The reference desk / In practice

SSE

Cloud-delivered security services such as secure web access without requiring the networking half of SASE.

Security service edge

What it means

SSE groups cloud-delivered security capabilities for accessing web, cloud, and private applications. Common functions include secure web access, cloud application controls, and zero-trust network access. Unlike the broader SASE category, SSE does not require the wide-area networking component to be part of the same offering. Product boundaries still vary. What matters is which traffic and applications receive which controls, how identities are checked, and what evidence operators can retrieve. An SSE service complements the organization’s network design and application permissions rather than making them unnecessary.

AN ILLUSTRATIVE SCENARIO

Protecting a distributed consulting team

A consulting firm has staff working from many locations and wants consistent access policy without replacing its branch-network design. It pilots a security service for web access and selected private applications. Administrators check managed and unmanaged-device behavior, allowed destinations, and the logs available during an investigation. The internal expense application still controls which employee can approve a claim; gaining a permitted network path does not grant that business permission.

Put it to work

  1. Identify the users, devices, applications, and traffic in scope. Specify required web controls, private-application access, data handling, and investigation records separately.
  2. Pilot the actual access paths and identity policies. Document how traffic reaches the service, what can bypass it, and which unsupported clients or protocols need another approach.
  3. Agree policy ownership, exception handling, and outage procedures. Test operational effects before enabling disruptive filtering or encrypted-traffic inspection across the whole organization.

How to check your work

Check a permitted workflow, a prohibited workflow, and a known exception from representative devices. Verify policy decisions and usable logs, then confirm how access behaves during a service interruption or identity-provider failure.

Connect the ideas

  • SASE

    A category combining wide-area networking with cloud-delivered security services.

  • ZTNA

    Access that brokers application connectivity per identity and policy instead of placing users on a flat network.

  • CASB

    A control point for observing or constraining use of cloud services, including unsanctioned ones.

  • Authorization

    The decision about whether a person, device, workload, or anonymous requester may perform a particular action on a resource.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.