Q33
Single choice
A security analyst is evaluating all third-party software an organization uses. The analyst discovers that each department is violating the organization's policy by provisioning access to SaaS products without oversight from the security group and without using a centralized access control methodology.
Which of the following should the organization use to enforce its SaaS product access requirements?