What is Cloud Access Security Broker (CASB)?
Cloud Access Security Broker (CASB) is a security control point that sits between users and cloud services to enforce data security policies, provide visibility into cloud application usage, and detect threats. It covers both sanctioned and unsanctioned SaaS, IaaS, and PaaS environments.
What it does
A CASB sits inline or in API mode between an organization's users and the cloud services they access. It performs four core functions:
- Visibility: Discovers every cloud application in use, including shadow IT apps employees adopt without IT approval. It logs who accessed what, when, and from where.
- Data security: Inspects content moving to and from cloud services. It applies data loss prevention (DLP) rules to block or quarantine files containing sensitive data such as credit card numbers, health records, or source code.
- Compliance: Maps cloud usage to regulatory frameworks such as HIPAA, PCI-DSS, and FERPA. It generates reports showing which services meet policy and which do not.
- Threat protection: Detects anomalous behavior such as a user downloading thousands of files in minutes, logging in from two countries within an hour, or sharing documents with personal email addresses.
CASBs operate in two main deployment modes. API mode connects directly to cloud service APIs and scans data at rest and activity logs without touching network traffic. Inline (proxy) mode intercepts traffic in real time and can block actions before they complete.
Why teams buy it
Security teams buy CASBs when they lose visibility after moving workloads to SaaS. A firewall cannot see inside an HTTPS session to Salesforce or Google Drive. A CASB fills that gap. Education organizations use CASBs to meet student data protection laws such as CIPA and FERPA. Enterprises use them to prevent data exfiltration through personal cloud storage accounts.
What to look for
- Coverage: Does it support the specific SaaS apps your organization uses, not just the top 20?