Cloud Access Security Broker (CASB)
Visibility and control over SaaS/cloud application usage; OAuth application and data flow monitoring (Defender for Cloud Apps).
Loading…
Exfiltrating data
Visibility and control over SaaS/cloud application usage; OAuth application and data flow monitoring (Defender for Cloud Apps).
Data classification and enterprise information rights management (IRM); controls access to sensitive data and prevents unauthorized exfiltration. Foundational to DLP.
DLP controls that detect and block sensitive data from exiting through unauthorized channels.
Encrypting sensitive data at rest and in transit so it cannot be used even if stolen.
Restricting inbound/outbound traffic with default-deny filtering, egress control, and anti-spoofing (uRPF/BCP38).
IDS/IPS that detects and blocks known malicious patterns and anomalies in network traffic, with proper sensor placement.
Narrows egress channels with DNS hardening (protective DNS/RPZ + sinkhole) and web proxy/filtering.