What is Cloud Access Security Broker (CASB)?
A Cloud Access Security Broker is a policy enforcement point that mediates use of cloud services. It can work inline through a proxy or out of band through cloud APIs and logs. Typical controls include cloud-use discovery, access policy, data protection, and threat detection. CASB is one control within SSE or SASE. It is not always a physical broker in every traffic path.
Why it matters
Users can reach many cloud services outside a traditional network perimeter. A CASB can give an organization common visibility and policy across those services.
How it works
- The CASB observes cloud use through an inline proxy, service APIs, logs, or a combination of these methods.
- It relates the activity to user, device, service, and data context.
- It applies supported access, data, or threat controls and records the result.
Example
A CASB detects an upload of a sensitive file to an unsanctioned cloud storage tenant and blocks the upload on an inline path.
Pomerium boundary
Pomerium can protect a selected cloud service route with identity-aware and context-aware policy. It does not provide every CASB function, such as broad cloud-use discovery, API-mode remediation, or data classification.
Limits and non-claims
- Visibility and enforcement vary by deployment mode and by each cloud service API.
- TLS inspection can add performance, privacy, certificate, and application-compatibility concerns.
- A CASB cannot correct every permission, data-governance, or workload-security defect inside a cloud service.
Evaluation checklist
- Which inline, API, or log path lets the broker observe each cloud action and data object?
- Does the broker know the user, tenant, resource, action, and application permission involved?
- Can unmanaged clients, direct service access, encryption, or an unsupported API bypass inspection?
