Academy Central
----
Weather

CrowdStrike Falcon Shield — SaaS Security Module Guide

CrowdStrike Falcon Shield — SaaS 安全模組指南

Overview | 概述

This repository contains documentation for CrowdStrike Falcon Shield's SaaS security capabilities. Each module covers a specific domain of SaaS security, from application discovery to identity threat detection.

本儲存庫包含 CrowdStrike Falcon Shield SaaS 安全能力的文件。每個模組涵蓋 SaaS 安全的特定領域,從應用程式發現到身分威脅偵測。


Module Architecture | 模組架構


Module Cross-References | 模組交叉參考


Module Index | 模組索引

#ModuleFocus AreaFile#模組重點領域檔案
1DCU MatrixRisk prioritization scoringthe "DCU" matrix.md1DCU 矩陣風險優先排序評分the "DCU" matrix.md
2Applications InventoryOAuth, AI Agents, API Tokens, Extensionsmanaging-saas-inventories.md2應用程式清單OAuth、AI 代理、API 令牌、擴充功能managing-saas-inventories.md
3Devices InventoryDevice hygiene & complianceMonitoring SaaS-Connected Devices.md3裝置清單裝置健全度與合規Monitoring SaaS-Connected Devices.md
4Data InventoryPublic/external data exposureManaging Sensitive Data in SaaS Environments.md4資料清單公開/外部資料暴露Managing Sensitive Data in SaaS Environments.md
5Permissions InventoryLeast privilege enforcementSaaS Permissions Governance.md5權限清單最小權限實施SaaS Permissions Governance.md
6User InventoryIdentity risk assessmentIdentity Visibility and Risk Assessment with Falcon Shield.md6使用者清單身分風險評估Identity Visibility and Risk Assessment with Falcon Shield.md
7Identity GovernancePAG & compliance frameworksIdentity governance and compliance.md7身分治理特權存取治理與法規框架Identity governance and compliance.md
8ITDRThreat detection & responseITD - Identity Threat Detection and Response.md8ITDR威脅偵測與回應ITD - Identity Threat Detection and Response.md

Reading Order | 閱讀順序

For new users, we recommend the following learning path:

對於新使用者,建議以下學習路徑:


Key Concepts Glossary | 關鍵概念詞彙

TermDefinition術語定義
PoLPPrinciple of Least Privilege — users get only the minimum access neededPoLP最小權限原則 — 使用者僅獲得所需的最低存取權
PAGPrivileged Access Governance — managing high-risk privileged accountsPAG特權存取治理 — 管理高風險特權帳戶
ITDRIdentity Threat Detection and Response — detecting identity-based attacksITDR身分威脅偵測與回應 — 偵測身分型攻擊
SODSegregation of Duties — dividing critical functions among usersSOD職責分離 — 將關鍵功能分配給不同使用者
SaaS Security Posture ManagementMonitoring and enforcing security configurations across SaaS appsSaaS 安全態勢管理監控和執行跨 SaaS 應用程式的安全設定
DCUData Sensitivity + Configuration Complexity + Number of UsersDCU資料敏感度 + 設定複雜度 + 使用者數量
IOCIndicator of Compromise — forensic signs of a breachIOC入侵指標 — 違規的法證跡象
MITRE ATT&CKFramework mapping attacker tactics and techniquesMITRE ATT&CK映射攻擊者策略和技術的框架
RBACRole-Based Access ControlRBAC角色型存取控制
MFAMulti-Factor AuthenticationMFA多因素驗證

Quick Reference: Risk Priorities | 快速參考:風險優先級

PriorityFocusFrequency優先級重點頻率
CriticalEnterprise-wide apps with regulated dataWeekly極高全企業應用程式含受管制資料每週
HighDepartment-wide apps with sensitive dataMonthly部門級應用程式含敏感資料每月
MediumMulti-team apps with basic permissionsQuarterly多團隊應用程式含基本權限每季
LowLimited-use apps with public dataAnnually有限使用應用程式含公開資料每年

Getting Started | 開始使用

  1. Start with the DCU Matrix — Score your top 10 SaaS apps

  2. Connect your SaaS integrations — Falcon Shield supports 180+ apps

  3. Review the Applications Inventory — Identify all third-party access

  4. Work through each module — Follow the reading order above

  5. 從 DCU 矩陣開始 — 為您前 10 個 SaaS 應用程式評分

  6. 連接您的 SaaS 整合 — Falcon Shield 支援 180+ 應用程式

  7. 審查應用程式清單 — 識別所有第三方存取

  8. 逐一學習每個模組 — 遵循上述閱讀順序

More in this folder