Search the library

One index over every entry: titles, acronyms, categories, audiences, diagram labels and body text. 10 entries are indexed.

The complete library

Every published entry, grouped by type. None of it depends on client-side search: this listing is static HTML, and the terms under each entry are the same terms the index holds, so find-in-page reaches them all.

Concepts 5 entries

One architecture or control, defined, diagrammed and scoped.

  • Secure access service edge (SASE)

    How software-defined networking and cloud-delivered security converge at distributed edges, so access policy follows the user, the device and the data.

    • Cloud and networks
    • Intermediate
    • 3 min read
    • Security architects
    • Network engineers
    • Technical leaders
    Indexed terms for this entry (66)

    CASB · DLP · FWAAS · SASE · SDWAN · SWG · Remote worker · Finance analyst on hotel Wi-Fi · Managed laptop · Posture reported by the endpoint agent · Adversary on the same network · Branch site · SD-WAN edge with per-application steering · Edge gateway · Tunnel termination and path selection · Policy engine · Allow, step up, isolate or block · Security service chain · Selected by the policy verdict · ZTNA broker · Secure web gateway · Cloud access security broker · Firewall as a service · Data loss prevention · Identity provider · Single sign-on, MFA and risk claims · Security operations · Detection, investigation and response · Web destination · Unclassified internet site · SaaS platform · Sanctioned but not enterprise-operated · Payroll application · Private, with no inbound exposure · Payroll records · Shared and public networks · Corporate sites · Nearest SASE point of presence · Policy control · Security services · Public internet · Sanctioned SaaS · Private applications · Enterprise control plane · Network plane · Policy plane · Security plane · Opens payroll from hotel Wi-Fi · Encrypted tunnel to the nearest edge · SD-WAN overlay, steered per application · Request presented for a decision · Verdict and the controls it requires · Permitted web traffic · Permitted SaaS traffic · Brokered session, no network route · Application reads payroll records · Authentication and a second factor · Identity, group and risk claims · Device posture: signatures are stale · Session and path metrics · Every decision and the signals behind it · Inspection and data-handling events · Credential capture on the shared network · Stolen credentials replayed at the edge · Refused: unknown device, no posture signal · Payroll download blocked to a stale device

  • Security service edge (SSE)

    The cloud-delivered security half of SASE, without the networking half, and what stays unsolved when you buy the security services on their own.

    • Cloud and networks
    • Intermediate
    • 4 min read
    • Security architects
    • Network engineers
    • Technical leaders
    Indexed terms for this entry (82)

    CASB · DLP · SSE · SWG · Remote worker · Home or public network, no site involved · Managed laptop · Agent forwards traffic to the service edge · Adversary · Branch site · Users and devices behind one router · Wide-area transport · Circuits and steering SSE does not include · Service edge ingress · Agent, proxy or tunnel termination · Policy engine · Allow, step up, isolate or block · Secure web gateway · URL and content categorisation · TLS inspection where permitted · Malware and script analysis · Browser isolation for risky sites · Cloud access security broker · Sanctioned tenant enforcement · Unsanctioned SaaS discovery · API posture checks on tenants · Session controls inside SaaS · ZTNA broker · Brokered access to one application at a time · Data loss prevention · Content classification · Upload and download inspection · Block, mask, or allow and log · Identity provider · Single sign-on, MFA and risk claims · Security operations · One event stream from four services · Web destination · Unclassified internet site · SaaS platform · Sanctioned but not enterprise-operated · Private application · Reached by broker, with no inbound exposure · Users on any network · Branch and office sites · Wide-area transport, bought separately · Cloud security service edge · Policy control · Security services · Public internet · Sanctioned SaaS · Private applications · Enterprise control plane · Network plane · Policy plane · Security plane · Opens a site, a SaaS tenant or an application · Traffic forwarded to the nearest edge · Site traffic over transport bought elsewhere · Arrives at the security service edge · Authentication and a second factor · Identity, group and risk claims · Device posture from the local agent · Request presented for one decision · Web traffic, with the inspection it requires · SaaS traffic, with the tenant rules that apply · Private application access, scoped to one app · Data rules for this user and destination · Permitted web traffic, inspected · Inspected upload passed on · Permitted traffic to the sanctioned tenant · Brokered session, no network route · Every verdict and the signals behind it · Web inspection and isolation events · SaaS usage, including unsanctioned tenants · Data-handling decisions and their matches · Link to a credential-harvesting lookalike · Probes for exposed private applications · Attacks the transport the service does not run · Refused: newly registered domain, no category · No application named, so no session exists · Upload of regulated data refused

  • Software-defined WAN (SD-WAN)

    How an application-aware overlay picks a path across mixed transport, why that is a routing decision rather than a security one, and what it leaves for something else to do.

    • Cloud and networks
    • Intermediate
    • 4 min read
    • Network engineers
    • Security architects
    • Technical leaders
    Indexed terms for this entry (71)

    DLP · FWAAS · SDWAN · SWG · Branch staff · ERP client and a sanctioned SaaS suite · Card payment terminal · Kept in its own segment · Compromised device on guest wireless · SD-WAN edge device · Application classification · Loss, latency and jitter probes · Per-application path selection · Overlay tunnel encryption · Segment separation · Path choice · Which link this flow takes, decided locally · Contracted circuit · Predictable, metered, expensive · Local broadband · Cheap capacity, variable loss · Cellular standby · Held for failover only · Data centre edge device · Terminates the overlay tunnel · ERP application · Order records · Cloud security service · A separate purchase, not part of the fabric · Secure web gateway · Firewall as a service · TLS inspection · Data loss prevention · Sanctioned SaaS suite · Internet destination · SD-WAN orchestrator · Holds one policy for every site · Network operations · Path and application performance · Retail branch · Card payment segment · Guest wireless · Carrier transport · Regional data centre · Public internet · Sanctioned SaaS · Vendor-hosted control plane · Application overlay · Transport underlay · Management plane · ERP, SaaS and web traffic from the branch LAN · Payment traffic, kept in its own segment · Classified flow presented for steering · One encrypted overlay tunnel to the data centre · Internet-bound traffic steered to inspection · Reaches the ERP application · Application reads order records · Inspected SaaS traffic · Inspected web traffic · ERP flows placed on the contracted circuit · SaaS and web exit locally · Failover when both circuits degrade · Carries the tunnel across the carrier network · Carries the same tunnel over cellular · Carries the tunnel to the security service · Application policy pushed to every edge · Loss, latency and jitter per circuit · Path changes and per-application performance · Probes the branch LAN for the payment terminal · Its outbound traffic is steered like any other flow · Denied: guest wireless has no route to the payment segment

  • Cloud access security broker (CASB)

    How a broker gains visibility and control over cloud service use, why its deployment mode decides what it can actually see and stop, and where each mode runs out.

    • Data protection
    • Intermediate
    • 4 min read
    • Security architects
    • Security operations
    • Auditors and risk
    Indexed terms for this entry (63)

    CASB · Salesperson · Working through a notice period · Managed laptop · Agent steers cloud traffic to the proxy · Personal device · No agent, so nothing to steer traffic · Insider or hijacked account · Forward-proxy position · Inline, and only if traffic is steered to it · Reverse-proxy position · Inline via sign-on, no agent required · Out-of-band connector · Reads the tenant after the event · Shadow-IT discovery · Service catalogue with risk ratings · Users and volume per service · Newly seen services · Sanction, restrict or block advice · Data policy · Allow, coach, redact, quarantine or block · Identity provider · Single sign-on, and the reverse-proxy hook · Security operations · Investigation and audit evidence · Firewall and web proxy logs · Sanctioned CRM tenant · Connected by API and reachable inline · Files and sharing links · Personal file-sharing service · Discovered, never connected · Managed endpoints · Unmanaged and personal devices · Cloud access security broker · Inline positions · Out-of-band positions · Sanctioned cloud tenant · Discovered, unsanctioned services · Enterprise control plane · Access plane · Inline enforcement · Out-of-band inspection · Policy and evidence · Exports a customer list from the CRM · Single sign-on to the sanctioned tenant · Session redirected through the broker after sign-on · Unmanaged device, covered without an agent · Upload presented for a verdict before it leaves · Session and download presented for a verdict · Permitted traffic continues to the tenant · Permitted session reaches the tenant · Application stores files and creates sharing links · Activity, file and sharing state read through the API · Findings evaluated against the same policy · Sharing link quarantined two days after the fact · Outbound destinations recorded at the network edge · Logs ingested to build the service catalogue · Service risk rating and usage volume · Newly seen services and who is using them · Every verdict and the signals behind it · Customer list uploaded to a personal account · The same upload from a device with no agent · Refused: customer records to an unsanctioned service

  • Zero trust network access (ZTNA)

    How brokered, application-specific access replaces network-level connectivity, and what an over-broad application definition gives back.

    • Identity and access
    • Intermediate
    • 4 min read
    • Security architects
    • Network engineers
    • Technical leaders
    Indexed terms for this entry (56)

    ZTNA · Contractor · Needs one finance application · Laptop with access agent · Posture reported at connect and during the session · Adversary on the internet · ZTNA broker · Joins two outbound connections into one session · Policy engine · Allow this application, step up, or refuse · Continuous evaluation · Identity and group claims · Device posture and patch state · The application actually requested · Session risk and location change · Time since the last verification · Identity provider · Single sign-on, MFA and risk claims · Security operations · Detection, investigation and policy review · Application connector · Dials outbound, publishes no listener · Finance reporting application · The one application in this grant · Ticketing application · Same subnet, outside this grant · Finance records · Public and untrusted networks · Provider-operated access service · Policy control · Private application network · Enterprise control plane · Network plane · Policy plane · Security plane · Asks for the finance application by name · Outbound session from the agent · Authentication and a second factor · Identity, group and risk claims · Device posture, at connect and while running · This identity, this device, this application · Signals for the next re-evaluation · Verdict for one application and one session · Outbound tunnel raised from the inside · Authorised session handed over · Reaches one application, not the network · Application reads its own records · Session start, duration and re-evaluations · Every verdict and the signals behind it · Connector health and published applications · Scans the perimeter for a service to reach · Stolen credentials replayed at the broker · Compromised session probes the next system · Nothing listens inbound to be found · Refused: unknown device, no posture signal · The grant names one application only

Comparisons 3 entries

Two or more approaches in one shared scene, with the delta marked.

  • SASE compared with SSE

    SSE is the security half of SASE. Where the boundary falls decides whether branch and wide-area connectivity is part of the purchase or still your problem.

    • Cloud and networks
    • Intermediate
    • 3 min read
    • Security architects
    • Network engineers
    • Technical leaders
    Indexed terms for this entry (73)

    DLP · FWAAS · SWG · Remote worker · Working from a shared network · Managed laptop · Agent reports posture and tunnels out · Adversary · Scanning circuits and replaying credentials · Branch site · Staff, printers and local systems · Branch edge device · Per-application path selection · Link health measurement · Overlay tunnel to the service edge · Local breakout, steered by policy · Wide-area orchestrator · Path policy and circuit health · Service edge gateway · Tunnel termination and request admission · Policy engine · Allow, step up, isolate or block · Security service chain · Brokered private application access · Secure web gateway · Cloud application controls · Firewall as a service · Data loss prevention · Identity provider · Sign-on, second factor and risk claims · Security operations · Detection, investigation and tuning · Web destination · Unclassified internet site · SaaS platform · Sanctioned but not enterprise-operated · Private application · No inbound exposure to the internet · Application records · Shared and public networks · Branch site network · Cloud service edge · Policy control · Security services · Public internet · Sanctioned SaaS · Private applications · Enterprise control plane · Network plane · Policy plane · Security plane · Opens an application on the laptop · Agent tunnel to the nearest edge · Site traffic reaches the branch edge · Overlay, steered per application · Path policy for each application class · Loss, latency and jitter per circuit · Sign-on and a second factor · Identity, group and risk claims · Device posture at the time of the request · Request presented for a decision · Verdict and the controls it requires · Permitted web traffic, inspected · Permitted SaaS traffic · Brokered session, no network route · Application reads its own records · Session and admission events · Every verdict and the signals behind it · Inspection and data-handling events · Stolen credential replayed at the edge · Refused: unknown device, no posture signal · Probe against the branch internet circuit · Refused where branch breakout is steered inward

  • SIEM compared with XDR

    A SIEM centralises events from everything and keeps them. XDR goes deeper into one vendor's telemetry and can act on it. Most estates end up running both.

    • Detection and response
    • Intermediate
    • 4 min read
    • Security operations
    • Security architects
    • Auditors and risk
    Indexed terms for this entry (65)

    Adversary · Phished user, then harvested credentials · User workstation · Where the attachment was opened · Server workload · Reached by credential reuse · Endpoint agent · Process, file and network events · Detection logic on the host · Host isolation · Process termination · Network firewall · Connection and block records · Identity provider · Sign-on, second factor and risk events · Third-party SaaS audit log · Administrative trail from another supplier · Legacy business application · Syslog only, and no agent will run on it · Correlation and analytics · Normalise events to one shape · Correlate across sources · Score against detection content · Assemble the case evidence · Triage · Contain, escalate, gather more, or close · Automated response playbook · Vendor-supplied containment actions · Long-term event archive · Normalised events kept for the retention period · Compliance reporting · Control testing and audit evidence · Security analyst · The judgement neither product supplies · External network · Endpoint estate · Network and cloud services · Third-party SaaS · Legacy on-premises systems · Analysis platform · Correlation and triage · Retention and reporting · Security operations centre · Collection plane · Analysis plane · Response plane · Service and authentication events · Host detections and raw events · Sign-on outcomes and risk signals · Administrative trail from a third party · Syslog from a system no sensor covers · Correlated case with its evidence · Escalated for human judgement · Full process ancestry, supplied on demand · Live query pushed to the sensor · Containment selected from the verdict · Isolate the host, with no human step · Containment carried out in another console · Process terminated on the host · Normalised events kept for the full period · Evidence for audit and control testing · Hunting and late-starting investigations · Malicious attachment opened by the user · Credential reuse against a server · Host isolated, so the session is cut

  • ZTNA compared with remote-access VPN

    A VPN grants reachability to a network and then trusts you. ZTNA brokers one application per request and never puts you on the network at all.

    • Identity and access
    • Foundation
    • 4 min read
    • Security architects
    • Network engineers
    • Security operations
    Indexed terms for this entry (62)

    Contractor · Needs the finance application only · Contractor laptop · Unmanaged, posture unknown to the estate · Adversary · Holds a phished credential · VPN concentrator · Listening on the internet, terminates tunnels · ZTNA broker · One decision per request · Session scoped to one application · No route to the private network · Refusals recorded with the reason · Policy engine · Allow this app, step up, or refuse · Application connector · Dials outward; publishes no inbound port · Identity provider · Sign-on, second factor and risk claims · Finance application · The one thing the contractor needs · Payroll database · Shared file server · Unrelated to the engagement · Security operations · Detection, investigation and access review · Remote and unmanaged networks · Published internet edge · Brokered access service · Policy decision · Private network · Finance segment · Shared services segment · Enterprise control plane · Network plane · Policy plane · Security plane · Opens the finance application · Sign-on and a second factor · Identity asserted once, at tunnel setup · Tunnel to the published listener · Reachable once the tunnel is up · Also reachable, and never asked for · Identity and risk claims, per request · Client reaches the broker, not the network · Device posture presented with the request · Each request presented for a decision · Verdict naming a single application · Outbound-initiated, from inside the network · Session delivered to one application · Application reads its own records · Tunnel up, tunnel down, bytes moved · Which user reached which application · Credential phished from the contractor · Listener found by internet-wide scanning · Lateral movement across the routed segment · Stolen credential replayed at the broker · Refused: unknown device, no posture signal · Scan for an inbound port to reach · Nothing listening, so nothing answers · Second application requested on one session · Refused: this session authorises one app

Scenarios 2 entries

A concrete situation, followed decision by decision to the concepts it exercises.

  • A contractor needs one application for six weeks

    A third-party specialist needs access to a single internal console for a fixed engagement. The easy answer is an account, a network route and an offboarding task nobody runs.

    • Identity and access
    • Intermediate
    • 4 min read
    • Security architects
    • Auditors and risk
    • Technical leaders
    Indexed terms for this entry (63)

    CASB · DLP · Build-tooling contractor · Six-week engagement, named sponsor · Contractor's laptop · Unmanaged, owned by her firm · Attacker holding her credentials · Access broker · One named application per grant · Policy engine · Allow, step up, restrict or expire · Session and data controls · Isolated browser session · Data loss prevention · Cloud access security broker · Copy and upload rules · Engagement record · Sponsor, scope and end date · Identity provider · Guest identity with an expiry · Security operations · Evidence for the access review · Remote-access VPN · The route that was not taken · Finance system · Never in scope for this engagement · Build pipeline console · The one application in scope · Build artefacts · Contractor's cloud storage · Her firm's tenant, not inspectable · Contractor's own environment · Access broker service · Grant and policy control · Session inspection · Corporate network · Build tooling estate · Enterprise control plane · Contractor's cloud tenant · Network plane · Policy plane · Security plane · Guest identity and its expiry · Sign-in and a second factor · Starts work on her own laptop · Clientless session to the broker · Request presented for a decision · Device posture: asserted, not measured · Verdict and the controls it requires · Brokered session to one console · Console reads build artefacts · Inspected uploads to her own tenant · The easy answer, an account and a route · Grant expires at the end of day 42 · Session and grant events · Every verdict and the expiry behind it · Inspection and data-handling events · Stolen credentials used on a VPN account · Lateral movement to whatever routing reaches · The same credentials tried at the broker · Artefacts copied out of the session · Refused: expired grant, unknown device · Copy out of the isolated session refused

  • A remote worker opens payroll from untrusted Wi-Fi

    A finance analyst reaches payroll from hotel Wi-Fi on a managed laptop whose endpoint protection is stale. The identity is valid, the device is not, and allow or deny is the wrong pair of answers.

    • Identity and access
    • Foundation
    • 4 min read
    • Security architects
    • Security operations
    • Technical leaders
    Indexed terms for this entry (56)

    CASB · DLP · SWG · Finance analyst · Legitimate payroll entitlement · Managed laptop · Enrolled, signatures four days old · Another guest on the network · Access broker · One application per session · Policy engine · Allow, step up, restrict or block · Inspection and data controls · Data loss prevention · Cloud access security broker · Secure web gateway · Download and upload rules · Identity provider · Sign-in, second factor and step-up · Security operations · Detection, investigation and evidence · Payroll application · Private, with no inbound exposure · Payroll records · Cloud spreadsheet service · Sanctioned, not enterprise-operated · Hotel Wi-Fi · Nearest enforcement point · Access and policy control · Inspection services · Private payroll estate · Sanctioned cloud services · Enterprise control plane · Network plane · Policy plane · Security plane · Opens payroll at 08.42 · Encrypted session to the nearest edge · Sign-in and a second factor · Identity, group and risk claims · Request presented for one decision · Device posture: signatures four days old · Stronger verification required · Step-up challenge satisfied · Verdict: allow the session, refuse the file · Brokered session, no network route · Application reads payroll records · Inspected traffic to a sanctioned service · Session and application events · The verdict and the signals behind it · Inspection and data-handling events · Credential capture on the shared segment · Captured credentials replayed at the edge · Monthly export pulled toward a stale device · Refused: unknown device, no posture signal · Export refused while signatures are stale

Nothing matched? The concept index lists entries by category and difficulty, and the feed carries every new and revised entry.