" CASB is a solution to provide cloud access controls and visibility, acts as a gatekeeper. "
- Visibility – discover shadow IT cloud services and gain visibility into user activity within sanctioned apps
- Data security – enforce data-centric security such as encryption, tokenization, and information rights management
- Threat protection – detect and respond to insider threats, privileged user threats, compromised accounts
- Compliance – identify sensitive data in the cloud and enforce DLP policies to meet data residency and compliance requirements. Provide visibility for various compliance, for example, PII, HIPAA, PCI, PHI.
- Gives companies real-time security control enforcement or enough flexibility to "start out in an API mode or a monitoring mode of operation."
- help security teams understand a cloud security event before blocking is initiated.
- To simplify cloud access, companies need compliance reporting and usage monitoring.
- Protect your sensitive information and prevent data leak. ex. Prevent sensitive folders ( in OneDrive, dropbox, box, S3.... ) which are accessible by others who should not access it.
- Protect against insider threats and anomalous behaviors : some vendors also have UEBA capabilities.
- Get real-time controls for user access and sessions from managed and un-managed devices. ex. limit app access, block downloads, restrict copy/paste in SaaS apps
- Threat protection: some vendors also provide cloud sandbox capability
- Some vendors provide CSPM(Cloud Security PostureManagement) function: to evaluate and reduce laaS, PaaS and SaaS config risk
- Some vendors provide data protection functions. ex. data encryption.
/
Ref:
https://www.ciodive.com/news/gartner-security-risk-covid-strategy/585218/
https://www.mdeditor.tw/pl/2snx/zh-tw
https://www.statista.com/statistics/1067748/worldwide-cloud-access-security-broker-market-value/
https://www.appsruntheworld.com/top-10-cloud-access-security-broker-casb-software-vendors-and-market-forecast-2018-2023/
https://techcommunity.microsoft.com/t5/microsoft-security-and/securing-all-your-cloud-apps-with-microsoft/ba-p/1072310
https://cloudsecurityalliance.org/blog/2015/12/07/gartners-latest-casb-report-how-to-evaluate-vendors/
歡迎轉貼分享,轉貼時禁止修改內容及標題且保持所有連結。禁止商業使用,請註明原文標題、連結以及作者。
沒有留言:
張貼留言