SaaS SaaS Security and Compliance 1 — Questions and Answers
Question 1: Which security framework is most commonly referenced for SaaS vendor compliance in the United States?
- SOC 2 Type II (Correct answer)
- ISO 27001
- PCI DSS
- HIPAA
Correct answer: SOC 2 Type II
SOC 2 Type II is the most widely referenced SaaS security framework in the US, auditing controls over a period of time.
Question 2: What does the shared responsibility model mean for SaaS customers?
- The vendor handles all security, including user data
- The customer is responsible for identity, access, and data governance (Correct answer)
- The customer must manage the underlying infrastructure
- Both parties share equal responsibility for network security
Correct answer: The customer is responsible for identity, access, and data governance
In the SaaS shared responsibility model, the vendor secures infrastructure and application, while the customer manages identity, access controls, and data governance.
Question 3: Which regulation governs the privacy of health information handled by SaaS applications used by US healthcare providers?
- GDPR
- CCPA
- HIPAA (Correct answer)
- SOX
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) governs the handling of protected health information (PHI) by covered entities and their business associates.
Question 4: What is a Business Associate Agreement (BAA) in the context of SaaS?
- A contract defining SLA uptime guarantees
- A legal contract required when a SaaS vendor handles PHI on behalf of a HIPAA-covered entity (Correct answer)
- An agreement outlining software licensing terms
- A partnership deal between two SaaS companies
Correct answer: A legal contract required when a SaaS vendor handles PHI on behalf of a HIPAA-covered entity
A BAA is a legal contract required under HIPAA when a SaaS vendor processes, stores, or transmits protected health information on behalf of a covered entity.
Question 5: What is the purpose of Single Sign-On (SSO) in enterprise SaaS security?
- To allow users to access multiple applications with one set of credentials (Correct answer)
- To encrypt data at rest across all SaaS platforms
- To automatically patch security vulnerabilities
- To monitor network traffic for intrusions
Correct answer: To allow users to access multiple applications with one set of credentials
SSO enables users to authenticate once and gain access to multiple SaaS applications, reducing password fatigue and centralizing access control.
Question 6: Which encryption standard is considered best practice for protecting SaaS data at rest?
- MD5
- SHA-1
- AES-256 (Correct answer)
- DES
Correct answer: AES-256
AES-256 (Advanced Encryption Standard with 256-bit keys) is the industry best practice for encrypting SaaS data at rest.
Which security framework is most commonly referenced for SaaS vendor compliance in the United States?