← All 186 courses
SEC-208 Security

SaaS Security Posture Management (SSPM)

Secure the estate that never went through architecture review. Learners discover shadow SaaS, apply tenant configuration baselines across Microsoft 365, Google Workspace and business platforms, control OAuth application and integration risk, and shut down oversharing without breaking the business. Drift detection and SaaS-side logging turn the one-off cleanup into a monitored posture with owners and SLAs.

B4Professional
6modules
42skill atoms
1role journey
Curriculum

What this course covers.

6 modules, 42 named skill atoms. Expand any module to see them.

1SaaS Estate Reality7 skill atoms
shadow SaaS discovery from IdP, expense and proxy databusiness-owned vs IT-owned tenantsdata classification per applicationtenant sprawl and duplicate instancesorphaned tenants and unknown adminslicence tier gating security featuresbuilding an authoritative SaaS register
2Tenant Configuration Baselines7 skill atoms
Microsoft 365 and Entra ID baselinesGoogle Workspace admin controlsSalesforce and ServiceNow hardeningCIS benchmarks for SaaS platformssecure defaults vs inherited tenant historyexception handling per business unitbaseline versioning as vendors ship changes
3OAuth & Integration Risk7 skill atoms
third-party app consent grantsadmin consent vs user consentscope review and over-permissioned appsservice principals and non-human identitiesrefresh token lifetime and revocation realitymarketplace app vetting processapp allowlisting and grant revocation
4Sharing & Collaboration Controls7 skill atoms
external sharing defaultsanyone-with-the-link exposureguest access lifecyclesensitivity labels and DLP policypublic site and portal exposurefile and record level oversharing discoveryremediation sequencing that avoids breaking workflows
5Drift Detection & Remediation7 skill atoms
continuous configuration monitoringalerting on tenant admin actionsSSPM tooling operation and coverage limitsAPI rate limits shaping scan cadenceownership routing and remediation SLAauto-remediation behind guardrailsposture trend per application
6SaaS Logging & Evidence7 skill atoms
audit log availability by licence tierretention defaults and export to the SIEMunified audit log gapsdetections for admin role change and mailbox rule creationpulling auditor evidence from SaaS APIstuning noisy SaaS alert sourcesinvestigating with incomplete telemetry
Where it fits

SEC-208 in a role journey.

This course appears in 1 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

Cloud Security Engineer

Professional stage
SEC-207SEC-208SEC-302

Roles this course serves

The capability ladder

This course is authored to band B4.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-208 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free