The widespread availability of cloud services and the growth of mobile and personal devices have made security and compliance harder for organizations. Employees can use personal cloud tools for work without approval, and business units can procure cloud services without risk assessments, creating “shadow IT” and compliance exposure. Key concerns include where data is stored and processed, the possibility of cloud provider staff accessing customer data, lawful government access to data without customer permission (illustrated by revelations about U.S. government access to Yahoo emails), and the impact of GDPR for organizations holding personal data about people in Europe.
A governance-led approach to cloud usage is required, but it must be supported by technology that provides visibility and enforceable controls. Cloud Access Security Brokers (CASBs) are positioned to deliver these capabilities, especially around detecting cloud service usage, controlling access and data movement, protecting against cyber risks, and supporting compliance with pre-built and ideally certified controls.
CensorNet Unified Security Service (USS) is presented as a multi-functional cloud security platform combining web security, email security, cloud application control, and adaptive multi-factor authentication. Its Cloud Application Control module discovers, monitors, and enforces policies for cloud and on-premises applications via a gateway and optional agents, supporting BYOD and multiple proxy deployment options. It uses a continuously updated cloud application database, baseline risk ratings, and extensive reporting (including 42 preset charts and custom report building). Policy enforcement can be coarse or highly granular, tied to user identity, Active Directory groups, device context, and network conditions, down to specific in-app actions. USS adds layered malware and phishing defenses, HTTPS inspection, and Office 365 controls, plus monitoring and reporting aligned to common compliance needs. Noted gaps include lack of integrated cloud data-at-rest encryption and lack of content-based control over data stored in cloud services.
See All Locations
See All Locations