The reference desk / In practice

SASE

A category combining wide-area networking with cloud-delivered security services.

Secure access service edge

What it means

SASE combines wide-area networking with security services commonly delivered through a distributed cloud edge. The networking portion helps connect users, branches, and applications; the security portion applies controls such as web filtering or access policy. Actual offerings vary in architecture, integration, and supported traffic. The useful question is how a specific design carries and protects your organization’s traffic. SASE does not remove application authorization, endpoint security, or the need to understand dependency and outage behavior. It also does not imply that every traffic path automatically passes through the controls.

AN ILLUSTRATIVE SCENARIO

Connecting retail stores and traveling staff

A retailer wants stores and remote employees to reach cloud applications with consistent policy. Its design selects network paths for branch traffic and applies appropriate security controls to staff access. The team tests what happens when a preferred connection or service location fails. Payment systems and ordinary browsing have different requirements, so the rollout considers segmentation, latency, and operational continuity instead of sending every flow through one unexamined policy.

Put it to work

  1. Map users, locations, applications, and traffic types. Define access, performance, resilience, and logging requirements before comparing product bundles or deployment models.
  2. Pilot identity integration, traffic steering, and policy enforcement on representative devices and sites. Document bypasses, unsupported protocols, and application-specific access controls that remain necessary.
  3. Test failover and outage behavior with network and security owners. Agree how policy changes, troubleshooting, certificates, and incident evidence will be managed across the service.

How to check your work

Trace an approved user’s path to an application from a branch and a remote connection. Confirm expected policy and logs, then test a disallowed action and a controlled failure scenario. Compare actual behavior with the documented design.

Connect the ideas

  • SSE

    Cloud-delivered security services such as secure web access without requiring the networking half of SASE.

  • ZTNA

    Access that brokers application connectivity per identity and policy instead of placing users on a flat network.

  • Trust boundary

    A place where identity, network, or data assumptions change and a fresh check is required.

  • Availability

    The property that authorized people can use a system or record when they need it.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.