Overview
SaaS Posture integrations provide visibility into the configuration and security posture of your connected SaaS applications. Cato continuously reviews the application settings and compares them to the recommended posture defined by Cato’s research team. This helps identify misconfigurations that can increase risk, such as authentication settings, third-party integrations, and data-sharing controls.
Posture data appears in the Applications dashboard, where you can view posture scores and the highest-severity findings across connected applications. You can review each posture check from the Posture page, including the issue details, status, and remediation action required to pass the check.
For more information, see Reviewing the Security Posture of Your SaaS Applications.
To configure the SaaS Posture integration, you need to:
Configure the required settings in the SaaS application
Create the API connector in the CMA
A CASB license is required for SaaS Posture integrations.
GitHub統合の設定
GitHub統合を設定するには、新しい個人アクセストークンを作成してください。
必要条件
GitHub Enterprise Cloud または GitHub Enterprise Server のライセンスを購入済みである必要があります。
接続する組織はGitHub Enterpriseアカウントに紐付けられている必要があります。
ステップ1:GitHubデベロッパーセンターで統合を設定
GitHubデベロッパーセンターで、CMAに入力するアクセス トークンを特定します。
GitHub統合を設定するには:
指定されたユーザーで GitHubアカウント にサインインします。
個人アクセス トークン > トークン(クラシック) に移動し、新しいトークンを生成 → 新しいトークン(クラシック)をクリックします。
次の詳細を設定します:
注: 認識しやすいラベル
有効期限: 有効期限を設定しないでください
スコープ: 以下を選択します:
admin:orgread:orgread:audit_logread:enterpriseリポジトリユーザ
トークンを生成をクリックします。
トークンをコピーして保存し、それをCMAに入力できるようにします。
SAML SSOを強制する組織の場合のみ:
個人アクセス トークン > トークン(クラシック) に移動します。
新しいトークン行を探して SSO を設定をクリックします。
SAML SSOを強制する各組織に対して、承認をクリックし、その組織のIDプロバイダを介してサインインします。
ステップ 2: CMAにAPIコネクタを作成する
必要なアプリケーションとの統合設定後、その詳細を CMA に追加します。
CMA に API コネクタを作成するには:
ナビゲーションメニューから リソース > 統合 をクリックします。
設定済みの統合タブをクリックします。
「新規」をクリックします。新規統合 パネルが開きます。
追加したいSaaS アプリケーション を選択します。
機能ドロップダウンでSaaS構成を選択します。
手順一で作成した詳細を追加します
エンタープライズ名: エンタープライズスラッグ
管理者ベアラトークン: ステップ1で作成したトークン
保存 をクリックします。
アプリが 統合されたアプリ テーブルに 接続済み ステータスで表示されます。