financetom
Technology
financetom
/
Technology
/
GuidePoint Security and Cloud Security Alliance Launch SaaS Security Capability Framework to Standardize Application Security
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
GuidePoint Security and Cloud Security Alliance Launch SaaS Security Capability Framework to Standardize Application Security
Sep 24, 2025 7:32 AM

New industry standard strengthens SaaS security and third-party risk management

RESTON, Va.--(BUSINESS WIRE)--

GuidePoint Security, a cybersecurity solutions leader enabling organizations to make smarter decisions and minimize risk, in collaboration with the Cloud Security Alliance (CSA), today announced the launch of the SaaS Security Capability Framework (SSCF). This groundbreaking framework establishes the first comprehensive, standardized set of Software-as-a-Service (SaaS) security controls—addressing a long-standing gap in third-party risk management.

SaaS has revolutionized the way organizations operate, but this rapid adoption has also ushered in a new era of security challenges. While foundational frameworks such as CSA’s Cloud Controls Matrix (CCM), SOC 2, and ISO certifications assess an organization’s overall security posture, they often overlook the configurable, customer-facing features that directly impact SaaS security. This gap in the Shared Responsibility Model has left many organizations without clear guidance on how to evaluate or enforce critical protections, leaving them vulnerable to overlooked risk.

The SSCF addresses these challenges by defining 41 essential, customer-facing security controls across six key domains, including:

Change Control & Configuration Management

Data Security & Privacy Lifecycle Management

Identity & Access Management

Interoperability & Portability

Logging & Monitoring

Security Incident Management

Meticulously crafted by a global consortium of experts—including leaders from GuidePoint Security, MongoDB, the CSA SaaS Working Group and other domain specialists—the SSCF sets a new common baseline of security capabilities for both SaaS providers and their customers.

“In working with customers, we continually see the need for clearer SaaS security guidance. The SSCF is a pivotal step toward SaaS security standardization,” said Jonathan Villa, Senior Cloud Practice Director at GuidePoint Security and one of the lead authors of the framework. “It bridges the disconnect between high-level organizational assessments and the product-level security features that matter most to customers. With this framework, organizations can easily reduce risk, streamline procurement and strengthen trust in SaaS solutions.”

By providing precise, standardized security capabilities, the SSCF empowers organizations to move beyond ad hoc risk assessments and toward proactive, strategic security management—strengthening overall security posture and fostering a safer cloud ecosystem.

“This framework is the product of true collaboration,” added Lefteris Skoutaris, Associate Vice President of GRC Solutions at CSA. “With input from GuidePoint Security, MongoDB, and experts across the SaaS ecosystem, the SSCF balances rigorous requirements with practical guidance. It will help raise the bar for SaaS security while enabling faster, more confident cloud adoption.”

For more information or to download the full framework, visit cloudsecurityalliance.org/artifacts/saas-security-capability-framework-sscf.

About GuidePoint Security

GuidePoint Security provides trusted cybersecurity expertise, solutions, and services that help organizations make better decisions that minimize risk. Our experts act as your trusted advisor to understand your business and challenges, helping you through an evaluation of your cybersecurity posture and ecosystem to expose risks, optimize resources and implement best-fit solutions. GuidePoint’s unmatched expertise has enabled 40% of Fortune 500 companies and more than half of the U.S. government cabinet-level agencies to improve their security posture and reduce risk. Learn more at www.guidepointsecurity.com.

Source: GuidePoint Security

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
AT&T says issue disrupting some calls between wireless carriers resolved
AT&T says issue disrupting some calls between wireless carriers resolved
Jun 4, 2024
(Reuters) - AT&T said late on Tuesday that an issue that had prevented making some calls to other wireless carriers had been resolved. Earlier, AT&T, Verizon and T-Mobile said they were all experiencing issues with some calls between carriers. The interoperability issue between carriers has been resolved. We collaborated with the other carrier to find a solution and appreciate our...
Three US wireless companies report connection problems between carriers
Three US wireless companies report connection problems between carriers
Jun 4, 2024
(Reuters) -AT&T, Verizon and T-Mobile said on Tuesday that some customers were having problems with calls made to other wireless carriers, prompting the Federal Communications Commission to investigate. The extent of the problem was not immediately clear, though all three carriers said they were not experiencing widespread outages. There is a nationwide issue that is affecting the ability of customers...
Market Whales and Their Recent Bets on AT&T Options
Market Whales and Their Recent Bets on AT&T Options
Jun 4, 2024
Investors with a lot of money to spend have taken a bearish stance on AT&T ( T ) . And retail traders should know. We noticed this today when the trades showed up on publicly available options history that we track here at Benzinga. Whether these are institutions or just wealthy individuals, we don't know. But when something this big...
US investigating reports of inability to make wireless calls in multiple states
US investigating reports of inability to make wireless calls in multiple states
Jun 4, 2024
June 4 (Reuters) - The Federal Communications Commission said on Tuesday it was investigating reports that consumers in multiple states are unable to make wireless calls. ...
Copyright 2023-2026 - www.financetom.com All Rights Reserved