arXiv ScienceSearch

arXiv subjects

Rithika Dulam

Publications and source records attributed to Rithika Dulam.

1 recordsLinked to original sources

A Control-Driven Framework for Secure SaaS Onboarding in Regulated Enterprises

As enterprises increasingly adopt Software-as-a-Service (SaaS) platforms for mission-critical functions, onboarding these services has emerged as a complex governance challenge. In regulated environments, SaaS onboarding must address multiple interdependent control domains, including Third-Party Risk Management (TPRM), cybersecurity assessment, Identity and Access Management (IAM), and disaster recovery (DR). These domains are often executed in isolation, resulting in delayed go-lives, duplicated assessments, unclear ownership, and residual operational risk. This paper proposes a control-driven, end-to-end SaaS onboarding framework that integrates TPRM, cybersecurity, IAM, and DR into a unified lifecycle model spanning intake and risk scoping, architecture validation, identity design, resilience assessment, and post-production governance. Key contributions include: (1) a structured onboarding lifecycle emphasizing sequencing and dependency management across control domains; (2) a cross-domain control mapping that highlights failure modes caused by siloed reviews; and (3) practical design patterns for secure connectivity, federated identity, least-privilege access, and shared-responsibility disaster recovery. Unlike prior frameworks that treat these domains independently, this work introduces a formally gate-sequenced, cross-domain lifecycle, the first integrated model that encodes mandatory dependency ordering across all four control domains with traceable evidence artifacts at each stage, directly addressing structural gap responsible for enterprise-owned SaaS failures such as the 2024 Ticketmaster-Snowflake breach.

cs.CR