If the posture score of your apps and instances is poor, you can improve it for better security. You can improve the posture score by analysing either the 3rd Party Apps with the lowest posture score or the critical severity rules that have the highest number of failures. Given below are various ways of using SSPM to improve your security posture.
Remediate Failed Finding by Rule
In scenarios when you have a bulk of resources failing because of a particular rule, then it is good to remediate that rule. Remediating such rules will clear a bulk of your failed findings, giving you maximum reduction in your failed count. To remediate the rule failed for max number of resources, follow the procedure:
-
Navigate to API-enabled Protection > Security Posture SaaS > Apps.
-
Click on the total Failed Findings number in the metrics section. The page will navigate you to the Findings page with failed results.

-
Click on the Rules tab.
-
Sort the #Failed Findings column in the table in descending order. The rule at the top is the one failed most number of times.

-
Click on the rule and navigate to the Remediation tab and follow the steps for remediation.
Remediate Failed Finding by Severity
Critical and High severity findings have a significant impact on your security posture and hence it is a good point to start with remediating failed findings for these severities. To remediate failed findings, follow the procedure:
-
Navigate to API-enabled Protection > Security Posture SaaS > Apps.
-
Click on the total Failed Findings number in the metrics section. The page will navigate you to the Findings page with failed results.

-
Select Add Filter > Severity > Critical or High.

-
Analyse the list of failed critical findings. Choose one rule by clicking on it.
-
Navigate to the Remediation tab and follow the steps for remediation.
Remove Irrelevant Rules from Policy
In some cases, some rules may not be relevant in your environment. In which case, you could consider disabling irrelevant rules to reduce the failed findings. To analyse the rules attached to a policy, follow the procedure:
-
Navigate to Policies > SaaS Security Posture Management > Policies.
-
Click on the policy to see the details.
-
Go to the Rules field to see the list of rules assigned to this policy. If the rule isn’t relevant, consider disabling it from the policy. You can review the rule by going through the description of the rule.
-
Click Save.
Analyse 3rd Party Apps
3rd Party App score has a significant impact on your security posture. Hence, managing your 3rd Party App security will be a good place to begin to improve your security posture. To check the permissions and scopes for a 3rd Party App, follow the procedure:
-
Navigate to API-enabled Protection > Security Posture SaaS > 3rd Party Apps.
-
Identify the 3rd Party App by filtering for Critical severity.
-
Analyse the 3rd Party App and remediate using the following approach:
-
Check if the 3rd Party App is required – If it’s not needed, remove it entirely. This reduces potential attack surface and improves the overall health of your SaaS environment.
-
Inspect permissions and scope – When you click on a 3rd Party App, a detail pane will show the permissions and scopes requested. Review them carefully, and if possible, revoke any permissions that are not strictly required for the app to meet its business function.
-
In some cases, the list of permissions and scopes may not be available. Review the 3rd Party App in the context of your organization’s requirements and decide whether to keep or remove it.
-
-
Update app status – Mark the app as either “Approved” (safe to use), “Risk-Accepted” (needed but has some risk).
-
Update Posture Score settings – Enable “Exclude Approved 3rd Party Apps” and “Exclude Risk Accepted 3rd Party Apps” in Posture Score settings. This way, your posture score calculation will exclude such apps. See Customizing Posture Score – Netskope Knowledge Portal to learn more.
-

