Insights on Crypto Payments, Infrastructure, and Operations

Cloud Access Security Broker (CASB)

Abbreviation: CASB

Pronunciation: KLOWD AK-sess sih-KYOOR-uh-tee BROH-kur (C-A-S-B)

Also known as: CASB

Definition

A Cloud Access Security Broker (CASB) is a security control layer that provides visibility and policy enforcement between users, workloads, and cloud services across sanctioned and unsanctioned usage. It differs from Cloud Security Posture Management, which primarily assesses cloud resource configuration and control posture rather than individual access and data activity. Capabilities may include discovery, access control, data protection, malware detection, session monitoring, and policy enforcement, but deployment must account for encryption, APIs, performance, privacy, and coverage gaps.

Overview

A Cloud Access Security Broker (CASB) is a security control layer that provides visibility and policy enforcement between users, workloads, and cloud services across sanctioned and unsanctioned usage. The control exists to discover and reduce security exposure across cloud services, configurations, identities, data, access paths, and externally reachable resources. It differs from Cloud Security Posture Management, which primarily assesses cloud resource configuration and control posture rather than individual access and data activity. It should be interpreted alongside Cloud Security Posture Management (CSPM) because the concepts can affect the same decision without representing the same control, event, or risk.

The workflow collects data through cloud APIs, logs, network observation, repositories, and service integrations, then normalizes resources and assigns ownership. Findings should be prioritized by sensitivity, privilege, reachability, exploitability, business criticality, and compensating controls rather than severity labels alone. In this context, capabilities may include discovery, access control, data protection, malware detection, session monitoring, and policy enforcement, but deployment must account for encryption, APIs, performance, privacy, and coverage gaps.

It should connect the term to Data Loss Prevention (DLP) where that relationship changes access, transaction treatment, investigation, communication, or recovery.

Records should retain resource identifiers, account and region, configuration, identities, data classification, exposure path, detector version, first and last seen dates, owner, exception, remediation, and verification. Coverage gaps and unsupported services should remain visible.

Useful measures include environment coverage, unknown assets, public exposure, excessive privilege, sensitive-data findings, remediation time, drift, recurring misconfiguration, exception age, and verified risk reduction.

The relationship with Adaptive Authentication should be documented where it affects residual risk or control ownership.

Key Takeaway

Capabilities may include discovery, access control, data protection, malware detection, session monitoring, and policy enforcement, but deployment must account for encryption, APIs, performance, privacy, and coverage gaps.

Sources

  1. Cloud Security Glossary — Cloud Security Alliance (2026-08-03)
  2. Cloud Security Posture Management and Related Cloud Security Capabilities — Cloud Security Alliance (2026-08-03)
  3. NIST Cybersecurity Framework 2.0 — NIST (2026-08-03)