibility into their controls. A systematic classification of SaaS controls along the observability axis has not been proposed before.

Keywords

References

Alghofaili, Y., Albattah, A., Alrajeh, N., Rassam, M. A., & Al-rimy, B. A. S. (2021). Secure cloud infrastructure: A survey on issues, current solutions, and open challenges. Applied Sciences, 11(19), 9005. https://doi.org/10.3390/app11199005
Alshabibi, M. M., Bu dookhi, A. K., & Hafizur Rahman, M. M. (2024). Forensic investigation, challenges, and issues of cloud data: A systematic literature review. Computers, 13(8), 213. https://doi.org/10.3390/computers13080213
Azad, M. A., Abdullah, S., Arshad, J., Lallie, H., & Ahmed, Y. H. (2024). Verify and trust: A multidimensional survey of zero-trust security in the age of IoT. Internet of Things, 27, 101227. https://doi.org/10.1016/j.iot.2024.101227
Badirova, A., Dabbaghi Varnosfaderani, S., Fatemi Moghaddam, F., Wieder, P., & Yahyapour, R. (2023). A survey on identity and access management for cross-domain dynamic users: Issues, solutions, and challenges. IEEE Access, 11, 61660–61679. https://doi.org/10.1109/ACCESS.2023.3279492
Chauhan, M., & Shiaeles, S. (2023). An analysis of cloud security frameworks, problems and proposed solutions. Network, 3(3), 422–450. https://doi.org/10.3390/network3030018
Cloud Security Alliance. (2021). Cloud Controls Matrix and CAIQ v4.0. Cloud Security Alliance.
Cloud Security Alliance. (2025). SaaS Security Capability Framework (SSCF), version 1.0. Cloud Security Alliance.
Humayun, M., Niazi, M., Almufareh, M. F., Jhanjhi, N. Z., Mahmood, S., & Alshayeb, M. (2022). Software-as-a-service security challenges and best practices: A multivocal literature review. Applied Sciences, 12(8), 3953. https://doi.org/10.3390/app12083953
International Organization for Standardization. (2022). ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection – Information security management systems – Requirements. ISO.
Jeong, B., Kim, J., Lee, S., & Park, J. (2026). FOREST: Inspecting and tracking RESTful APIs for constructing a cloud forensic knowledge base. Forensic Science International: Digital Investigation, 56, 302070. https://doi.org/10.1016/j.fsidi.2026.302070
Joint Task Force. (2020). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53, Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5
Mushtaq, S., Mohsin, M., & Mushtaq, M. M. (2025). A systematic literature review on the implementation and challenges of zero trust architecture across domains. Sensors, 25(19), 6118. https://doi.org/10.3390/s25196118
Punia, A., Gulia, P., Gill, N. S., Ibeke, E., Iwendi, C., & Shukla, P. K. (2024). A systematic review on blockchain-based access control systems in cloud environment. Journal of Cloud Computing, 13, 146. https://doi.org/10.1186/s13677-024-00697-7
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
Suhonen, T., & Martínez, C. (2024). Continuous auditing and continuous certification of cloud services in MEDINA: Security auditor’s view. Open Research Europe, 3, 208. https://doi.org/10.12688/openreseurope.16703.2
Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero Trust Architecture (ZTA): A comprehensive survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/ACCESS.2022.3174679
Tuyishime, E., Balan, T. C., Cotfas, P. A., Cotfas, D. T., & Rekeraho, A. (2023). Enhancing cloud security: Proactive threat monitoring and detection using a SIEM-based approach. Applied Sciences, 13(22), 12359. https://doi.org/10.3390/app132212359

Most read articles by the same author(s)

1 2 3 4 5 6 7 8 9 10 > >> 

Similar Articles

71-80 of 101

You may also start an advanced similarity search for this article.