<img src="//pixel.quantserve.com/pixel/p-_JKXxuL8SR7wu.gif?labels=_fp.event.Default" style="display: none;" border="0" height="1" width="1" alt="Quantcast">

Next-Gen CASB for AWS

Protect S3 and Custom Cloud Apps

Amazon Web Services is the dominant public cloud Infrastructure as a Service (IaaS) provider. While AWS provides some native security & compliance functionality, such as admin transaction logging, there are gaps. The Bitglass Cloud Access Security Broker (CASB) for AWS fills those gaps, providing identity management and SSO, contextual access control, and cross-application user behavior analytics.


Zero-day Security for AWS

Native security controls from application vendors are inadequate for enterprises in regulated industries or those with valuable intellectual property. Bitglass enables you to enforce data security policies on SaaS and IaaS apps in real time, from any device. Moreover, Bitglass provides cross-app visibility, empowering you to discover suspicious and abnormal behavior. If a user accesses an app from LA, and then an hour later tries to access the same app from NYC, Bitglass can flag and prevent that login.
  • Limit risky behavior with customized access control policies. Prevent data leakage by controlling external sharing, and mobile download + sync.

  • Cloud encryption keeps sensitive data shielded from anyone outside your organization.
  • User behavior analytics ensure immediate response to suspicious activities and compromised credentials - across all of your cloud apps.  


Encrypt or Tokenize Stored Data


Among the top concerns for organizations adopting AWS is securing data-at-rest in S3 while making that data accessible to users when needed. Only Bitglass can effectively protect IaaS data lakes.  

  • Protect data in any storage format with full-strength 256-bit AES encryption or tokenization.
  • Define security levels to control which users can decrypt sensitive data.
  • Support for KMIP gives you control over your own encryption keys.

Advanced Threat Protection on any device

Cloud apps enable your users to be productive on any device anywhere, and your security solution needs to match. Bitglass' Next-Gen multi-protocol proxies enable Zero-Day threat protection of your data on any device.
Bitglass’ Advanced Threat Protection (ATP) powered by Cylance, blocks the spread of unknown and zero day attacks. Policies can be enforced in real-time on the proxy for uploads and downloads, or via API for data-at-rest in the cloud.
protect data

Contextual Control of Admin Users


Privileged users with Admin access to AWS require contextual access control to ensure the highest security and compliance. Bitglass integrates AWS with IAM and SSO while enforcing step-up multi-factor authentication and Role-Based-Access-Control that depends on the context.
      • Flexible identity integration options including Active Directory Sync, integration with leading IAM providers like Okta and Ping, or leverage Bitglass’ native identity management system to simplify the picture even further.
      • Step-up MFA for high-risk transactions .
      • Control access privileges depending on user, group, geo, IP, device type and more.
cloud solutions brief image

enable AWS security

Learn more about how Bitglass' cloud security solution can help your organization protect all AWS services.

download now