CISSP GLOSSARY · RISK MANAGEMENT & GOVERNANCE
Cloud Access Security Broker (CASB)
A policy enforcement point between users and cloud services that delivers visibility, compliance, data security, and threat protection, including discovery of shadow IT.
A Cloud Access Security Broker (CASB) is a policy enforcement point that sits between users and the cloud services they consume, extending the organisation’s security policy into applications it does not host. A CASB can work through the cloud provider’s APIs, as a forward proxy on managed devices, or as a reverse proxy in front of sanctioned applications, and it enforces controls such as encryption, access rules, and data loss prevention on cloud traffic.
CASBs are defined by four pillars: visibility (who is using which cloud services), compliance (whether that use meets regulatory obligations), data security (applying data classification aware controls to data in the cloud), and threat protection (spotting compromised accounts and malicious use). The signature capability is shadow IT discovery: revealing the unsanctioned services staff have adopted, which no on-premises control ever sees.
Exam relevance: if a scenario mentions employees using unsanctioned cloud applications, discovering shadow IT, or extending policy into SaaS, the answer is CASB. The nearest confusable is DLP itself: DLP is the content-inspection technology, while a CASB is the enforcement point that can apply DLP (and much else) specifically to cloud usage. If the question asks where policy is enforced for cloud services, choose the CASB; if it asks how sensitive content is recognised, choose DLP.