Concept
Cloud access security broker (CASB)
How a broker gains visibility and control over cloud service use, why its deployment mode decides what it can actually see and stop, and where each mode runs out.
Goal
Being able to show a third party what a control does, when it did it and to whom — from evidence rather than from a diagram.
3 entries: 1 concept, 1 comparison, 1 scenario.
Concept
How a broker gains visibility and control over cloud service use, why its deployment mode decides what it can actually see and stop, and where each mode runs out.
Comparison
A SIEM centralises events from everything and keeps them. XDR goes deeper into one vendor's telemetry and can act on it. Most estates end up running both.
Scenario
A third-party specialist needs access to a single internal console for a fixed engagement. The easy answer is an account, a network route and an offboarding task nobody runs.
Where these entries sit in the taxonomy