What is software as a service (SaaS)?
SaaS is software the provider runs for you and you use over the internet. What the provider looks after, what stays with you, and what to ask before signing up.
Software as a service (SaaS) is software that the provider runs on its own cloud systems and you use over the internet, usually in a web browser. You do not install it on a server or look after the machines it runs on. Web-based email is the example given by the US National Institute of Standards and Technology (NIST), whose definition this lesson follows.
What the provider runs
Under NIST’s definition, a SaaS customer does not manage or control the network, the servers, the operating systems or the storage. The customer does not control the application’s features either, apart from a limited set of settings for its own users.
So the provider patches the servers, updates the application and keeps it running. You get the same version as every other customer, and new features arrive when the provider releases them.
The other two service models
NIST describes three ways of buying cloud services, and SaaS is the one that hands the most to the provider.
- Infrastructure as a service (IaaS) gives you processing, storage and networks. You install and look after the operating systems and applications yourself.
- Platform as a service (PaaS) gives you a place to run applications you have written or bought, without managing the servers or operating systems beneath them.
Why it suits a small business
The Australian Signals Directorate (ASD) points out that cloud providers typically have substantial resources and knowledge. It advises small businesses to use services where the provider carries a high level of the security work. Its example is using a trusted SaaS product to host a website, and not running a web server and its operating system yourself.
For an office with no IT staff, that takes patching a server off the list of jobs.
What is still yours
ASD is clear that the customer always keeps some responsibilities. With SaaS they are mostly about people and settings:
- Who can get to your data, and removing access when someone leaves.
- Giving each person only the access they need.
- Turning on multi-factor authentication. ASD recommends the phishing-resistant kind.
- Checking the default settings, which may not be secure enough for you.
- Backups, if the service does not include them.
What to ask before you sign up
ASD’s guidance uses a simple test. Suppose you delete a file by mistake, or someone gets into your account and deletes it. What happens next? Its questions include:
- Does the provider back up our data, or do we need to? Is that automatic, or an extra to set up and pay for?
- Can we restore data ourselves, and can we go back to an earlier version?
- Will we be told when someone signs in from an unfamiliar device?
- In which country is the data held?
- Is there a document that sets out who is responsible for what?
If the answer on backups is that you need your own, start with the 3-2-1 backup rule. For help with accounts and access across the services you use, see identity and access management.
Sources
- SP 800-145: The NIST definition of cloud computing (National Institute of Standards and Technology) nvlpubs.nist.gov
- Cloud shared responsibility model: guidance for individuals and small and medium businesses (Australian Signals Directorate) cyber.gov.au
- Cloud computing security for tenants (Australian Signals Directorate) cyber.gov.au