incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
CybersecuritymediumShadow IT SaaSHigh asset
Scenario

Marketing uploaded customer spreadsheet to unsanctioned AI tool — CASB high-risk alert

A medium Cybersecurity scenario on Shadow IT SaaS.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.

catalog id · shadow-it-saas-marketing-ai

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Shadow-IT SaaS discovery
  • Business-data-leak scoping discipline
MITRE ATT&CKmitre-attack
  • Data from Information Repositories · CollectionT1213 · TA0009
    PartialMedium confidence

    Trains defensive scoping when business data is shared to an unsanctioned SaaS.

MITRE D3FENDmitre-d3fend
  • Network Traffic AnalysisD3-NTA
    MappedMedium confidence

    Trains traffic-visibility investigation of unsanctioned SaaS endpoints.

  • Resource Access Policy AuditingD3-RAPA
    MappedHigh confidence

    Trains the access-policy audit response to discovered shadow SaaS.

NIST CSF 2.0nist-csf-2
  • Asset Management · IdentifyID.AM · ID
    MappedHigh confidence

    Trains discovery and inventory of unsanctioned SaaS usage.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains scoping of business risk from a discovered shadow SaaS.

CISA Cybersecurity Performance Goalscisa-cpg
  • Secure Sensitive Data2.I
    MappedMedium confidence

    Trains the data-protection baseline for sensitive content leaving sanctioned systems.

  • Asset Inventory1.A
    MappedHigh confidence

    Trains the asset-inventory baseline that surfaces shadow SaaS.

CIS Controls v8cis-controls
  • Inventory and Control of Software AssetsControl 2
    MappedHigh confidence

    Trains the software-inventory control.

  • Service Provider ManagementControl 15
    MappedHigh confidence

    Trains the third-party-provider control the scenario exercises.