Concept
Cloud access security broker (CASB)
How a broker gains visibility and control over cloud service use, why its deployment mode decides what it can actually see and stop, and where each mode runs out.
Goal
Removing reachable things. Every exposed port, standing permission and implicit route is surface, whether or not it is currently in use.
9 entries: 5 concepts, 2 comparisons, 2 scenarios.
Concept
How a broker gains visibility and control over cloud service use, why its deployment mode decides what it can actually see and stop, and where each mode runs out.
Concept
How software-defined networking and cloud-delivered security converge at distributed edges, so access policy follows the user, the device and the data.
Concept
The cloud-delivered security half of SASE, without the networking half, and what stays unsolved when you buy the security services on their own.
Concept
How an application-aware overlay picks a path across mixed transport, why that is a routing decision rather than a security one, and what it leaves for something else to do.
Concept
How brokered, application-specific access replaces network-level connectivity, and what an over-broad application definition gives back.
Comparison
A VPN grants reachability to a network and then trusts you. ZTNA brokers one application per request and never puts you on the network at all.
Comparison
SSE is the security half of SASE. Where the boundary falls decides whether branch and wide-area connectivity is part of the purchase or still your problem.
Scenario
A finance analyst reaches payroll from hotel Wi-Fi on a managed laptop whose endpoint protection is stale. The identity is valid, the device is not, and allow or deny is the wrong pair of answers.
Scenario
A third-party specialist needs access to a single internal console for a fixed engagement. The easy answer is an account, a network route and an offboarding task nobody runs.
Where these entries sit in the taxonomy