I spent a few years building a SaaS governance program inside the federal government. We found hundreds of SaaS apps across the org, sprawl that nobody had a full picture of and that had quietly become one of our biggest risks. Identifying them was step one. From there we built a report to assess each one against more than 60 controls, along with a handful of other supporting artifacts, and only after that did we bring in a tool, AppOmni, to actually secure them. That loop, discover, manage, secure, is what convinced me cybersecurity needs a structured framework instead of ad hoc effort.
The pillars here, Assess, Manage, and Validate, aren’t identical to what we used, but the same idea drives them: cybersecurity has to be handled as a whole, not as a pile of disconnected checklists. This post is meant to be a practical starting point for building a program that protects critical assets and meets compliance requirements.
Below is each pillar, broken into the elements that make it up.
Assess
The “Assess” pillar is about identifying critical assets, understanding the risks and vulnerabilities tied to them, and prioritizing action based on actual impact.
The main elements within this pillar include:
- Identify the critical assets and data within the systems.
- Understand and evaluate the risks and vulnerabilities associated with the assets.
- Understand the regulatory and compliance requirements relevant to the system(s).
- Prioritize the security and compliance actions based on potential impact.
In practice, this is where we built out a report to evaluate each discovered SaaS app against more than 60 controls, plus a handful of supporting artifacts, so we weren’t just finding shadow SaaS but actually scoring how risky each one was.
Manage
The “Manage” pillar involves developing and implementing policies, configuring security technologies, conducting employee training, and working with engineering teams on recovery processes.
The main elements within this pillar include:
- Develop, implement, and oversee policies and procedures to protect assets and ensure compliance.
- Configure and maintain security technologies to defend against threats.
- Conduct training and awareness programs for employees.
- Review and work with engineering teams on recovery processes to mitigate the impact of security breaches.
This was also the point where we brought in AppOmni, a SaaS security posture management tool, to actually enforce controls on the apps we’d flagged instead of just tracking them in a spreadsheet.
Validate
The “Validate” pillar covers continuous monitoring of security controls, regular auditing and testing of security practices, and confirming that the organization’s security and compliance efforts are actually working.
The main elements within this pillar include:
- Continuously monitor security controls and compliance measures to detect and respond to threats in real time.
- Regularly audit and test security practices and compliance status to identify gaps or weaknesses.
- Review and adjust security measures based on the findings from continuous monitoring and audits.
- Ensure that the organization’s security and compliance efforts are effective and meet industry standards and regulations.
What About Governance?
Governance runs through each pillar:
Within Assess
Governance keeps assessments aligned with business objectives, risk tolerance, and regulatory requirements, and it’s what decides which risks get prioritized and where resources go.
Within Manage
Governance sets the policies and standards for managing security and compliance, so practices stay consistent with organizational goals and get implemented the same way across every department.
Within Validate
Governance mandates the validation mechanisms, audits and monitoring, and makes sure they’re run with integrity and produce something actionable. It also drives the response: corrective actions have to actually happen, and improvements have to actually get made.
Conclusion
This framework won’t fit every organization exactly as-is, but Assess, Manage, and Validate give you three concrete places to start instead of trying to solve everything at once.