Cloud Access Security Broker (CASB)
According to Gartner, a cloud access security broker is a security policy enforcement point placed between cloud service consumers and cloud service providers.
CASBs aggregate enterprise security policies and enforce them as cloud resources are accessed.
Common CASB Features
- Authentication and single sign-on
- Authorization and credential mapping
- Device profiling
- Encryption and tokenization
- Logging and alerting
- Malware detection and prevention
- Data loss prevention and activity monitoring
- Shadow IT detection
Scope
CASBs are mainly used to protect SaaS applications in the cloud. Their support for PaaS and IaaS is usually more limited.
Deployment Modes
- Proxy mode
- API mode
Use Cases
- Shadow IT discovery and governance
- Data exfiltration prevention
- Threat detection and forensic investigation
- Compliance support and activity monitoring