What is a CASB?
A Cloud Access Security Broker (CASB) is a security policy enforcement point between cloud service consumers and cloud service providers. CASBs combine and interject enterprise security policies as cloud-based resources are accessed.
Four pillars of CASB
- Visibility: Discover all cloud services in use, including shadow IT
- Compliance: Ensure cloud usage meets regulatory requirements
- Data security: Protect sensitive data through encryption and DLP
- Threat protection: Detect and prevent threats targeting cloud applications
How CASBs work
CASBs can be deployed as a forward proxy, reverse proxy, or API-based integration. They inspect traffic between users and cloud applications to enforce security policies, detect anomalies, and prevent data exfiltration.