Academy Central
----
Weather

Identity Governance and Compliance

身分治理與法規遵循

Overview | 概述

Effective identity governance ensures the right users have the right access to the right resources for the right reasons. Falcon Shield strengthens identity governance by providing visibility across 180+ SaaS applications through consolidated inventories.

有效的身分治理確保適當的使用者出於適當的理由存取適當的資源。Falcon Shield 透過整合清單提供對 180+ SaaS 應用程式的可見性,強化身分治理。


Key Principles | 關鍵原則

PrincipleDescription原則說明
Least PrivilegeUsers have only the minimum access needed最小權限使用者僅拥有所需的最低存取權
Segregation of DutiesCritical functions divided among users職責分離關鍵功能由不同使用者分工
Access CertificationRegular reviews of access rights存取認證定期審查存取權限
Centralized Policy ManagementConsistent policy application across systems集中化策略管理跨系統一致的策略應用
Comprehensive AuditingDetailed records of changes and exceptions全面稽核變更和例外的詳細記錄

Falcon Shield Governance Capabilities | Falcon Shield 治理能力

Users Inventory | 使用者清單

Provides a consolidated view of all identities with risk scoring to identify potential vulnerabilities.

提供所有身分的整合視圖和風險評分,以識別潛在漏洞。

Permissions Inventory | 權限清單

Maps all permissions and roles across applications to prevent unauthorized access.

跨應用程式映射所有權限和角色,以防止未授權存取。

Privileged Access Governance (PAG) | 特權存取治理

Monitors sensitive permissions and enforces separation of duties to reduce misuse risk.

監控敏感權限並強制職責分離,以降低濫用風險。

External Identity Monitoring | 外部身分監控

Tracks third-party access to ensure adherence to security policies.

追蹤第三方存取以確保遵守安全策略。

Device-to-Identity Correlation | 裝置-身分關聯

Ensures users access SaaS only from secure devices.

確保使用者僅從安全裝置存取 SaaS。

Custom Security Checks | 自訂安全檢查

Aligns with your organization's specific identity policies.

與您組織的特定身分政策保持一致。


Managing Access Rights | 管理存取權限

Permissions Inventory Features | 權限清單功能

FeatureDescription功能說明
Unified Permissions ViewConsolidated overview across all apps統一權限視圖跨所有應用程式的整合概覽
Role DetailsInsights into each role and assigned users角色詳情每個角色和已分配使用者的洞察
Permission Usage AnalysisHow often specific permissions are used權限使用分析特定權限的使用頻率
Custom FilteringFocus on specific apps, types, or groups自訂篩選關注特定應用程式、類型或群組
Historical TrackingPermission changes over time歷史追蹤隨時間變化的權限變更

Compliance Monitoring and Reporting | 法規遵循監控與報告

Framework Mapping | 框架映射

Security checks are aligned with major compliance frameworks:

安全檢查與主要法規遵循框架保持一致:

Compliance Features | 法規遵循功能

FeatureDescription功能說明
Compliance DashboardsVisual compliance status across frameworks法規遵循儀表板跨框架的視覺化遵循狀態
Control EvidenceDocumentation of control implementation控制證據控制措施實施的文件記錄
Compliance ReportingAutomated reports for auditors and stakeholders法規遵循報告為稽核者和利害關係人自動化報告

Privileged Access Governance (PAG) | 特權存取治理

PAG focuses on managing and securing privileged access — the highest-risk accounts.

PAG 專注於管理和保護特權存取 — 最高風險的帳戶。

PAG Capabilities | PAG 能力

PAG Implementation Steps | PAG 實施步驟

  1. Identify all privileged roles across applications

  2. Limit privileged access to only those who require it

  3. Implement time-limited privileged access where possible

  4. Review privileged access assignments regularly

  5. Monitor privileged user activities for suspicious behavior

  6. 識別跨應用程式的所有特權角色

  7. 限制特權存取僅限需要的使用者

  8. 盡可能實施限時特權存取

  9. 定期審查特權存取分配

  10. 監控特權使用者活動以偵測可疑行為

PAG Use Cases by Application | 各應用程式的 PAG 使用情境

ApplicationMonitored Permissions應用程式監控的權限
SalesforceView All Data, Modify All Data, admin capabilitiesSalesforce檢視所有資料、修改所有資料、管理功能
NetSuiteFinancial control permissions, administrative accessNetSuite財務控制權限、管理存取
Office 365Exchange, Azure AD, O365 admin rolesOffice 365Exchange、Azure AD、O365 管理角色
Google WorkspaceSuper admin access, sensitive API permissionsGoogle Workspace超級管理員存取、敏感 API 權限
WorkdayHR data, financial info, system configurationsWorkdayHR 資料、財務資訊、系統設定

Custom Security Checks for Identity Governance | 身分治理的自訂安全檢查

CheckDescription檢查說明
External users with privileged rolesExternal collaborators with admin access pose security risks擁有特權角色的外部使用者擁有管理存取權的外部合作者帶來安全風險
Segregation of duties violationsUsers assigned conflicting roles職責分離違規被分配衝突角色的使用者
Dormant privileged accountsInactive accounts with elevated permissions閒置特權帳戶具提升權限的非活動帳戶
Excessive permission accumulationUsers with unusually high number of permissions過度權限累積擁有異常多權限的使用者
Unmanaged accounts with sensitive accessAccounts not managed by IdP with sensitive data access未管理的敏感存取帳戶未由 IdP 管理但有敏感資料存取權的帳戶

Best Practices for Custom Checks | 自訂檢查的最佳實踐

  1. Use clear naming conventions — Ensure clarity and searchability

  2. Organize with tags or groups — Categorize by team or framework

  3. Document custom check logic — Maintain transparency for audits

  4. Review checks periodically — Keep checks relevant as environment evolves

  5. 使用清晰的命名規則 — 確保清晰度和可搜尋性

  6. 使用標籤或群組組織 — 按團隊或框架分類

  7. 記錄自訂檢查邏輯 — 維護稽核的透明度

  8. 定期審查檢查 — 隨環境演進保持檢查的相關性


Extending Governance with APIs | 透過 API 擴展治理

Falcon Shield APIs enable programmatic access to identity data and governance capabilities:

Falcon Shield API 提供對身分資料和治理能力的程式化存取:

API CapabilityDescriptionAPI 能力說明
Monitor Security ChecksManage checks across SaaS apps監控安全檢查跨 SaaS 應用程式管理檢查
Respond to AlertsTrack and respond to security alerts回應警報追蹤並回應安全警報
Monitor InventoriesAccess user and device data監控清單存取使用者和裝置資料
Manage IntegrationsEnsure secure data exchange管理整合確保安全的資料交換
Access Compliance InfoVerify regulatory adherence存取法規資訊驗證法規遵循
Monitor System LogsTrack activity and detect anomalies監控系統日誌追蹤活動並偵測異常

Prerequisites | 前置條件:

  1. Valid API credentials with appropriate scopes

  2. Access to the CrowdStrike Falcon platform

  3. Proper network access to API endpoints

  4. 具有適當範圍的有效 API 憑證

  5. 存取 CrowdStrike Falcon 平台

  6. 對 API 端點的正確網路存取


Related Modules | 相關模組

ModuleDescription關聯模組說明
User InventoryIdentity visibility and risk assessment使用者清單身分可見性與風險評估
Permissions GovernanceEnforce least privilege權限治理實施最小權限
ITDRDetect identity-based threatsITDR偵測身分型威脅
Devices InventoryDevice-identity correlation裝置清單裝置-身分關聯