White Paper | SASE for Superheroes | Check Point Software
White Paper | SASE for Superheroes
SASE for Superheroes
SASE Stands for Secure Access Service Edge
Secure Access Service Edge (SASE) pronounced “sassy,” is a cloud-based network security model proposed by research firm Gartner that combines multiple network security technologies primarily delivered as a service. SASE includes Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Firewall as a Service (FWaaS), SaaS Security, and SD-WAN (software-defined wide area network). SASE changes the way organizations connect and secure their data, resources, and users. It connects an organization’s assets to a single, secure, cloud-based network that provides zero trust access to on-prem and cloud resources. SASE lets companies effortlessly set up and manage networks and create customized, user-focused access policies based on device, role, and other granular attributes. Plus, SASE includes monitoring and logging utilities, total network visibility, and access control from a centralized admin panel.
Why SASE?
The traditional perimeter-based security model is no longer effective thanks to the shift to the cloud and the ever-expanding trend towards remote work that now includes more than 36 million Americans by 2025. Businesses are now struggling with complex, costly, and inefficient security infrastructures ill-equipped to handle the performance and security demands that a modern business requires. Organizations are often grappling with:
- A patchwork of security tools complicating administration and reducing visibility
- Insufficient secure remote access leaving the door open to threat actors
- Performance bottlenecks reducing user experience and productivity
SASE for Superheroes
Moving from Site-Centric to User-Centric Security
The SASE approach to these issues assumes employees are not tied to a specific location. This allows businesses to enforce security policies for both employees in the office and those working remotely. It avoids the performance hits of traditional hardware-based networks, integrates easily with cloud-based and on-prem resources, and creates a more scalable security apparatus that can be rapidly deployed to new departments and employees. There are four primary use cases for SASE:
- Zero Trust remote access, enabling users to securely access internal resources be they on-prem or in the cloud
- Internet security for users accessing websites
- SD-WAN for optimized branch connectivity
- Fast and efficient network connectivity between any user and resource enabled by a global network of points of presence (PoPs)
On-Device Protection
SASE Components:
A unified SASE solution takes standalone services and combines them into a streamlined package:
- Globally Distributed Backbone
- Zero Trust Network Access
- Secure Web Gateway
- Firewall as a Service
- SaaS Security (CASB)
- SD-WAN
Globally Distributed Network
One of the key underpinnings of any SASE approach is a global backbone with a distributed network of high-performance points of presence (PoPs). To be as robust as possible, these PoPs must have multiple Tier-1 providers and peering agreements with major cloud providers to ensure fast network traffic delivery.
Zero Trust Network Access (ZTNA)
ZTNA has become the de facto standard for remote access. The basic principle of ZTNA is that no one should be fully trusted when accessing corporate resources. Instead, every access request must be verified on an application-by-application basis. The verification should consist of either a login with a username and password or verification via a single sign-on provider, plus multi-factor authentication. In addition, the verification should include contextual checks such as confirming the user’s device is complying with company security standards.
Secure Web Gateway (SWG)
The ability to observe web traffic for threats is an essential part of a comprehensive network security posture. SASE solutions provide malware protection with full TLS traffic analysis and real-time threat detection, without the need for expensive hardware. They are able to scan unknown files for zero-day exploits and advanced persistent threats both on and off the network using a variety of methods including traditional signature-based detection, virtual code processing, and heuristic analysis to discover patterns and behaviors of hidden or unknown malware. Web filtering, meanwhile, allows administrators to block users from navigating to specific websites.
The Benefits of SASE
SASE enables the delivery of converged networking and network security services that support digital transformation, workforce mobility, and access management. Key benefits include:
- Complexity and cost reduction
- Network performance improvements
- Ease of use and visibility
- Improved security
- Centralized policy management
Cloud-based SASE offerings update an organization’s ability to defend against new threats and enable them to quickly adopt new security capabilities. In addition, policy controls allow for distributed connection points close to cloud resources and users for better performance, as well as regional networking where needed. As more SASE services are adopted, additional cost reductions will be realized since it simplifies many tools in the security technology stack into a single platform.
Get SASE
Traditional network security architectures typically place enterprise on-prem hardware at the center of IT resources. This ends up creating roadblocks to the dynamic access that hybrid and remote work models require. That’s why SASE platforms are critical for smarter networking and stronger security.