Docusign:配置SaaS姿态集成

Prev Next

Overview

SaaS Posture integrations provide visibility into the configuration and security posture of your connected SaaS applications. Cato continuously reviews the application settings and compares them to the recommended posture defined by Cato’s research team. This helps identify misconfigurations that can increase risk, such as authentication settings, third-party integrations, and data-sharing controls.

Posture data appears in the Applications dashboard, where you can view posture scores and the highest-severity findings across connected applications. You can review each posture check from the Posture page, including the issue details, status, and remediation action required to pass the check.

For more information, see Reviewing the Security Posture of Your SaaS Applications.

To configure the SaaS Posture integration, you need to:

  1. Configure the required settings in the SaaS application

  2. Create the API connector in the CMA

A CASB license is required for SaaS Posture integrations.

配置DocuSign集成

要配置DocuSign集成,请在DocuSign管理门户中创建应用程序。

条件

  • 您的DocuSign帐户必须配置一个组织(DocuSign管理员 / 组织管理)

  • 认证用户必须拥有组织管理员身份

  • 使用标准电子签名账户访问权限,用于账户级安全性设置、密码规则、用户和连接Webhook配置

步骤1:在DocuSign管理门户中配置集成

在DocuSign管理门户中配置用户和应用程序。

创建用户

配置集成的第一步是创建具有所需角色的用户。

要创建用户:

  1. 在DocuSign管理门户中创建用户。 有关详细信息,请参阅DocuSign文档。

  2. 为用户分配组织管理员或安全报告管理员角色。

  3. 在用户页面复制并保存用户ID以便在CMA中输入。

配置应用程序

下一步是创建集成密钥和私钥。

配置应用程序:

  1. 在DocuSign管理门户,导航到设置 > 集成 > 应用和密钥。

  2. 点击添加应用和集成密钥。

    image__73_.png

  3. 添加以下内容:

    • 应用名称:选择一个应用名称

    • 集成类型:第三方集成密钥

      image__74_.png

    • 重定向URIs:点击添加URI 并输入:

      https://cc.catonetworks.com/redirect/cas/appconnector/callback      

    • 允许的HTTP方法:检查GET和POST        

  4. 复制并保存集成密钥以便在CMA中输入。

  5. 在服务集成部分,点击生成RSA。 复制并保存私钥以便在CMA中输入。

    注意:此信息仅显示一次。

  6. 应用程序在 集成的应用程序 表中显示,状态为 已连接。

步骤2:在CMA中创建API连接器

设置所需应用程序的集成后,在CMA中添加详细信息。

要在CMA中创建API连接器:

  1. 从导航菜单中,点击资源 > 集成。

  2. 点击已配置集成选项卡。

  3. 点击 新建。

    新集成面板开启。

  4. 选择您要添加的 SaaS应用程序。

  5. 在 功能下拉菜单中选择 SaaS姿态。

  6. 添加在步骤一中创建的详细信息。

  7. 如果您要集成开发环境,请检查是开发环境框,如果与生产环境集成,请取消该选项。

  8. 在同意端点 字段中:

  9. 应用程序在 集成的应用程序 表中显示,状态为 已连接。

    DocuSign同意流程开启。

  10. 授予这些范围的同意:

    • 签名

    • 隐喻

    • 用户读取

    • organization_read

    • account_read

    • group_read

    • permission_read

    • identity_provider_read

    • domain_read

  11. 应用程序在集成应用程序表中可见,并显示为已连接状态。