Cloud Access Security Broker
A Cloud Access Security Broker (CASB) is a security tool that sits between an organization's users and the cloud services they use, acting as a checkpoint that enforces the organization's security policies. As users access cloud applications, the CASB inspects that traffic and applies rules to help keep data and access under control. It can be deployed either on-premises or in the cloud.
A CASB is a security policy enforcement point positioned between cloud service consumers and cloud service providers, deployable as software, hardware, on-premises, or cloud-based. It inspects traffic between users and cloud services (including SaaS) to enforce security policies as users access those services. Operating as an intermediary between an organization's infrastructure or users and cloud providers, a CASB provides visibility into and control over cloud usage. Note that a CASB is a technical control and does not itself provide security governance or leadership; decisions about which policies to enforce, and accountability for those decisions, remain with the organization and its security leadership.
Why it matters
As organizations shift more of their operations into cloud and SaaS applications, they often lose the visibility and control they once had over data flowing through on-premises networks. A CASB matters because it re-establishes a policy enforcement point between users and the cloud services they access, giving an organization a way to inspect that traffic and apply its own security rules. Without such a checkpoint, sanctioned and unsanctioned cloud usage can proceed largely unobserved, making it difficult to govern where data goes and who can reach it.
The value of a CASB, however, depends heavily on the quality of the policies it is asked to enforce. A CASB is a technical control; it does not decide what should be protected or how, and it does not supply security leadership. Those decisions, and accountability for them, remain with the organization and its security leadership. Deployed without clear governance and well-defined policy objectives, a CASB can generate activity without meaningfully reducing risk, which is a common source of disappointment for buyers who expect the tool alone to solve cloud security.
For security leaders, a CASB is best understood as one instrument within a broader cloud security and governance program rather than a substitute for one. Its effectiveness typically varies by how well cloud usage is understood, how policies are scoped, and how the tool is integrated with the rest of the organization's controls and processes.
Who it's relevant to
Inside CASB
Common questions
Answers to the questions practitioners most commonly ask about CASB.