Organizations are rapidly adopting cloud services for faster deployment, flexibility, and cost advantages, but cloud usage often sits outside established IT access governance. While on‑premises access is usually controlled, cloud services—including personal “shadow IT” tools and mobile access from outside the network perimeter—create gaps in oversight. These gaps raise compliance and cyber-risk concerns, especially where laws and regulations require control over personal data transmission, processing, and storage, as highlighted by GDPR-driven requirements. Uncontrolled cloud usage can also enable adversaries to steal or corrupt cloud-held data or introduce malware that later infects the organization.
Because traditional governance and security tools were slow to extend full cloud controls, CASBs emerged to detect cloud usage, control access to approved services, protect against threats (including malware and data leakage), and support compliance through regulation-aligned capabilities. KuppingerCole recommends CASBs that combine discovery, policy-based control, cyber protection (potentially including encryption/tokenization despite SaaS functional tradeoffs), and compliance features that are ideally certified or evidenced in real deployments.
Symantec CloudSOC, built from Blue Coat and Elastica technology and integrated with Symantec’s broader portfolio, is positioned as a second-generation CASB delivered as a cloud service. CloudSOC Audit analyzes firewall/proxy logs (optionally anonymized via SpanVA) to identify shadow IT and assess cloud apps using 100+ security attributes plus user behavior analytics. CloudSOC Security for SaaS uses API and gateway controls (“Securlets” and “Gatelets”) to enforce granular policies, classify and protect sensitive data (ContentIQ), monitor activity (StreamIQ), and compute user-centric risk scores (ThreatScore). Integrations extend capabilities through DLP, encryption, tokenization that preserves application behavior, endpoint protection, strong authentication (VIP), and threat protection. Key challenges include complexity across multiple products and the lack of comprehensive access governance reporting across on‑premises and cloud services.
See All Locations
See All Locations