In this article, I will explain SASE in a diagram. For those who would listen, SASE is going to be our future of network security. Applications have mostly left to the cloud from the data center with few legacy applications and services remaining on premise. Those applications operate in silos, separated from corporate security controls, leaving an absence in policy enforcement. Each application has their own security standards, user credentials, and policies governing their use.
SASE Diagram

SASE stands for Secure Access Service Edge, which is a network architecture that combines network security functions with wide-area networking (WAN) capabilities to support the dynamic, cloud-driven needs of today’s enterprises.
Identity Verification’s Role in SASE
The SASE model incorporates Identity and Access Management (IAM) capabilities to enforce granular access controls based on user identity, device posture, and other contextual factors. This helps ensure that only authorized users and devices can access enterprise resources and applications, regardless of their location.
The Role of Device Posture in SASE (ZTNA)
The role of device security posture is really an element of ZTNA (Zero Trust) in the SASE architecture model. The purpose of device security posture is to ensure that devices meet minimum security standards, all the time. Those standards may include having an EDR solution in place, up to date operating system patches, and device encryption.
SD-WAN in the SASE Diagram
SD-WAN plays an important role in SASE. Its job is to dynamically route traffic across multiple network links based on application requirements, network conditions, and security policies. The dynamic routing capability ensures optimal performance and reliability for accessing both cloud-based and on-premises applications, regardless of the user’s location.
Continuous Verification (ZTNA)
Continuous verification is a component of ZTNA. Once you are connected with legacy security technologies, such as a VPN, MFA, or SSL, verification stops. SASE incorporates ZTNA in its design and says that in order to access a service, you need to continually verify your identity, device posture, and other standards set forth in a security policy.
Secure Web Gateway & Secure DNS in SASE
A Secure Web Gateway (SWG) plays a critical role in a Secure Access Service Edge (SASE) architecture by providing advanced web security capabilities to protect users and devices accessing the internet, regardless of their location. This happens through inspecting and filtering web traffic (content filtering), regardless of SSL/TLS encryption. It also includes DLP components to ensure that sensitive information is not leaving the device. It is typically enforced through a locally installed agent on the end user device.
Cloud Access Security Broker (CASB) in SASE
Cloud Access Security Broker (CASB) plays a crucial role in a Secure Access Service Edge (SASE) architecture by providing comprehensive security controls and visibility for cloud-based applications and services. It provides insight into who is accessing cloud services, from where, on which devices. It has the capability to provide IT with centralized access controls and authentication mechanisms for cloud services, allowing organizations to enforce policies based on user identity. It includes capabilities such as SSO (single sign-on), MFA, and session management.
Data Loss Prevention
Data Loss Prevention (DLP) plays a vital role in a Secure Access Service Edge (SASE) architecture by safeguarding sensitive data as it moves across the network and interacts with cloud-based applications and services. In a SASE architecture, DLP solutions integrate with cloud access security brokers (CASBs) to extend data protection capabilities to cloud-based applications and services. This integration enables DLP policies to be enforced consistently across all cloud environments, regardless of whether the data is accessed from a corporate network or a remote location.
Service Orchestration
Service orchestration in the context of Secure Access Service Edge (SASE) refers to the centralized management and coordination of various networking and security services within the SASE architecture. It involves the automated provisioning, configuration, monitoring, and optimization of network and security functions to ensure consistent and efficient delivery of services across distributed environments.
API Integration
API integration in the context of Secure Access Service Edge (SASE) refers to the seamless communication and interoperability between various networking and security components within the SASE architecture using Application Programming Interfaces (APIs). APIs enable different services and platforms to exchange information, trigger actions, and automate workflows, thereby enhancing the overall functionality, agility, and efficiency of the SASE framework.
API integration enables different networking and security services, such as SD-WAN, CASB, FWaaS, ZTNA, and SWG, to work together cohesively within the SASE architecture. By standardizing communication protocols and data formats, APIs facilitate interoperability between diverse platforms and ensure seamless integration of services across distributed environments.
SASE in 2024 and 2025
SASE is just getting off the ground. In the next few years it will become more and more mainstream and within ten years it will be as commonly known as a traditional firewall is known by the business today. Software vendors will continue to control their applications and their delivery in a SaaS model and users ultimately will be working in a remote or hybrid model. With these two big driving factors, and the continual trend of needing increased cybersecurity due to advanced threats, organizations will need to look to a SASE architecture to protect their data. I hope you found this diagram and the explanations of each role in the SASE model helpful and easy to understand.
Let me know you found this article helpful by posting it to your LinkedIn, or other favorite sharing channels.