Cloud Access Security Broker (CASB)
CASBDefinition
A security policy enforcement point positioned between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud-based resources are accessed. CASBs provide visibility into cloud application usage, data security, threat protection, and compliance monitoring across SaaS, PaaS, and IaaS environments. They enforce security policies such as authentication, authorization, credential mapping, encryption, tokenization, logging, alerting, and malware detection.
التعريف بالعربية
نقطة تطبيق سياسة أمنية موضوعة بين مستهلكي الخدمات السحابية ومزودي الخدمات السحابية للجمع بين سياسات أمن المؤسسة وإدراجها عند الوصول إلى الموارد السحابية. توفر وسطاء أمن الوصول السحابي رؤية شاملة لاستخدام التطبيقات السحابية وأمن البيانات والحماية من التهديدات ومراقبة الامتثال عبر بيئات البرمجيات كخدمة والمنصات كخدمة والبنية التحتية كخدمة. وتطبق سياسات أمنية مثل المصادقة والتفويض وتعيين بيانات الاعتماد والتشفير والترميز والتسجيل والتنبيه واكتشاف البرمجيات الخبيثة.
Practical Example
A Saudi financial institution subject to SAMA CSF requirements deploys a CASB solution to monitor all employee access to cloud storage services like Microsoft OneDrive and Google Drive. The CASB enforces data loss prevention policies by scanning uploaded files for sensitive customer information regulated under PDPL, blocking uploads containing unencrypted personal data, and generating compliance reports demonstrating adherence to SAMA CSF Domain 8 (Third Party Service Provider Management) and NCA ECC controls for cloud service oversight.