Secure by Design · Controls Assurance

SASE — how ZTNA, Defence in Depth & PAM are fulfilled

Converged Secure Access Service Edge, viewed as a controls map. Pick a lens to focus the components involved, watch how a request is handled, and trace each requirement to the architectural control that satisfies it.

Speed
Access edge SASE cloud PoP Destinations Standard user managed endpoint Privileged user administrator Branch / SD-WAN site tunnel Identity provider · MFA · device posture SAML / OIDC · step-up authentication · compliance signals Policy engine — PDP / PEP identity · device · context · risk → least-privilege entitlement Defence in depth — overlapping inspection planes (single pass) PLANE SASE CONTROL NET Network FWaaS L3–L7 firewall · IPS · geo/IP filtering WEB Web SWG TLS termination · inspection · RBI · URL filter APP Cloud app CASB SaaS visibility · shadow IT · cloud-app control DATA Content DLP content inspection · egress control · data tagging THR Threat Threat Prevention sandbox · threat intel · AV · malware ZTNA broker — per-app, least privilege outbound app connectors · no inbound exposure · no lateral movement Continuous authorisation & telemetry session re-evaluated on risk / posture change · full logging Privileged Access Management — adjacent control, integrated via ZTNA Credential vault no standing creds injection — never seen JIT elevation time-bound access approval + MFA step-up Session broker isolated proxy full recording · audit Internet / web filtered egress SaaS apps M365 · Salesforce Private apps data centre · IaaS Infrastructure servers · databases

Zero Trust Network Access

Hover a requirement to spotlight the control that fulfils it Live highlight follows the animation through the architecture