SASE
SASE (Secure Access Service Edge) combines network and security functions into a single, cloud-delivered service.
Secure Access Service Edge (SASE) combines network and security functions in a single cloud service. Sites and mobile employees use it to connect securely to the internet, cloud and internal applications.
How it works
Previously, traffic ran through the central data centre and its firewall. This model is a poor fit for cloud applications and remote work. SASE shifts security functions to the provider's cloud. These include ZTNA for internal applications, a Secure Web Gateway, a Cloud Access Security Broker and a Firewall as a Service. Each connection is inspected at the user's current location.
For example, a company with twelve sites replaces its VPN and branch firewalls with SASE. Employees working from home are subject to the same rules as in the office. Access to internal applications uses ZTNA, removing the need for broad VPN access.
What to look out for
- Plan the migration in stages, usually starting with remote access.
- Check where providers operate their nodes and where data is processed.
- Clarify how you can access the logs. Without them, the SOC lacks an important source.
- Pay attention to resilience. If the service fails, access for everyone is affected.
Switzerland and regulation
With SASE, all traffic flows through the provider. Under the revFADP (revised Federal Act on Data Protection), you must clarify where data is processed and if adequate data protection exists. Banks and securities firms must also review the outsourcing against the requirements of FINMA (Swiss Financial Market Supervisory Authority).
Typical mistakes
SASE is often introduced purely as a replacement for the VPN. Its other functions remain unused or are poorly configured. A second mistake is failing to integrate logs into the SOC. Then, no one sees when an account suddenly accesses many applications.
How we implement it
We integrate logs from your SASE solution into the SOC, correlating them with identities and endpoints. We are happy to discuss architecture questions as part of our Security Consulting.