+ All Categories
Home > Technology > CASBs: Real-world use cases

CASBs: Real-world use cases

Date post: 18-Feb-2017
Category:
Upload: bitglass
View: 294 times
Download: 1 times
Share this document with a friend
17
STORYBOARDS Cloud Access Security Brokers Real-World Use Cases Rich Campagna VP, Products Bitglass Salim Hafid Marketing Manager Bitglass
Transcript
Page 1: CASBs: Real-world use cases

STORYBOARDS

Cloud Access Security BrokersReal-World Use Cases

Rich CampagnaVP, ProductsBitglass

Salim HafidMarketing ManagerBitglass

Page 2: CASBs: Real-world use cases

STORYBOARDS

Enterprise Needs

Visibility and audit

Restrict data on unmanaged devices

Prevent hacked accounts

Prevent data leakage & control access

Page 3: CASBs: Real-world use cases

STORYBOARDS

First Attempt - Infrastructure “Lockdown”

Firewall DLP

Web Proxy

VPN

HQ & Branch Office

Starbucks

ApartmentVPN

MDM

+many more...

Page 4: CASBs: Real-world use cases

STORYBOARDS

Components

Usage/Consumption

Data

Application

Services

Servers & Storage

Network

Area

Data

Application

Infrastructure

Owner

Enterprise

Second Attempt - Rely on Cloud App Vendors

Page 5: CASBs: Real-world use cases

STORYBOARDS

Solution?

Cloud Access Security Brokers (CASBs)

Page 6: CASBs: Real-world use cases

STORYBOARDS

Use Cases

1. Discover unknown cloud apps and exfiltration 2. Visibility and user behavior analytics 3. Contextual access control4. Data leakage prevention5. Mobile data protection

Page 7: CASBs: Real-world use cases

STORYBOARDS

CASB Architecture Options

1. Managed Devices Forward Proxy ActiveSync Proxy Device ProfilerSAML Proxy

+ SSO

2. Unmanaged Devices Reverse Proxy + AJAX VM ActiveSync Proxy No agents/No cert install Any device

Rev. Proxy

Fwd. Proxy

3. Data at Rest API Visibility & Control

+many more...

Page 8: CASBs: Real-world use cases

STORYBOARDS

Total Data ProtectionCl

oud

On-

Prem

ise

Managed BYOD

Cloud

Network

Access

Device

Page 9: CASBs: Real-world use cases

STORYBOARDS

Typical CASB Policy

Managed device

Application Access Access Control Data Protection

BYOD

In the Cloud

Forward ProxyActiveSync Proxy

Device Profile: Pass● Email● Browser● Thick clients

● Full Access

Reverse Proxy + AJAX VMActiveSync Proxy

● DLP/DRM/encryption ● Device controls

API Control External Sharing Blocked ● Block external shares● Alert on DLP events

Device Profile: Fail● Mobile Email● Browser

Page 10: CASBs: Real-world use cases

STORYBOARDS

Bay Cove Human Services - Google Apps + HIPAA

2500 Employees

HIPAA Compliance with GApps and BYOD● Google cost effective for non-profits, enhances productivity

● Challenges: Protect PHI, remain HIPAA compliant, keep costs low

● Key features: Data leakage prevention, visibility, integrated identity management, mobile data protection

Page 11: CASBs: Real-world use cases

STORYBOARDS

UNC Charlotte - Dropbox

Controlling External Sharing● Moved to Dropbox to centralize Faculty file storage/sharing,

including sensitive research data

● Challenges: External sharing, Unmanaged device access

● Key features: Contextual access control, encryption, watermarking, DRM

26,000 Students3,000 Employees

Page 12: CASBs: Real-world use cases

STORYBOARDS

Ad Agency - O365 OneDrive

Protect unreleased creative files in OneDrive● Global clients demanded protection

● Challenges: Prevent data leakage

● Key features: External file sharing visibility/control, restricted access from unmanaged devices, Integrated identity/SSO

200 EmployeesGlobal clients

Page 13: CASBs: Real-world use cases

STORYBOARDS

Financial Services - Salesforce Encryption

Full strength encryption of PII● First-gen cloud encryption gateway weakened encryption; brittle

proxy technology

● Challenges: Maintain Salesforce functionality, encrypt data, extend risk-appropriate access

● Key features: Encryption with KMS Integration, visibility, access control

100k+ Employees

Page 14: CASBs: Real-world use cases

STORYBOARDS

The Bitglass Mission:Total data protection outside the firewall

$35M investment Est. Jan. 2013 CA, NY, MA, IL, NC

Page 15: CASBs: Real-world use cases

STORYBOARDS

Bitglass: The Only Complete CASB Solution

Data Exfiltration

Integrated Identity & SSO

Mobile SecurityActiveSync Proxy

Access Control: Data-at-restAPI integration

Data Protection Watermarking, Encryption,

DLP, DRM

Access ControlForward Proxy

Reverse Proxy + AJAX-VM

Cloud Encryption

ShadowIT

Access Control SAML Proxy

Out-of-Band

Inband

Page 17: CASBs: Real-world use cases

STORYBOARDS

Total Data ProtectionBeyond the Firewall

Rich CampagnaVP ProductsBitglass

[email protected]@RichCampagna

Salim HafidMarketing ManagerBitglass

[email protected]@SalimHafid


Recommended