ÏÖÔÚ£¬Ô½À´Ô½¶àµÄ×éÖ¯ÒÀÀµ SaaS Ó¦ÓÃÀ´¿ªÕ¹ÒµÎñ£¬±£ÕÏÕâЩӦÓõĻƽð³Ç¹ÙÍøÐÔ±äµÃÖÁ¹ØÖØÒª¡£Èç¹ûȱ·¦ÓÐÁ¦µÄ·À»¤´ëÊ©£¬Ãô¸ÐÊý¾Ý¡¢Óû§·ÃÎÊȨÏÞÒÔ¼°ÔÆ»ù´¡ÉèÊ©¶¼¿ÉÄÜÃæÁÙ±»¹¥»÷µÄ·çÏÕ¡£SaaS »Æ½ð³Ç¹ÙÍø²»Äܽö¿¿µ¥Ò»Êֶνâ¾ö£¬¶øÊÇÐèÒª¶àÖÖ·½·¨À´Ó¦¶ÔÉí·Ý¡¢Êý¾ÝºÍÓ¦ÓóÌÐò·½ÃæµÄÍøÂç»Æ½ð³Ç¹ÙÍøÍþв¡£01¹¹½¨»Æ½ð³Ç¹ÙÍø SaaS ¼Ü¹¹µÄ¹Ø¼ü×é¼þ´òÔì»Æ½ð³Ç¹ÙÍøµÄ SaaS ¼Ü¹¹£¬Òª×ÅÖØ¿¼ÂÇÄÇЩ×îÖØÒªµÄ»Æ½ð³Ç¹ÙÍøÒòËØ£¬ÕâЩÒòËØÄܹ»ÓÐЧµÖÓù¿ÉÄÜΣº¦Ó¦Óûò¿Í»§ÐÅÏ¢µÄ¸÷ÀàÍþв¡£
Éí·ÝÓë·ÃÎʹÜÀí£¨IAM£©
Ò»¸ö¿É¿¿µÄ IAM ½â¾ö·½°¸¿ÉÒÔͨ¹ý¶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©¡¢µ¥µãµÇ¼£¨SSO£©ÒÔ¼°Óû§ÅäÖõÈÊÖ¶ÎÀ´È·±£»Æ½ð³Ç¹ÙÍø·ÃÎÊ£¬´Ó¶ø½µµÍ»ùÓÚÉí·ÝµÄÍþв·çÏÕ¡£½« Azure AD¡¢Okta »ò Google Workspace µÈÉí·ÝÌṩÉÌÕûºÏ½øÀ´£¬¾ÍÄÜʵÏÖ¶ÔÓû§Éí·ÝÑéÖ¤ºÍÊÚȨµÄ¼¯Öйܿء£
Êý¾Ý±£»¤
Òª¶ÔÃô¸ÐÊý¾Ý½øÐмÓÃÜ£¬Öƶ¨Êý¾Ý·Àй©£¨DLP£©²ßÂÔ£¬²¢ÇÒ¿ØÖÆÊý¾Ý¹²Ïí£¬ÒÔ´Ë·ÀÖ¹Êý¾Ýй¶»òÎ¥¹æ¡£Í¬Ê±£¬ÊµÊ©¾²Ì¬Êý¾ÝºÍ´«ÊäÖÐÊý¾ÝµÄ¼ÓÃÜ´ëÊ©£¬È«·½Î»±£»¤Êý¾Ý»Æ½ð³Ç¹ÙÍø¡£
»Æ½ð³Ç¹ÙÍø¿ª·¢Êµ¼ù
×ñѻƽð³Ç¹ÙÍø±àÂëÔÔò£¬¿ªÕ¹´úÂëÉó²é£¬²¢ÔËÓÃ×Ô¶¯»¯»Æ½ð³Ç¹ÙÍøÉ¨Ã蹤¾ß£¬ÔÚ¿ª·¢ÖÜÆÚµÄÔçÆÚ½×¶Î¾Íʶ±ð³ö©¶´¡£½èÖú SonarQube¡¢Snyk »ò Checkmarx µÈ¹¤¾ßɨÃè´úÂ룬¼°Ê±·¢ÏÖDZÔÚ©¶´¡£
ÍøÂç»Æ½ð³Ç¹ÙÍø
±ØÐ벿Êð·À»ðǽ¡¢ÐéÄâ˽ÓÐÔÆ£¨VPC£©ÒÔ¼°ÍøÂç·Ö¶Î¼¼Êõ£¬½«Ãô¸Ð¹¤×÷¸ºÔØÖÃÓڻƽð³Ç¹ÙÍøµÄ±ß½çÄÚ£¬´Ó¶øËõС¹¥»÷Ãæ¡£´ËÍ⣬ͨ¹ýʵʩ IP °×Ãûµ¥¡¢VPN ·ÃÎÊÒÔ¼°ÍøÂç¼¶¼à¿Ø£¬±£ÕÏÊý¾Ý´«ÊäµÄ»Æ½ð³Ç¹ÙÍø¡£
ʼþÏìÓ¦¼Æ»®
ÖÆ¶¨Ò»Ì×ÍêÉÆµÄʼþÏìÓ¦¼Æ»®£¬Ã÷È·ÔÚ·¢Éú»Æ½ð³Ç¹ÙÍøÊ¼þʱµÄ¼ì²â¡¢¶ôÖÆºÍ»Ö¸´Á÷³Ì¡£¶¨ÆÚ¿ªÕ¹ÑÝÁ·£¬ÈÃÔ±¹¤ÊìϤӦ¶ÔÁ÷³Ì£¬ÌáÉýÓ¦¶Ô»Æ½ð³Ç¹ÙÍøÊ¼þµÄÄÜÁ¦¡£
½«ÕâÐ©ÒªËØÕûºÏÆðÀ´£¬¾ÍÄÜΪ SaaS ¼Ü¹¹ÖþÀθù»ù¡£
ҪʵÏÖÓÐЧµÄ SaaS »Æ½ð³Ç¹ÙÍø£¬ÐèÒª²ÉÓ÷ֲã·À»¤²ßÂÔ¡£ÒÔÏÂÕâЩ¹Ø¼ü²ßÂÔÄܹ»°ïÖú SaaS Ó¦ÓõÖÓùδ¾ÊÚȨµÄ·ÃÎÊ¡¢ÅäÖôíÎóÒÔ¼°µÚÈý·½Â©¶´µÄÍþв£º
1¡¢Êý¾Ý¼ÓÃÜ£º±ØÐë¶Ô¾²Ì¬Êý¾ÝºÍ´«ÊäÖеÄÊý¾Ý½øÐмÓÃÜ£¬·Àֹδ¾ÊÚȨµÄ·ÃÎÊ¡£Í¬Ê±£¬ÒªÈ·±£¼ÓÃÜÃÜÔ¿µÄ»Æ½ð³Ç¹ÙÍø¹ÜÀí£¬±ÜÃâÃÜÔ¿±»Ð¹Â¶¡£
2¡¢·ÃÎÊ¿ØÖÆ£º²ÉÓûùÓÚ½ÇÉ«µÄ·ÃÎÊ¿ØÖÆ£¨RBAC£©£¬×ñÑ×îСȨÏÞÔÔò¡£¶¨ÆÚÉó²éºÍÉó¼ÆÈ¨ÏÞÉèÖ㬷ÀÖ¹³öÏÖ¹ý¶ÈÊÚȨµÄÕË»§¡£
3¡¢»Æ½ð³Ç¹ÙÍøÅäÖ㺶¨ÆÚÉó²é²¢¼Ó¹ÌÔÆ·þÎñµÄÅäÖ㬼õÉÙDZÔڵĻƽð³Ç¹ÙÍøÂ©¶´¡£AWS Config¡¢Azure »Æ½ð³Ç¹ÙÍøÖÐÐÄºÍ GCP »Æ½ð³Ç¹ÙÍøÖ¸»ÓÖÐÐĵȹ¤¾ß¿ÉÒÔ°ïÖú±£³ÖÒ»ÖµĻƽð³Ç¹ÙÍøÅäÖá£
4¡¢¼à¿ØºÍÈÕÖ¾¼Ç¼£ºÆôÓÃÏêϸµÄÈÕÖ¾¼Ç¼¹¦ÄÜ£¬²¢ÀûÓÃÏà¹Ø¹¤¾ß¼ì²â¿ÉÒÉÐÐΪ¡£AWS CloudTrail¡¢Azure Monitor ºÍ Google Cloud Operations µÈ½â¾ö·½°¸Äܹ»ÎªÊ¼þÏìÓ¦ÌṩÓÐÁ¦Ö§³Ö¡£
5¡¢µÚÈý·½·çÏÕ¹ÜÀí£ºÆÀ¹ÀµÚÈý·½¼¯³ÉµÄ»Æ½ð³Ç¹ÙÍøÐÔ¡£¶¨ÆÚ¶Ô¹©Ó¦É̽øÐлƽð³Ç¹ÙÍøÆÀ¹À£¬Á˽âÍⲿ·þÎñ¿ÉÄÜ´øÀ´µÄ·çÏÕ¡£
½«ÕâЩ²ßÂÔ½áºÏÆðÀ´£¬¿ÉÒÔÏÔÖøÌáÉý SaaS Ó¦ÓõĻƽð³Ç¹ÙÍøÐÔ¡£
03ʵʩÉí·ÝÓÅÏȻƽð³Ç¹ÙÍø£¬¼ÓÇ¿·ÃÎÊ¿ØÖÆ
ÒÔÉí·ÝΪºËÐĵÄÍøÂç»Æ½ð³Ç¹ÙÍø²ßÂÔ½«·À»¤Öصã´ÓÍøÂç±ß½ç×ªÒÆµ½¸öÈËÓû§Éí·ÝÉÏ£¬Í¨¹ý½«Éí·Ý×÷Ϊ±£»¤×ÊÔ´µÄºËÐÄÒªËØ£¬ÓÐЧÔöÇ¿ÁË·ÃÎÊ¿ØÖƵĻƽð³Ç¹ÙÍøÐÔ¡£
1¡¢¼¯ÖÐʽÉí·Ý¹ÜÀíʹÓà Azure AD¡¢Okta »ò Google Workspace µÈ¼¯ÖÐʽÉí·ÝÌṩÉÌ£¨IdP£©£¬¼ò»¯Óû§¹ÜÀíÁ÷³Ì£¬È·±£»Æ½ð³Ç¹ÙÍø²ßÂÔµÄÒ»ÖÂÐÔ¡£¼¯ÖÐʽÉí·Ý¹ÜÀí¿ÉÒÔ¼õÉÙÉí·Ý¹ÜÀíµÄ¸´ÔÓÐÔ£¬·½±ãʵʩ¶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©¡¢ÃÜÂë²ßÂԺͻỰ¿ØÖƵȻƽð³Ç¹ÙÍø´ëÊ©¡£
2¡¢¶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©ÔڹؼüÓ¦ÓÃÖÐÆôÓà MFA£¬¼´Ê¹Óû§Æ¾Ö¤±»Ð¹Â¶£¬Ò²ÄÜÓÐЧ·Àֹδ¾ÊÚȨµÄ·ÃÎÊ¡£ÆôÓÃ×ÔÊÊÓ¦ MFA£¬¸ù¾ÝÓû§ÐÐΪ»òÉ豸λÖõȷçÏÕÐźţ¬Áé»î¾ö¶¨ÊÇ·ñÐèÒª¶îÍâÑéÖ¤¡£
3¡¢»ùÓÚ½ÇÉ«µÄ·ÃÎÊ¿ØÖÆ£¨RBAC£©Í¨¹ý RBAC È·±£Óû§Ö»ÄÜ·ÃÎÊÓëÆä½ÇÉ«Ïà¹ØµÄ×ÊÔ´£¬±ÜÃâ¹ý¶ÈÊÚȨ¡£¶¨ÆÚÉó²éºÍÉ󼯽ÇɫȨÏÞ£¬·ÀֹȨÏÞ¹ý¶È»ýÀÛ¡£
4¡¢°´Ðè·ÃÎÊ£¨JIT£©½öÔÚ±ØÒªÊ±ÊÚÓèÁÙʱµÄ¸ß¼¶±ð·ÃÎÊȨÏÞ£¬¼õÉÙ³¤ÆÚÌØÈ¨ÕË»§´øÀ´µÄ·çÏÕ£¬½µµÍ¹¥»÷ÕßÀûÓùý¶È»òÐÝÃßȨÏ޵ĿÉÄÜÐÔ¡£
ÒÔÉí·ÝΪºËÐĹ¹½¨»Æ½ð³Ç¹ÙÍøÌåϵ£¬ÓÐÖúÓÚÆóÒµ¸üºÃµØ¿ØÖÆ·ÃÎÊȨÏÞ£¬½µµÍÊý¾Ýй¶µÄ·çÏÕ¡£
04¹¹½¨»Æ½ð³Ç¹ÙÍøµÄSaaS¹¤×÷Á÷
ʵʩ»Æ½ð³Ç¹ÙÍøµÄ¹¤×÷Á÷¿ÉÒÔ¼õÉÙÈËΪ´íÎóºÍDZÔڵĻƽð³Ç¹ÙÍøÂ©¶´£¬È·±£Êý¾Ý¡¢Éí·ÝºÍÓ¦ÓÃÐÐΪµÄÒ»ÖÂÐÔ´¦Àí¡£
-
»Æ½ð³Ç¹ÙÍøµÄÈëÖ°ºÍÀëÖ°Á÷³Ì£ºÖƶ¨ÇåÎúµÄÈëÖ°ºÍÀëÖ°Á÷³Ì£¬¸ßЧ¹ÜÀíÓû§·ÃÎÊȨÏÞ¡£ÀûÓÃ×Ô¶¯»¯¹¤¾ß½øÐÐÓû§È¨ÏÞµÄÅäÖúͳ·Ïú£¬·ÀÖ¹³öÏÖ¹ÂÁ¢ÕË»§¡£½«ÕâЩÁ÷³ÌÓë IAM ÌṩÉ̼¯³É£¬¼ò»¯·ÃÎʹÜÀí¡£
-
»Æ½ð³Ç¹ÙÍøµÄ API ¹ÜÀí£ºÈ·±£ËùÓÐ SaaS API ¶¼¾¹ýÉí·ÝÑéÖ¤¡¢¼ÓÃÜ£¬²¢ÓÐÏêϸµÄÎĵµ¼Ç¼¡£Í¨¹ý API Íø¹ØÏÞÖÆ±©Â¶µÄ¶Ëµã£¬Ê¹Óà OAuth 2.0¡¢OpenID Connect ºÍ API ËÙÂÊÏÞÖÆµÈ¼¼ÊõÔöÇ¿ API »Æ½ð³Ç¹ÙÍøÐÔ¡£
-
Êý¾Ý±¸·ÝºÍ»Ö¸´£º½¨Á¢ÑϸñµÄ±¸·ÝºÍ»Ö¸´Á÷³Ì£¬¶¨ÆÚ²âÊÔ»Ö¸´¹ý³Ì£¬È·±£ÔÚ·¢Éú»Æ½ð³Ç¹ÙÍøÊ¼þʱÄܹ»¿ìËÙ»Ö¸´Êý¾Ý£¬¼õÉÙÍ£»úʱ¼ä¡£ÀûÓà AWS Backup¡¢Azure Backup »ò Google Cloud Backup µÈ·þÎñʵÏÖ×Ô¶¯»¯µÄ±¸·Ý¹ÜÀí¡£
×ñÑÕâЩʵ¼ù£¬ÆóÒµ¿ÉÒÔʵÏֻƽð³Ç¹ÙÍø¡¢¸ßЧµÄ¹¤×÷Á÷¹ÜÀí¡£
05Éí·Ý»Æ½ð³Ç¹ÙÍø£ºÏÖ´úÍøÂç»Æ½ð³Ç¹ÙÍøµÄ»ùʯ
Éí·Ý»Æ½ð³Ç¹ÙÍø¶ÔÓÚ±£»¤ÔÆÓ¦ÓᢷþÎñºÍÊý¾ÝÖÁ¹ØÖØÒª¡£ÓÉÓÚÍøÂç¹¥»÷ÍùÍù´ÓµÁÓÃÉí·Ý¿ªÊ¼£¬Òò´Ë¼ÓÇ¿Éí·Ý»Æ½ð³Ç¹ÙÍøÊÇÔ¤·ÀÖØ´ó»Æ½ð³Ç¹ÙÍøÊ¼þµÄ¹Ø¼ü¡£
·ÀÖ¹»ùÓÚÆ¾Ö¤µÄ¹¥»÷£º¹¥»÷Õß³£³£ÀûÓÃÈõÃÜÂë»ò±»µÁµÄÓû§Æ¾Ö¤½øÐй¥»÷¡£Í¨¹ýʵʩ¶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©¡¢ÃÜÂë²ßÂԺͻùÓÚÐÐΪµÄ¼à¿ØµÈ´ëÊ©£¬¿ÉÒÔÓÐЧ½µµÍÕâÖÖ·çÏÕ¡£Microsoft Defender for Identity¡¢Google Cloud Identity Protection ºÍ Okta ThreatInsight µÈ¹¤¾ßÄܹ»¼ì²â¿ÉÒɵÄÉí·ÝÏà¹ØÐÐΪ¡£
ʵÏÖÁãÐÅÈμܹ¹£ºÉí·Ý»Æ½ð³Ç¹ÙÍøÓëÁãÐÅÈÎÔÔòÏàÆõºÏ£¬È·±£Ä¬ÈÏÇé¿öϲ»ÐÅÈÎÈκÎÓû§»òÉ豸¡£Ã¿´Î·ÃÎÊÇëÇó¶¼»á¸ù¾ÝÉí·Ý¡¢É豸½¡¿µ×´¿öºÍλÖõÈÐÅÏ¢½øÐÐÑéÖ¤£¬È»ºó²ÅÊÚÓè·ÃÎÊȨÏÞ¡£
ÔöÇ¿Óû§ÎÊÔðÖÆ£ºÍ¨¹ýÉí·Ý¸ú×ÙºÍÉ󼯹¦ÄÜ£¬ÆóÒµ¿ÉÒÔ¼à¿ØÓû§ÐÐΪ£¬¼°Ê±·¢ÏÖ¿ÉÒɻ¡£AWS CloudTrail¡¢Azure AD ÈÕÖ¾ºÍ Google Cloud Éó¼ÆÈÕÖ¾µÈ¹¤¾ßÌṩÁËÉí·ÝÏà¹ØÊ¼þµÄÏêϸ¼Ç¼¡£
Ìá¸ßºÏ¹æÐÔ£ºÉí·Ý»Æ½ð³Ç¹ÙÍøÓÐÖúÓÚÂú×ã¸÷ÖֺϹæÒªÇó£¬Í¨¹ýʵʩ·ÃÎÊ¿ØÖÆ¡¢Î¬»¤É󼯼ǼºÍ±£»¤Êý¾Ý»Æ½ð³Ç¹ÙÍø£¬Âú×ã ISO 27001¡¢SOC 2 ºÍ HIPAA µÈ±ê×¼µÄÒªÇó¡£
½«Éí·Ý»Æ½ð³Ç¹ÙÍø×÷ΪÓÅÏÈÊÂÏÆóÒµ¿ÉÒÔ¹¹½¨ÆðµÖÓùÍøÂçÍþвµÄ¼á¹Ì·ÀÏß¡£
SaaS »Æ½ð³Ç¹ÙÍø²¢·ÇÒ»´ÎÐÔŬÁ¦£¬¶øÊÇÒ»ÖÖ½áºÏÖ÷¶¯Íþв·ÀÓù¡¢ÒÔÉí·ÝΪÖÐÐĵķÃÎÊ¿ØÖƺͿÉÀ©Õ¹×Ô¶¯»¯µÄ³ÖÐø²ßÂÔ¡£Í¨¹ýʵʩǿ´óµÄÊý¾Ý¼ÓÃÜ¡¢Ç¿ÖÆÖ´ÐÐ×îСȨÏÞ·ÃÎʺ;«È·¹ÜÀíÉí·Ý£¬ÆóÒµ¿ÉÒÔÏÔÖø¼õÉÙÆäÊܵ½ÍþвµÄ±©Â¶·çÏÕ¡£
ÓÅÏÈ¿¼ÂÇÉí·Ý»Æ½ð³Ç¹ÙÍø£¬ÎªÁãÐÅÈε춨ÁË»ù´¡£¬²¢ÓÐÖúÓÚÂú×ãÈÕÒæÔö³¤µÄºÏ¹æÐèÇó¡£Í¶×ÊÕâЩ»Æ½ð³Ç¹ÙÍø´ëÊ©²»½ö±£»¤ÁËÄãµÄ SaaS ¶ÑÕ»£¬¶øÇÒËæ×ÅÒµÎñ¹æÄ£µÄÀ©´ó£¬Ò²½¨Á¢Á˳¤ÆÚµÄ¿Í»§ÐÅÈκÍÔËÓªÈÍÐÔ¡£