GitHub: SaaS 보안 상태 통합 구성

Prev Next

Overview

SaaS Posture integrations provide visibility into the configuration and security posture of your connected SaaS applications. Cato continuously reviews the application settings and compares them to the recommended posture defined by Cato’s research team. This helps identify misconfigurations that can increase risk, such as authentication settings, third-party integrations, and data-sharing controls.

Posture data appears in the Applications dashboard, where you can view posture scores and the highest-severity findings across connected applications. You can review each posture check from the Posture page, including the issue details, status, and remediation action required to pass the check.

For more information, see Reviewing the Security Posture of Your SaaS Applications.

To configure the SaaS Posture integration, you need to:

  1. Configure the required settings in the SaaS application

  2. Create the API connector in the CMA

A CASB license is required for SaaS Posture integrations.

GitHub 통합 구성

GitHub 통합을 구성하려면 새로운 개인 액세스 토큰을 생성하세요.

필수 조건

  • GitHub 엔터프라이즈 클라우드 또는 GitHub 엔터프라이즈 서버 라이센스를 구매해야 합니다.

  • 연결하려는 조직은 GitHub 엔터프라이즈 계정에 첨부되어 있어야 합니다.

단계 1: GitHub 개발자 센터에서 통합 구성

GitHub 개발자 센터에서 CMA에 입력할 액세스 토큰을 식별합니다.

GitHub 통합을 구성하려면:

  1. GitHub 계정에 토큰 소유자로 지정된 사용자로 로그인합니다.

  2. 개인 액세스 토큰 > Tokens (classic) 로 이동하여 신규 토큰 생성 → 신규 토큰 생성 (classic)을 클릭합니다.

  3. 다음 세부 정보를 구성합니다.

    • 참고: 인식 가능한 레이블

    • 만료일: 만료를 설정하지 마세요.

    • 스코프: 다음 항목을 선택하세요.

      • 관리자:조직

      • 읽기:조직

      • 읽기:감사 로그

      • 읽기:엔터프라이즈

      • repo

      • user

  4. Click 토큰 생성

  5. CMA에 입력할 수 있도록 토큰을 복사하고 저장합니다.

  6. SAML SSO만을 시행하는 조직의 경우:

    1. 개인 액세스 토큰 > Tokens (classic)으로 이동합니다.

    2. 새로운 토큰 행을 찾아 구성 SSO를 클릭합니다.

    3. 각 조직이 SAML SSO를 시행하는 경우 승인을 클릭하고 조직의 신원 공급자를 통해 로그인합니다.

단계 2: CMA에서 API 커넥터 생성

필수 애플리케이션과의 통합을 설정한 후, CMA에 세부 정보를 추가합니다.

CMA에서 API 커넥터를 생성하려면:

  1. 네비게이션 메뉴에서 동반자 > 통합을 클릭하십시오.

  2. 구성된 통합 탭을 클릭합니다.

  3. 새로운을 클릭하십시오.
    신규 통합 패널이 열립니다.

  4. 추가하고자 하는 API 커넥터를 선택하십시오.

  5. 기능 드롭다운에서 SaaS 상태를 선택합니다.

  6. 이전에 생성된 세부 정보를 추가하십시오.

    • 기업 이름: 기업 슬러그

    • 관리자 Bearer 토큰: 1단계에서 생성한 토큰

  7. 저장을 클릭하십시오.

앱은 연결된 앱 테이블에서 연결됨 상태로 표시됩니다.