NIST SP 800-146
SaaS Operational Posture

NIST SP 800-146 NISTSP146-2: SaaS Operational Recommendations and Provider Assurance

Apply NIST SP 800-146 Chapter 5 SaaS operational recommendations to every SaaS service consumed. Coverage must include (a) data ownership and exit clauses in the SaaS subscription contract, (b) provider security and privacy assurance package (SOC 2 Type II / ISO 27001 / FedRAMP equivalent), (c) application configuration baseline aligned to organisational policy (password complexity, session management, MFA, audit logging, retention), (d) integration security (SSO via SAML or OIDC, SCIM provisioning, API access control), (e) data export and portability path (machine-readable export format and frequency), (f) tenant administrator separation of duties. Maintain a SaaS register that records the operational posture for every active SaaS subscription with annual re-assessment.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.