Moving business-critical networking and security capabilities to a vendor-delivered service requires a significant amount of trust and introspection, secure access service edge (SASE) provider Cato Networks said.
“SASE may no longer be the new kid on the block, but like any project, you should do ample planning and prepare a business case,” Cato explained in its guide on how to adopt SASE – the Gartner-coined term for a cloud-native convergence of networking and security.
Evin Safdia, director of product marketing at Cato, told SDxCentral SASE is designed to bring "cohesive security capabilities to organizations while reducing complexity." Time-consuming tasks that required specialized product skills are now simplified as part of the service, including signature and firmware updates, threat-hunting, and site deployment.
"The configurations and policies that took months to architect, deploy, and evaluate can now be accomplished in just days," Safdia added.
Proper SASE preparation requires enterprises to consider what their end goals and use cases are, such as appliance elimination, migration from MPLS to SD-WAN, secure remote access or branch internet access, or multi- and hybrid-cloud use.
Gartner predicts that by 2025, 80% of enterprises will have adopted a strategy to unify web, cloud services, and private application access using a SASE architecture, up from 20% in 2021.
SASE can be adopted over time, allowing enterprises to phase out hardware appliances and MPLS circuits when ready. Still, organizations should implement thoughtful planning, taking into consideration any obstacles that might impact their adoption timeline – from major holidays to budgets and technical staff availability – to "ensure maximum ROI," Safdia said.
Eliminating Siloes for SASE AdoptionSafdia said to some extent, "networking and security have always overlapped, and there should be strong communication and teamwork between the two teams."
"SASE provides a complete framework for networking and security that makes it possible for fast correlation of networking and security events," he added.
When it comes to adopting a solution that explicitly overlaps the two domains (such as SASE), both teams should work together to establish the criteria by which they are evaluating potential solutions, keeping a "regular meeting cadence moving forward."
"We have seen that many organizations have these teams operating in silos," Safida said. "Like any relationship, fostering openness and transparency is key,"
SASE Vendor SelectionCato suggests preparing a request for information (RFI) or request for proposal (RFP) to begin evaluation of vendors based on capability and cost. Questions to ask when evaluating any vendor should surround their product architecture, service level agreements (SLAs), networking, connectivity, security capabilities, and support services.
Additionally, “global points of presence matter” when building out a SASE architecture, Cato said. Ideally, PoPs should be as close to users as possible, so enterprises need to evaluate the locations of their offices and users in order to identify which prospective SASE vendors have the most “usable” PoPs.
“Keep in mind that not all vendors have all capabilities available at every PoP, so you should do some extra due diligence in this area,” the provider noted.
Based on the adoption plan, budget, and RFI/RFP responses, undertaking proof of concepts (PoC) also helps to better evaluate each vendor candidate’s SASE solution within the context of an organization’s specific drivers and needs.
Don't Skip SecurityMuch of the focus surrounding SASE adoption has been pulled toward network access components — like a global private backbone, full mesh connectivity, and optimization – with security elements often taking the back seat.
Underscoring this trend, more SD-WAN vendors have adopted security stacks to build out SASE solutions while fewer pure-play security vendors have acquired networking stacks to deliver SASE, Gartner told SDxCentral.
But Cato warned organizations not to forget that security performance is “critical” to any SASE offering. “Capabilities across vendors can vary greatly and skipping this step can lead to the need for additional investment or increased complexity by filling gaps with point products,” the provider said.
Even if users and branch locations do not connect to private data center resources, SaaS and internet applications are likely essential, according to Cato — and the public internet is “not always predictable.”
The SASE Security ToolboxCato suggests that at a minimum, vendors should offer a firewall rather than a proxy, secure web gateway (SWG), and basic anti-malware capabilities once users are admitted to the network. The company also agrees with Gartner that cloud access security broker (CASB) and zero-trust network access (ZTNA) are the remaining fundamental capabilities within a SASE security suite.
Data loss prevention (DLP), intrusion prevention system (IPS), and zero-day/polymorphic threat prevention are other capabilities Cato says can improve security posture.
Safdia said typically a converged SASE solution provides "better performance and superior security outcomes." That said, he noted "the only time separate solutions are preferable is when an organization has budget constraints and an existing investment in either SSE or SD-WAN."
"The end goal, however, should be a complete offering as this is the only way to really leverage all the advantages of SASE," Safdia added.
Comments