Cloud Access Security Broker (CASB)
What is Cloud Access Security Broker (CASB)?

Cloud access security broker or CASB is a security solution that sits between cloud service consumers and cloud service providers and brokers secure connection to SaaS applications, ensuring sensitive data remains protected, data loss is prevented, and the chances of a cyberattack are reduced.

A professional holding a laptop.
  • CASB explained
  • Where does CASB fit in SASE?
  • Why should I consider CASB?
  • How does CASB work?
  • Features of CASB
  • HPE and CASB
  • Benefits of HPE Aruba Networking CASB
CASB explained
Functions of a CASB diagram.
Functions of a CASB diagram.
TAP IMAGE TO ZOOM IN

CASB explained

According to Gartner%3Ca%20href%3D%22https%3A%2F%2Fwww.gartner.com%2Fen%2Finformation-technology%2Fglossary%2Fcloud-access-security-brokers-casbs%23%3A%7E%3Atext%3DCloud%2520access%2520security%2520brokers%2520%28CASBs%29%2520are%2520on%252Dpremises%252C%2Ccloud%252Dbased%2520resources%2520are%2520accessed.%22%20target%3D%22_blank%22%20data-analytics-region-id%3D%22footnote_tip%7Clink_click%22%3EGartner%20IT%20Glossary%2C%20%E2%80%9CCloud%20Access%20Security%20Broker%2C%E2%80%9D%20August%202024.%3C%2Fa%3E,  “Cloud access security brokers (CASBs) are on-premises, or cloud-based security policy enforcement points, placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as the cloud-based resources are accessed.”

In a world where confidential corporate data is distributed across data centers, public clouds (IaaS, PaaS), or SaaS applications, CASB ensures data protection, compliance to regulations, and threat protection and helps security teams extend their Zero Trust network security beyond on-premises data centers and into cloud and SaaS. A CASB solution offers the following four functions:

  • Visibility: Provide visibility into all user traffic and SaaS applications used by employees.
  • Compliance: Enforce compliance with regulations like GDPR, PCI DSS, HIPPA, etc., by limiting access to sensitive data hosted across multiple cloud environments.
  • Data security: Enforce data security policies, prevent unauthorized sharing of data, and monitor and scan data usage to and from SaaS providers.
  • Threat protection: Remediate threats whenever unusual behaviors are detected across cloud application, reducing risks from ransomware, malware, or compromised users.
Where does CASB fit in SASE?

Where does CASB fit in SASE?

SASE (Secure Access Service Edge) is a combination of SD-WAN and cloud-delivered security service edge or SSE. SSE is comprised of key security services including Cloud access security broker or CASB that enables businesses to secure sensitive data in public cloud and help deliver part of the security vision of SASE.

Why should I consider CASB?
How CASB works diagram.
How CASB works diagram.
TAP IMAGE TO ZOOM IN

Why should I consider CASB?

Sensitive corporate data no longer resides behind a firewall in your servers, it is spread across data centers, public cloud or SaaS applications. And with hybrid work, employees access data and apps via unsecured networks—opening critical security challenges for businesses and security teams starting with:

1. How to restrict employees from sharing (uploading/downloading) sensitive data on managed and unmanaged (by IT) cloud apps.

2. How to control the use of applications and services that are not explicitly approved by IT (shadow IT).

3. How to meet various compliance regulations that mandate strict data privacy.

4. How to secure sensitive data in public cloud and restrict access on BYOD.

5. How to monitor data in public cloud for malware, ransomware, etc. and safeguard employees from downloading these types of malicious software.

The availability of cloud services in a click offers easy and unchecked access to employees. Things get complicated when employees use certain applications like GitHub, Dropbox, etc., for both professional and personal work, or create accounts on unmanaged apps for data analysis or managing project workflows. Actions like these open unseen challenges for security teams and put the corporate data at huge security risk.

CASBs help security teams extend their control to cloud by providing visibility into all cloud services used by the employees, monitoring or scanning SaaS applications for potential threats, securing data against threats, meeting compliance regulations, and restricting sensitive data sharing.  

How does CASB work?

How does CASB work?

A CASB solution is delivered via on premises hardware or software or as a cloud service, CASB uses proxy and API methods to enforce strong security checks: 

  • Proxy workflow: for real time data inspection.

1. User attempts to access a SaaS app or IaaS platform. Traffic is intercepted by CASB and SSL inspection is performed.

2. CASB validates identity and applies policy via in-line CASB and data protection controls to restrict upload, download, and share activities. Compliances are checked, and access is automatically adapted based on real-time context changes.

3. With restricted actions in place, secure SaaS access is extended to the user while restricting unauthorized behaviors to prevent data loss and enforce compliance.

4. Admins gain visibility into all user activity while accessing the SaaS app. If security posture changes or the user attempts unauthorized activity, access is reassessed, and admins alerted.

  • API workflow: for scanning data at rest.

CASB leverages out-of-band application programming interface (API) security for monitoring data stored in cloud services like Microsoft Office 365, Salesforce, Workday, SharePoint, etc. CASB integrates with the APIs of these cloud services and scans for malware, ransomware, malicious software, and other types of cyber threats. 

Features of CASB

Features of CASB

  • In-line CASB: Enforce security policies in real time as data moves to and from the cloud. This can include authentication, encryption, and other security controls.
  • SSL inspection for CASB control: Inspect encrypted SSL/TLS traffic to stop potential threats or data leakage before it happens. By decrypting the traffic, the CASB can apply security policies to protect sensitive data.
  • Visibility into apps and shadow IT: Shadow IT refers to the use of applications and services without IT’s explicit approval. With CASB businesses gain visibility into SaaS apps and shadow IT to better understand and manage the risks associated with sanctioned and unsanctioned app usage.
  • Granular control of restricted actions: Admins can set granular policies that restrict certain actions like uploading, downloading, sharing data, etc., from any SaaS application. This is an important requirement to protect against data loss and ensure compliance with various regulations.
  • DLP for SaaS based apps: DLP (Data Loss Prevention) helps protect sensitive data within SaaS applications by monitoring, detecting, and blocking potential data breaches or unauthorized access. DLP can use regular expressions (regex) and dictionary matching or use OCR (Optical Character Recognition) to identify and protect sensitive data.
  • Compliance with predefined and custom dictionaries: Predefined and custom dictionaries can be created to ensure compliance with specific regulations like HIPAA, PCI DSS, GDPR, and NIST. These dictionaries contain terms and patterns that are unique to each regulation, helping organizations meet their compliance obligations.
HPE and CASB

HPE and CASB

HPE Aruba Networking CASB is a modern Cloud Access Security Broker (CASB) solution designed to enhance cloud security and secure access to SaaS applications for organizations. Our CASB serves as the security mediator between users and SaaS applications, providing inline CASB protection for data in motion, effectively regulating data flows, uncovering shadow IT, and preventing data loss.

HPE Aruba Networking CASB provides end‑to‑end visibility, allowing centralized management of user access, downloads, and sharing permissions. Our CASB’s operation is straightforward: it proxies traffic to avoid risky pass-through connections, validates identities, applies policies, and securely connects users to resources while inspecting traffic and monitoring user experience.

Emphasizing ease of use and scalability, HPE Aruba Networking CASB delivers secure access to modern cloud services and applications. In our cloud‑centric world, CASB as part of the broader HPE Aruba Networking SSE platform aims to deliver value with increased visibility, compliance, and data security from the outset.

Benefits of HPE Aruba Networking CASB

Benefits of HPE Aruba Networking CASB

HPE Aruba Networking CASB enables businesses to embrace cloud and extend the same level of data security as they have for on premise services. Our CASB solution offers the following benefits:

  • Enhanced data security: Provides real-time scanning and monitoring of data usage and flow to and from the SaaS provider. This includes DLP capabilities that protect sensitive data by preventing unauthorized sharing and ensuring that data security policies are enforced. 
  • Visibility and control: Offers detailed visibility and control over cloud environments. Teams can see all user traffic, identify which cloud applications people are using, and apply granular controls to manage how data is accessed and used. 
  • Compliance: Supports compliance with data privacy regulations by enforcing corporate cybersecurity policies across multiple cloud environments.  Risk assessments and scores for users and applications aid in the management of compliance requirements. 
  • Threat mitigation: Protects against both known and unknown threats, including anti-malware and anti-virus. Detects unusual behavior across cloud applications, identifying risks like ransomware, compromised users, and rogue applications, and can automatically remediate threats to limit organizational risk. 
  • Operational efficiency: Consolidates multiple types of security policy enforcement into a single point, for streamlined security operations, and simplified management of security policies and securing multiple cloud services. 

Related products, solutions or services

HPE Aruba Networking SSE

Enable seamless and secure access for every user, device, and application from anywhere with Security Service Edge (SSE).

HPE Aruba Networking EdgeConnect SD-WAN

Enable data access wherever it lives with a secure SD-WAN SASE solution that produces both the connectivity and security necessary for hybrid cloud.

Related topics

SSE (Security Service Edge)

Zero Trust Network Access (ZTNA)

Secure Access Service Edge (SASE)