THANK YOU FOR SUBSCRIBING
Network Infrastructure Magazine | Monday, January 03, 2022
Secure Access Secure Edge (SASE) is an evolutionary step for SD-WAN manufacturers in their efforts to improve SD-WAN security in a multi-cloud environment.
FREMONT, CA: SD-WANs are frequently virtualized and make extensive use of the public Internet and a variety of private WAN connections. Secure SD-WAN services have become necessary due to systemic changes in how organizational applications and data are provided and dramatic changes in the workplace. Security management for SD-WAN is a dynamic target and a delicate balancing act.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
As a result, SASE reinvented SD-WAN security by doing away with the physical boundary that has regulated security for centuries, particularly in the enterprise setting. SASE is tackling enterprise security in the context of two significant themes. A long-term trend involves migrating applications and data from the data center to the cloud. That has been the case for more than a decade. According to analysts, more than half of workloads have already been transferred to public clouds. Simultaneously, the workforce was compelled to transition away from the campus or office environment and into a work-from-home (WFH) or work-from-anywhere environment. This has far-reaching consequences.
Covid-19 will accelerate both tendencies in 2020, and the WFH environment, in particular, will present a challenge to enterprise CSOs striving to maintain order and security while not in charge of the network. CIO/CSOs are particularly concerned about home networks, which IT may not easily monitor and reveal a slew of new threats.
SASE is a distributed security architecture designed to meet the challenges inherent in today's cloud-centric environment. Rather than assuming a physical border, SASE prioritizes the security of people and programs over subnetworks and IP resources.
Security services are distributed into the cloud, more precisely at the edge, in the SASE architecture. Users seek access via cloud connections, regardless of their location on the globe. Once access is authorized, the user's identity, role, and context are considered before apps and data can be accessed. If the context changes, the access privileges may also change. These decisions are made regardless of the physical location, network, or other factors.
SASE is predicated on the Zero Trust and Zero Trust Network Access technologies (ZTNA). Zero Trust does away with the concept of trust, requiring that access be granted for each application transaction. In other words, whenever something is accessed, both inside and outside an organization's perimeter, ZTNA dynamically determines whether the user has the necessary privileges, the proper context, their identity is authenticated. They have vetted access to the requested material.
More in News