01Introduction
Employees adopt cloud apps faster than security teams can review them. A CASB was created to answer two questions: which cloud services are people using, and what are they doing with company data there?
02What is CASB?
A cloud access security broker (CASB) is a security control point between users and cloud services that provides visibility into cloud app usage, enforces access and data policies, and detects threats, either inline as a proxy or through APIs.
CASB is now usually bundled into security service edge (SSE) platforms with secure web gateways and zero trust network access, a pillar of zero trust. It commonly carries DLP policy and overlaps with SSPM on configuration.
03How CASB works
CASBs combine discovery with inline and API-based control.
- 1.
Discover
Analyze network and proxy logs to find sanctioned and unsanctioned cloud services.
- 2.
Control access
Apply policy by user, device, location and app, including blocking risky services.
- 3.
Protect data
Inspect uploads and sharing for sensitive content.
- 4.
Detect threats
Flag compromised accounts, unusual downloads and malware in cloud storage.
04Threats and risks
CASBs focus on users and SaaS, which leaves other ground uncovered.
Shadow IT
Unapproved apps holding company data with no security review.
Account takeover
Stolen SaaS credentials used from unfamiliar locations.
Proxy bypass
Unmanaged devices and direct API access that skip inline controls.
Infrastructure blind spot
A CASB governs app usage, not how your own cloud infrastructure is configured.
05How Parameter helps
Parameter covers the infrastructure and application side that a CASB doesn't.
Your own cloud
Cloud Security assesses the AWS, Google Cloud, Azure and Oracle Cloud accounts you build on.
Your own apps
The pentesting agents test the applications you ship to customers.
Your own code
Sentinel and Supply Chain cover what goes into them.

