SASE and SSE: Secure Access in the Modern Enterprise
Modern organizations no longer have a simple network perimeter. Users work remotely, applications run in the cloud, and data is distributed across SaaS, public cloud, private applications, and data centers.
Two important concepts that address this model are SASE and SSE.
CISSP OSG note: SASE is explicitly covered in the CISSP Official Study Guide 10th Edition under Domain 3.1.11 — Secure Access Service Edge. SSE is not covered as a separate concept in the OSG. The SSE section below is added as complementary industry knowledge.
1. What is SASE?
SASE = Secure Access Service Edge
SASE is a framework that combines networking/WAN capabilities with security services, delivered primarily through a cloud-native architecture.
The CISSP OSG describes SASE as a framework combining network security functions with WAN capabilities for modern organizations dealing with cloud adoption, mobile users, and distributed access.
Simple mental model
SASE
│
┌──────────┴──────────┐
│ │
NETWORKING SECURITY
│ │
WAN/SD-WAN ZTNA / SWG / CASB
│ FWaaS / etc.
└──────────┬──────────┘
│
Cloud / Edge
│
┌────────────┼────────────┐
▼ ▼ ▼
Users Devices Applications
2. Why SASE?
Traditional security was heavily based on a network perimeter:
User → Corporate Network → Firewall → Application
Modern environments look more like:
Remote User ──┐
Branch ───────┤
Mobile ───────┼──► Cloud / SaaS / Private Apps
IoT ──────────┘
SASE addresses this distributed environment by moving networking and security capabilities closer to users and resources.
The OSG specifically associates SASE with:
Cloud adoption
Mobile workforce
Distributed users
Cloud applications
Increased need for network security
3. Key SASE characteristics
☁️ Cloud-native
SASE uses a cloud-native architecture to unify network and security services.
Benefits include:
Scalability
Flexibility
Reduced dependence on on-premises hardware
👤 Identity-centric
SASE moves away from relying primarily on network location.
Instead:
Identity of the user/device matters more than where they are connecting from.
Remember:
SASE → Identity > Location
🔐 Zero Trust / ZTNA
SASE uses Zero Trust Network Access (ZTNA) to implement its identity-centric approach.
Core idea:
Never trust by default.
Users and devices must go through:
Authentication
Authorization
MFA, when possible for users
This applies whether the entity is inside or outside the organization's network.
🌎 Edge computing
SASE uses edge computing to bring networking and security closer to users/devices.
This can:
Reduce latency
Improve performance
Improve access to cloud applications
🌐 Globally distributed
SASE emphasizes a globally distributed network so users can receive consistent security and performance regardless of geographic location.
📊 Continuous monitoring
SASE continuously monitors:
User behavior
Network conditions
This allows adaptive security controls to respond to changing conditions in real time.
☁️ Delivered as a service
SASE is often delivered as a service, allowing organizations to subscribe to required capabilities.
Benefits include:
Simplified management
Scalability
Reduced capital expenditure
4. What is SSE?
SSE = Security Service Edge
SSE is the security-focused portion of the broader SASE model.
It focuses on delivering cloud-based security services for users, devices, applications, and data.
Industry references commonly describe SSE around these core capabilities:
| SSE capability | Purpose |
|---|---|
| ZTNA | Identity-based secure access to private applications |
| SWG | Secure and control web/Internet access |
| CASB | Secure and control cloud/SaaS usage |
| FWaaS | Cloud-delivered firewall capabilities |
Simple model
SASE
│
┌─────────┴─────────┐
│ │
NETWORKING SSE
│ │
SD-WAN ┌────────┼────────┐
│ │ │
ZTNA SWG CASB
│
FWaaS
Important: Exact SSE component lists can vary by vendor; ZTNA, SWG and CASB are commonly identified as the core three, with FWaaS and other capabilities often included.
5. SASE vs SSE
The easiest way to remember it:
SASE = Networking + Security
SSE = Security part of SASE
| SASE | SSE | |
|---|---|---|
| Full form | Secure Access Service Edge | Security Service Edge |
| Scope | Networking + Security | Security |
| Networking | ✅ | ❌ |
| SD-WAN | Typically included | ❌ |
| ZTNA | ✅ | ✅ |
| SWG | ✅ | ✅ |
| CASB | ✅ | ✅ |
| FWaaS | Often included | Often included |
| Cloud delivered | ✅ | ✅ |
| Identity-centric | ✅ | ✅ |
| Zero Trust | ✅ | ✅ |
SSE is generally described as a subset of SASE focused on security services, while SASE combines those security services with networking capabilities such as SD-WAN.
6. SASE vs VPN
Traditional VPN:
Remote User
│
▼
VPN Gateway
│
▼
Corporate Network
│
▼
Application
SASE/ZTNA approach:
User / Device
│
▼
Cloud Security Edge
│
Identity
+ Context
+ Policy
│
▼
Specific Application
The important conceptual difference is:
VPN → network-level connectivity
ZTNA/SASE → identity- and policy-based access to resources
For CISSP, focus on the security architecture principle, rather than memorizing a vendor-specific product comparison.
7. SASE + SSE + Zero Trust
This is the relationship worth remembering:
SASE
│
┌──────────┴──────────┐
│ │
NETWORKING SECURITY
│ │
SD-WAN SSE
│
┌───────────┼───────────┐
│ │ │
ZTNA SWG CASB
│
Identity
│
Zero Trust
In one sentence:
SASE provides the overall networking + security architecture, while SSE provides the security services and ZTNA applies identity-centric Zero Trust access.
8. CISSP Exam Memory
SASE
Secure Access Service Edge
Remember:
Cloud + Edge + Identity + ZTNA + Networking + Security
SSE
Security Service Edge
Remember:
Security services at the edge
Golden comparison
SASE = NETWORK + SECURITY
SSE = SECURITY
ZTNA = IDENTITY-BASED ACCESS
CISSP OSG takeaway
The OSG explicitly identifies SASE as a Domain 3.1.11 topic and discusses its cloud-native architecture, identity-centric security, ZTNA, edge computing, global distribution, continuous monitoring, and service-based delivery.
SSE is not a separate OSG topic, so for your CISSP preparation, prioritize SASE. SSE is useful complementary knowledge for understanding how modern SASE security architectures are commonly structured.
Final memory hook
SASE = the whole architecture SSE = the security half ZTNA = identity-based access SD-WAN = networking half

