Cloud Access Security Broker (CASB)
A Cloud Access Security Broker (CASB) is a security component that mediates between users and cloud services. A CASB creates transparency about the cloud and SaaS applications used, enforces security policies and helps to control data outflow, shadow IT and risky access. The term is particularly relevant for organizations that use many cloud-based applications and have to manage security requirements centrally.
Typical CASB functions are application discovery, access control, data classification, policy enforcement, threat detection and support for compliance requirements. Depending on the architecture, a CASB can work via APIs, proxies or integrations with identity services. In modern security environments, it complements SaaS Security and Cloud Security, because it makes the usage and risks of cloud applications visible.
Cloud access security brokers are closely linked to Data Protection. They help to detect sensitive data in cloud services and to control its disclosure on the basis of rules. At the same time, a CASB should not be understood as an individual measure, but as part of a security architecture that considers identities, devices, data and applications together.
See also: Identity Security.