GitHub: 配置SaaS姿态集成

Prev Next

Overview

SaaS Posture integrations provide visibility into the configuration and security posture of your connected SaaS applications. Cato continuously reviews the application settings and compares them to the recommended posture defined by Cato’s research team. This helps identify misconfigurations that can increase risk, such as authentication settings, third-party integrations, and data-sharing controls.

Posture data appears in the Applications dashboard, where you can view posture scores and the highest-severity findings across connected applications. You can review each posture check from the Posture page, including the issue details, status, and remediation action required to pass the check.

For more information, see Reviewing the Security Posture of Your SaaS Applications.

To configure the SaaS Posture integration, you need to:

  1. Configure the required settings in the SaaS application

  2. Create the API connector in the CMA

A CASB license is required for SaaS Posture integrations.

配置GitHub集成

要配置GitHub集成,请创建新的个人访问令牌。

先决条件

  • 您必须购买GitHub Enterprise Cloud或GitHub Enterprise Server许可证。

  • 您正在连接的组织必须附属于GitHub Enterprise账户。

步骤1:在GitHub开发者中心配置集成

在GitHub开发者中心,识别要输入到CMA的访问令牌。

要配置GitHub集成:

  1. 使用指定的用户登录到您的GitHub账户来拥有令牌。

  2. 导航到 个人访问令牌 > 令牌(经典)并点击 生成新令牌 → 生成新令牌(经典)。

  3. 配置这些详细信息:

    • 注意:可识别标签

    • 到期日:不要设置到期日

    • 权限:选择以下内容:

      • admin:org

      • read:org

      • read:audit_log

      • read:enterprise

      • repo

      • 用户

  4. 点击生成令牌

  5. 复制并保存令牌,以便输入到CMA中。

  6. 仅对于强制执行SAML SSO的组织:

    1. 导航到个人访问令牌 > 令牌(经典)

    2. 找到新令牌行并点击 配置SSO

    3. 对于每个强制执行SAML SSO的组织,点击授权并通过组织的身份提供者登录。

步骤2:在CMA中创建API连接器

在您设置集成所需的应用程序后,在CMA中添加详细信息。

要在CMA中创建API连接器:

  1. 从导航菜单中点击资源>集成。期间Always-On和防篡改被禁用多久。

  2. 点击 已配置集成选项卡。

  3. 点击新建。
    新集成面板开启。

  4. 选择您要添加的 SaaS应用程序。

  5. 在 功能下拉菜单中选择 SaaS姿态。

  6. 添加在步骤一中创建的详细信息。

    • 企业名称:企业Slug

    • 管理员Bearer令牌:您在步骤一中创建的令牌

  7. 单击 保存。

应用程序在集成应用程序表中可见,并显示为已连接状态。