Skip to main content

Command Palette

Search for a command to run...

SASE and SSE: Secure Access in the Modern Enterprise

Updated
•6 min read•View as Markdown
S
I like breaking things that are supposed to be secure. When I’m not hunting vulnerabilities, I’m exploring systems, architectures, and the assumptions behind them.

Modern organizations no longer have a simple network perimeter. Users work remotely, applications run in the cloud, and data is distributed across SaaS, public cloud, private applications, and data centers.

Two important concepts that address this model are SASE and SSE.

CISSP OSG note: SASE is explicitly covered in the CISSP Official Study Guide 10th Edition under Domain 3.1.11 — Secure Access Service Edge. SSE is not covered as a separate concept in the OSG. The SSE section below is added as complementary industry knowledge.

1. What is SASE?

SASE = Secure Access Service Edge

SASE is a framework that combines networking/WAN capabilities with security services, delivered primarily through a cloud-native architecture.

The CISSP OSG describes SASE as a framework combining network security functions with WAN capabilities for modern organizations dealing with cloud adoption, mobile users, and distributed access.

Simple mental model

                    SASE
                     │
          ┌──────────┴──────────┐
          │                     │
      NETWORKING             SECURITY
          │                     │
       WAN/SD-WAN        ZTNA / SWG / CASB
          │                 FWaaS / etc.
          └──────────┬──────────┘
                     │
               Cloud / Edge
                     │
        ┌────────────┼────────────┐
        ▼            ▼            ▼
      Users       Devices     Applications

2. Why SASE?

Traditional security was heavily based on a network perimeter:

User → Corporate Network → Firewall → Application

Modern environments look more like:

Remote User ──┐
Branch ───────┤
Mobile ───────┼──► Cloud / SaaS / Private Apps
IoT ──────────┘

SASE addresses this distributed environment by moving networking and security capabilities closer to users and resources.

The OSG specifically associates SASE with:

  • Cloud adoption

  • Mobile workforce

  • Distributed users

  • Cloud applications

  • Increased need for network security


3. Key SASE characteristics

☁️ Cloud-native

SASE uses a cloud-native architecture to unify network and security services.

Benefits include:

  • Scalability

  • Flexibility

  • Reduced dependence on on-premises hardware


👤 Identity-centric

SASE moves away from relying primarily on network location.

Instead:

Identity of the user/device matters more than where they are connecting from.

Remember:

SASE → Identity > Location


🔐 Zero Trust / ZTNA

SASE uses Zero Trust Network Access (ZTNA) to implement its identity-centric approach.

Core idea:

Never trust by default.

Users and devices must go through:

  1. Authentication

  2. Authorization

  3. MFA, when possible for users

This applies whether the entity is inside or outside the organization's network.


🌎 Edge computing

SASE uses edge computing to bring networking and security closer to users/devices.

This can:

  • Reduce latency

  • Improve performance

  • Improve access to cloud applications


🌐 Globally distributed

SASE emphasizes a globally distributed network so users can receive consistent security and performance regardless of geographic location.


📊 Continuous monitoring

SASE continuously monitors:

  • User behavior

  • Network conditions

This allows adaptive security controls to respond to changing conditions in real time.


☁️ Delivered as a service

SASE is often delivered as a service, allowing organizations to subscribe to required capabilities.

Benefits include:

  • Simplified management

  • Scalability

  • Reduced capital expenditure


4. What is SSE?

SSE = Security Service Edge

SSE is the security-focused portion of the broader SASE model.

It focuses on delivering cloud-based security services for users, devices, applications, and data.

Industry references commonly describe SSE around these core capabilities:

SSE capability Purpose
ZTNA Identity-based secure access to private applications
SWG Secure and control web/Internet access
CASB Secure and control cloud/SaaS usage
FWaaS Cloud-delivered firewall capabilities

Simple model

                 SASE
                  │
        ┌─────────┴─────────┐
        │                   │
    NETWORKING            SSE
        │                   │
     SD-WAN        ┌────────┼────────┐
                   │        │        │
                  ZTNA     SWG      CASB
                            │
                          FWaaS

Important: Exact SSE component lists can vary by vendor; ZTNA, SWG and CASB are commonly identified as the core three, with FWaaS and other capabilities often included.


5. SASE vs SSE

The easiest way to remember it:

SASE = Networking + Security

SSE = Security part of SASE

SASE SSE
Full form Secure Access Service Edge Security Service Edge
Scope Networking + Security Security
Networking ✅ ❌
SD-WAN Typically included ❌
ZTNA ✅ ✅
SWG ✅ ✅
CASB ✅ ✅
FWaaS Often included Often included
Cloud delivered ✅ ✅
Identity-centric ✅ ✅
Zero Trust ✅ ✅

SSE is generally described as a subset of SASE focused on security services, while SASE combines those security services with networking capabilities such as SD-WAN.


6. SASE vs VPN

Traditional VPN:

Remote User
     │
     ▼
VPN Gateway
     │
     ▼
Corporate Network
     │
     ▼
Application

SASE/ZTNA approach:

User / Device
      │
      ▼
Cloud Security Edge
      │
   Identity
   + Context
   + Policy
      │
      ▼
Specific Application

The important conceptual difference is:

VPN → network-level connectivity

ZTNA/SASE → identity- and policy-based access to resources

For CISSP, focus on the security architecture principle, rather than memorizing a vendor-specific product comparison.


7. SASE + SSE + Zero Trust

This is the relationship worth remembering:

                    SASE
                     │
          ┌──────────┴──────────┐
          │                     │
      NETWORKING             SECURITY
          │                     │
       SD-WAN                  SSE
                                │
                    ┌───────────┼───────────┐
                    │           │           │
                   ZTNA        SWG         CASB
                    │
                 Identity
                    │
              Zero Trust

In one sentence:

SASE provides the overall networking + security architecture, while SSE provides the security services and ZTNA applies identity-centric Zero Trust access.


8. CISSP Exam Memory

SASE

Secure Access Service Edge

Remember:

Cloud + Edge + Identity + ZTNA + Networking + Security

SSE

Security Service Edge

Remember:

Security services at the edge

Golden comparison

SASE = NETWORK + SECURITY

SSE  = SECURITY

ZTNA = IDENTITY-BASED ACCESS

CISSP OSG takeaway

The OSG explicitly identifies SASE as a Domain 3.1.11 topic and discusses its cloud-native architecture, identity-centric security, ZTNA, edge computing, global distribution, continuous monitoring, and service-based delivery.

SSE is not a separate OSG topic, so for your CISSP preparation, prioritize SASE. SSE is useful complementary knowledge for understanding how modern SASE security architectures are commonly structured.

Final memory hook

SASE = the whole architecture SSE = the security half ZTNA = identity-based access SD-WAN = networking half

2 views