Saltar al contenido
05 · Arquitectura05 · Architecture

SASE / SSESASE / SSE

Acceso seguro convergente para usuarios remotos y sucursales.Converged secure access for remote users and branch offices.

SASE · SSE · ZTNASASE · SSE · ZTNA Diseño y despliegue de tecnología de seguridadDesign and deployment of security technology

¿Qué es este servicio?What is this service?

Es el diseño y la implementación de una arquitectura donde la seguridad del acceso vive en la nube y no en el perímetro de la oficina. Conviene aclarar la diferencia: SSE es el componente de seguridad —pasarela web segura, CASB, acceso privado sin VPN y prevención de fuga—, mientras que SASE es SSE más la parte de red, es decir el transporte gestionado que conecta sucursales y usuarios.

The design and implementation of an architecture where access security lives in the cloud rather than at the office perimeter. The distinction is worth stating: SSE is the security component — secure web gateway, CASB, private access without VPN and data loss prevention — while SASE is SSE plus the networking side, meaning the managed transport connecting branches and users.

¿Para qué se usa?What is it used for?

El modelo de traer todo el tráfico de vuelta a la oficina para inspeccionarlo dejó de tener sentido cuando las aplicaciones se fueron a la nube y la gente dejó de sentarse en la oficina. El usuario remoto que va directo a una aplicación SaaS no atraviesa ningún control de la organización. Esta arquitectura mueve el control adonde está el usuario, sin obligarlo a rodear medio país por una VPN.

The model of hauling all traffic back to the office for inspection stopped making sense once applications moved to the cloud and people stopped sitting in the office. A remote user going straight to a SaaS application passes through none of the controls of the organisation. This architecture moves the control to where the user is, without forcing a detour across the country through a VPN.

Qué beneficios traeBenefits it delivers

  • Aplica la misma política de seguridad al usuario esté en la oficina, en la casa o en un aeropuerto.
  • El acceso privado por identidad reemplaza a la VPN tradicional, que da acceso a la red entera cuando solo hacía falta una aplicación.
  • Suele mejorar el rendimiento percibido, porque el tráfico deja de dar la vuelta por el centro de datos.
  • Consolida varias herramientas sueltas en una sola consola, lo que baja el costo operativo aunque no siempre el de licencia.
  • It applies the same security policy whether the user is in the office, at home or in an airport.
  • Identity-based private access replaces the traditional VPN, which grants the whole network when only one application was needed.
  • Perceived performance usually improves, because traffic stops detouring through the data centre.
  • It consolidates several separate tools into one console, lowering operating cost even if not always licence cost.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No es obligatorio en Costa Rica.
  • El Acuerdo CONASSIF 5-24 espera control sobre los accesos remotos y sobre los servicios en nube de las entidades supervisadas, y añadió una tabla de nube al perfil tecnológico donde ese uso queda declarado.
  • It is not mandatory in Costa Rica.
  • CONASSIF Agreement 5-24 expects control over remote access and cloud services in supervised entities, and added a cloud table to the technology profile where that usage is declared.

InternacionalInternational

  • Ningún marco exige SASE ni SSE por nombre: son categorías de mercado, no requisitos normativos.
  • ISO 27001 exige controlar el acceso remoto y el uso de servicios de red.
  • PCI-DSS exige que los accesos remotos al entorno de datos de tarjeta usen doble factor y estén restringidos.
  • No framework requires SASE or SSE by name: they are market categories, not regulatory requirements.
  • ISO 27001 requires controlling remote access and the use of network services.
  • PCI-DSS requires remote access to the cardholder data environment to use multi-factor and be restricted.

Requisitos mínimosMinimum requirements

  • Un directorio de identidad único y ordenado. Toda esta arquitectura se apoya en la identidad: si el directorio está sucio, la política será igual de sucia.
  • Un inventario de aplicaciones internas con quién debe acceder a cada una, que es el trabajo real del proyecto.
  • Capacidad de desplegar el agente en los equipos de los usuarios.
  • Enlaces de internet con ancho de banda suficiente en cada sede, porque el tráfico deja de concentrarse en el centro de datos.
  • A single, tidy identity directory. This whole architecture rests on identity: a messy directory produces an equally messy policy.
  • An inventory of internal applications with who should reach each one, which is the real work of the project.
  • The ability to deploy the agent on user devices.
  • Internet links with enough bandwidth at each site, since traffic stops concentrating in the data centre.

Plazo típico de entregaTypical delivery time

10 a 20 semanas 10 to 20 weeks rango habitual del mercado usual market range

El rango habitual va de diez a veinte semanas para el diseño y el despliegue por fases. Cae en el extremo bajo si solo se implanta el componente de seguridad para usuarios remotos. Sube al alto cuando hay sucursales con circuitos que migrar, aplicaciones internas heredadas que no toleran bien el acceso por identidad y un directorio que hay que limpiar antes de empezar.

The usual range runs from ten to twenty weeks for design and phased rollout. It lands at the low end when only the security component for remote users goes in. It rises towards the high end with branch circuits to migrate, legacy internal applications that tolerate identity-based access poorly, and a directory needing a clean-up first.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

SSESSE
El bloque de seguridad entregado desde la nube: filtrado web, control de aplicaciones en nube, acceso privado y prevención de fuga de datos. The security block delivered from the cloud: web filtering, cloud application control, private access and data loss prevention.
SASESASE
Todo lo anterior más la capa de red gestionada. La diferencia con SSE es justamente esa parte de red. All of the above plus the managed network layer. The difference from SSE is precisely that networking part.
ZTNAZTNA
Acceso a una aplicación concreta verificando identidad y estado del equipo, en lugar de entregar la red completa como hace una VPN. Access to a specific application after verifying identity and device state, instead of handing over the whole network as a VPN does.
SWGSWG
Pasarela que inspecciona la navegación del usuario y bloquea lo que la política no permite. A gateway inspecting user browsing and blocking whatever the policy does not allow.
PoPPoP
Los puntos de presencia del proveedor por los que sale el tráfico de la organización. Cuanto más cerca estén, menor es la latencia percibida. The provider points of presence through which the traffic of the organisation exits. The closer they are, the lower the perceived latency.