A healthcare provider is adopting a multi-tenant Software as a Service (SaaS) application to manage patient records across several remote clinics. The security architect must ensure that sensitive patient data transmitted to and from the SaaS application is monitored for policy violations, encrypted in transit, and protected against unauthorized data exfiltration without modifying the underlying cloud provider infrastructure. Which of the following solutions should the security team implement to meet these governance and control requirements?
- Cloud Access Security Broker (CASB)Cevap
- BVirtual Private Network (VPN) Concentrator
- CHypervisor-level virtual firewall
- DHost-based Intrusion Prevention System (HIPS) on the cloud provider's hosting servers
Cevap
Cloud Access Security Broker (CASB)
A Cloud Access Security Broker (CASB) is specifically designed to sit between users and cloud service providers to extend on-premises security controls into cloud environments. In a SaaS model, customers cannot manage underlying cloud servers, hypervisors, or infrastructure controls. A CASB enables organizations to implement single sign-on, access control, data loss prevention (DLP), and threat detection for SaaS usage across clinics.
Adım Adım Çözüm
Anahtar Kavram
Cloud Access Security Broker (CASB) integration in SaaS governance