Academy Central
----
Weather

DCU Matrix — SaaS App Risk Prioritization

DCU 矩陣 — SaaS 應用程式風險優先排序

Overview | 概述

The DCU Matrix helps security teams prioritize which SaaS applications need the most attention. Score each app on three dimensions — Data Sensitivity, Configuration Complexity, and Number of Users — then combine the scores to decide your governance focus.

DCU 矩陣 協助安全團隊決定哪些 SaaS 應用程式需要最優先關注。針對每個應用程式,從三個維度評分 — D(資料敏感度)、C(設定複雜度)、U(使用者數量)— 再將分數加總以決定治理重點。


Scoring Scale | 評分標準

Each dimension is rated 1 (lowest) to 5 (highest).

每個維度的評分為 1(最低)5(最高)

D — Data Sensitivity | 資料敏感度

ScoreLevelDescription分數等級說明
1MinimalPublic information only, no sensitive data1最低僅公開資訊,無敏感資料
2LowGeneral business info, marketing materials2一般業務資訊、行銷素材
3ModerateOperational data, internal comms, non-sensitive customer data3中等運營資料、內部溝通、非敏感客戶資料
4HighBusiness-critical data, financial info, strategic docs4業務關鍵資料、財務資訊、策略文件
5CriticalRegulated data (PII, PHI, PCI), IP/trade secrets, legal/HR records5極高受法規管制的資料(PII、PHI、PCI)、智慧財產、法務/人資紀錄

C — Configuration Complexity | 設定複雜度

ScoreLevelDescription分數等級說明
1MinimalFewer than 5 security settings, no complex permissions1最低少於 5 個安全設定,無複雜權限
2Simple5–15 settings, basic permissions and sharing2簡單5–15 個設定,基本權限與分享
3Moderate15–30 settings, standard RBAC, limited integrations3中等15–30 個設定,標準角色型存取控制,有限整合
4Complex30–50 settings, multiple sharing options, API integrations4複雜30–50 個設定,多種分享選項,API 整合
5Very Complex50+ settings, complex permission models, multiple auth methods5極複雜50+ 個設定,複雜權限模型,多種驗證方式

U — Number of Users | 使用者數量

ScoreLevelDescription分數等級說明
1LimitedLess than 10% of org, individual use1極少低於 10% 組織使用,個人使用
2Single Team10–24% of org, one department2單一團隊10–24% 組織使用,單一部門
3Multi-Team25–49% of org, several departments3多團隊25–49% 組織使用,跨多部門
4Department-Wide50–79% of org, critical for multiple depts4部門級50–79% 組織使用,多部門關鍵應用
5Enterprise-Wide80–100% of org, mission-critical5全企業80–100% 組織使用,營運核心

How to Use | 使用方式

Steps | 步驟:

  1. List your SaaS apps — Start with the Applications Inventory in Falcon Shield.

  2. Score each dimension — Use the tables above to rate D, C, and U.

  3. Calculate total — Add D + C + U (range: 3–15).

  4. Assign priority — Use the flowchart to determine review frequency and governance actions.

  5. Document and review — Re-score apps periodically as usage and data change.

  6. 列出你的 SaaS 應用程式 — 從 Falcon Shield 的應用程式清單開始。

  7. 為每個維度評分 — 使用上方表格為 D、C、U 打分。

  8. 計算總分 — 將 D + C + U 相加(範圍:3–15)。

  9. 決定優先級 — 使用流程圖決定審查頻率和治理行動。

  10. 記錄並定期審查 — 隨著使用和資料變化,定期重新評分。


Priority Actions by Score | 依分數採取的行動

Total ScorePriorityRecommended Actions總分優先級建議行動
3–5LowAnnual review, basic monitoring3–5年度審查,基本監控
6–9MediumQuarterly review, enable MFA, review permissions6–9季度審查,啟用 MFA,審查權限
10–12HighMonthly review, enforce least privilege, audit sharing10–12每月審查,實施最小權限,稽核分享設定
13–15CriticalWeekly review, encrypt data, restrict access, full compliance audit13–15極高每週審查,資料加密,限制存取,完整法規稽核

Related Modules | 相關模組

ModuleDescription關聯模組說明
Applications InventoryDiscover and inventory all third-party apps應用程式清單發現並盤點所有第三方應用程式
User InventoryIdentity visibility and risk assessment使用者清單身分可見性與風險評估
Permissions GovernanceEnforce least privilege across SaaS權限治理跨 SaaS 實施最小權限