CCAK · Question #120
Which of the following is MOST important to consider when developing an effective threat model during the introduction of a new SaaS service into a customer organization's architecture? The threat…
The correct answer is A. recognizes the shared responsibility for risk management between the customer and the CSP. When introducing a new SaaS service, the most critical threat modeling consideration is explicitly mapping the shared responsibility for risk between the customer and the CSP, because unaddressed boundary gaps are the most common source of SaaS security failures.
Question
Which of the following is MOST important to consider when developing an effective threat model during the introduction of a new SaaS service into a customer organization's architecture? The threat model:
Options
- Arecognizes the shared responsibility for risk management between the customer and the CSP.
- Bleverages SaaS threat models developed by peer organizations.
- Cis developed by an independent third-party with expertise in the organization's industry sector.
- Dconsiders the loss of visibility and control from transitioning to the cloud.
How the community answered
(25 responses)- A84% (21)
- B4% (1)
- C4% (1)
- D8% (2)
Why each option
When introducing a new SaaS service, the most critical threat modeling consideration is explicitly mapping the shared responsibility for risk between the customer and the CSP, because unaddressed boundary gaps are the most common source of SaaS security failures.
In a SaaS model, the CSP controls infrastructure, platform, and application layers while the customer retains responsibility for identity management, data governance, and access controls. A threat model that does not explicitly reflect this shared responsibility will produce an incomplete risk register, leaving threats in the CSP's domain untracked and threats in the customer's domain unmitigated. Mapping these boundaries is the foundational step that makes all other threat modeling activities meaningful.
Peer organizations' threat models reflect different data classifications, regulatory contexts, and architectures, making them unreliable substitutes for an organization-specific model tailored to the actual SaaS service being adopted.
Third-party expertise supplements but does not replace shared responsibility mapping; an independent party lacks knowledge of the organization's internal data flows and existing controls needed to produce an accurate, organization-specific model.
Loss of visibility and control is a real SaaS risk but is a subset of the shared responsibility analysis; answer A encompasses this concern while also requiring explicit risk assignment between the customer and CSP across all threat categories.
Concept tested: SaaS shared responsibility model in cloud threat modeling
Source: https://cloudsecurityalliance.org/research/guidance/
Topics
Community Discussion
No community discussion yet for this question.