Secure access service edge (SASE) vendors need to “put data security at the core” of efforts to stay ahead of the market, according to Forcepoint VP Jim Fulton.
Fulton noted most vendors are focused on the access piece of SASE, ensuring that networks and applications are secure from bad actors. But he said the application-centric SASE strategy is essentially “leaving the barn door open,” and more emphasis should be placed on securing data once users are permitted inside the network – especially now that bring-your-own-device (BYOD) and hybrid work have become standard Enterprise practice.
“The role of data security in SASE will continue to grow as organizations realize that it’s not enough to protect how users get to the web, cloud, and private apps,” Fulton told SDxCentral. “Keeping control of what they do with data after they get there is just as important.”
One of Forcepoint’s top goals for the next 12 months is to help businesses understand “how a data-first approach to SASE is about more than just modernizing their security, it’s about enabling people working anywhere to safely get to – and use – business data everywhere, making the organization more productive while reducing IT burdens and costs,” Fulton added.
Should DLP Define the security services edge (SSE) Stack?Fulton maintains that vendors must integrate SSE – the security suite that helps comprise SASE – with real inline data loss prevention (DLP), “not just basic pattern matching,” and advanced threat protection capabilities to give IT teams better control over how employees access and use data.
Gartner defines DLP as a set of technologies and inspection techniques used to classify information content contained within an object – such as a file, email, Packet, Application, or data – while at rest (in storage), in use (during an operation), or in transit (across a network)
While Gartner established the SSE portfolio as including zero-trust network access (ZTNA), Cloud Access Security Broker, firewall as-a-service (FWaaS), and secure web gateway (SWG), Fulton said DLP should be another SSE requisite.
“Anything that doesn't have data security technologies at its core misses the whole point,” he explained. “You not only can ensure that people get to websites, get to cloud apps, get to internal safely, but that the data stays safe even if they use it in the cloud or if they download it onto a laptop, that the organization can still retain control.”
Comments