# What is a Cloud Access Security Broker (CASB)?

> A cloud access security broker (CASB) is an industry category for a security capability placed logically between cloud-service consumers and providers or connected through provider application programming interfaces.

- Canonical URL: https://yellowcube.eu/glossary/cloud-access-security-broker/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It applies organizational policy to supported cloud use, commonly providing visibility, access control, data protection, activity monitoring, threat detection, or combinations of these functions.

Deployment models include forward and reverse proxies, endpoint-assisted traffic steering, API integrations, and log analysis. Inline methods can decide during a session but add a traffic-path dependency. API methods can examine stored data, sharing, and administrative activity without carrying traffic, although coverage and timeliness depend on provider interfaces.

### Key points

- **Policy context:** Relate identity, device condition, application, action, data sensitivity, destination, and sharing state to an explicit business rule.
- **Coverage design:** Inventory sanctioned and unsanctioned services, managed and unmanaged devices, service integrations, mobile applications, and paths that bypass inline controls.
- **Privacy and resilience:** Minimize collected content and activity, protect API credentials and logs, define lawful inspection, and test capacity, outages, bypasses, and failure behavior.
- **Important limitation:** CASB is not a uniform specification and cannot observe every cloud path. Unsupported applications, API delays, limited permissions, encryption, personal accounts, direct integrations, and provider changes create blind spots; a finding does not prove compliance or malicious intent.

### Related terms

[Secure web gateway (SWG)](<https://yellowcube.eu/glossary/secure-web-gateway/>) · [Security service edge (SSE)](<https://yellowcube.eu/glossary/security-service-edge/>) · [Secure access service edge (SASE)](<https://yellowcube.eu/glossary/secure-access-service-edge/>) · [Data loss prevention (DLP)](<https://yellowcube.eu/glossary/data-loss-prevention/>) · [SaaS security](<https://yellowcube.eu/glossary/saas-security/>) · [Shadow IT](<https://yellowcube.eu/glossary/shadow-it/>)

### Sources

[NIST glossary: Cloud Access Security Broker](https://csrc.nist.gov/glossary/term/cloud_access_security_broker) · [NIST SP 800-215: Guide to a Secure Enterprise Network Landscape](https://csrc.nist.gov/pubs/sp/800/215/final) · [CISA Secure Cloud Business Applications Technical Reference Architecture](https://www.cisa.gov/sites/default/files/2023-06/CSSO-SCUBA-TRA-guidance%20documentV2_508c.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

