CYYDER CLARITY™ Framework | Category: 🟧 Cloud & SaaS Security

Lab 7 — SaaS & Cloud Misconfiguration Decision Sandbox

💼 Business Scenario: The Marketing department created an anonymous external share link (“Anyone with the link can access/download”) on OneDrive containing a sensitive file Q4_Customer_DB_and_Strategy.xlsx. An unauthenticated external user (or a competitor) obtains the link and attempts to view and download the document. Which Cloud Security Control (CASB, DLP, Information Protection, or Tenant Sharing Policy) would intercept and prevent the data exposure?

ContextLandscapeAlignmentRisk & ControlTesting

Cloud Sharing & External Access Simulator

📊

Q4_Customer_DB_and_Strategy.xlsx

Sensitivity: contains PII, customer emails & internal financials.

Sharing action: anonymous external share link

https://company.sharepoint.com/:x:/s/marketing/guest-token-12345

External access scenarios

SaaS Data Access Pipeline

Request flow through the cloud control layers.

01

Anonymous Link Click

External Internet

02

Tenant Sharing Policy & Guest Access

M365 / SharePoint Level

03

Cloud Access Security Broker

CASB / Defender for Cloud Apps

04

Data Loss Prevention Engine

DLP Content Inspection

05

Purview Information Protection

MIP Classification & Encryption Rights

06

File Access Outcome

Download decision

Cloud & SaaS Defense Controls

Tenant Sharing & Guest Access — baseline governance

Binds every external session to a verified mailbox identity.

Content may be previewed in browser but never leaves the tenant.

Awaiting simulation — configure controls, pick a persona, then run the access attempt.

What should the CISO ask? — Executive governance