What is Cloud Access Security Broker (CASB)?

Data Security Knowledge Base 

What is a Cloud Access Security Broker (CASB)?

Text

A cloud access security broker (CASB) is a security policy enforcement point that sits between an organization's users and the cloud services they access. It gives security teams visibility into cloud app usage and enforces policies, such as authentication, encryption, data loss prevention, and threat protection, across sanctioned and unsanctioned apps and on both managed and unmanaged devices. 

First defined by Gartner in 2012 to address the rapid adoption of SaaS, CASBs are built around four pillars — visibility, data security, threat protection, and compliance — are now a core component of Secure Access Service Edge (SASE) and Security Service Edge (SSE) architectures.

How does a CASB work?

Text
A CASB works as a central policy enforcement point positioned between users and the cloud services they access. As data flows to and from cloud apps, it applies the organization's security policies to user behavior, data movement, and authentication — enforcing rules whether an app is sanctioned, tolerated, or unsanctioned. It continuously monitors activity to surface risky users and apps, blocks unauthorized data sharing, and can automatically remediate threats like ransomware or account compromise.

Why do organizations need a CASB?

Text
Organizations need a CASB because they adopt cloud apps faster than security teams can audit them, and each new app is another place sensitive data can leak and another target for attackers. Traditional "block or allow" security can't handle a workforce spread across multiple devices and locations. A CASB closes that gap, giving visibility into shadow IT, enforcing consistent policy across cloud apps, protecting sensitive data with DLP and encryption, and detecting threats like compromised accounts before they become breaches.

What are the four pillars of a CASB?

Text
CASBs are built around four core pillars, originally defined by Gartner. Visibility discovers all cloud apps in use, including shadow IT, and scores their risk. Compliance enforces data and access policies aligned with regulations. Data security protects sensitive information using data loss prevention (DLP), encryption, and tokenization. Threat protection detects and blocks attacks like malware, compromised accounts, and anomalous behavior. Together, they give organizations full control over how data moves through their cloud services.