SASE
acronymnetworkingsecuritycloud
Stands for: Secure Access Service Edge
Gartner's 2019 model that converges the WAN and its security stack into a single cloud-delivered service at the edge, as close to the user as possible.
Coined by Gartner analysts Neil MacDonald, Lawrence Orans, and Joe Skorupa in 'The Future of Network Security Is in the Cloud' (August 30, 2019) and pronounced 'sassy', SASE bundles SD-WAN with secure web gateway, CASB, zero trust network access, and firewall as a service, delivered from distributed points of presence and driven by identity rather than by the address of a data center. The pitch: stop backhauling a remote workforce through headquarters appliances and put both the network path and its inspection where the users and the SaaS already are. The term reorganized the vendor market within two years, and in 2021 Gartner carved out the security half under its own name, SSE, for buyers who wanted the protection without coupling it to the SD-WAN decision.
SASE is the argument that networking and security should be bought and operated as one cloud-delivered service rather than as separate stacks. The reasoning is sound: if users are everywhere and applications are in someone else's data centre, the old model of backhauling traffic to a building to inspect it protects a perimeter that no longer contains anything.
In practice it is the network half, software-defined WAN, plus the security half, which is SSE. Where vendors differ is which half they came from, and it shows: networking vendors bolt security onto a WAN product, security vendors bolt connectivity onto an inspection cloud, and the seams are visible in whichever half was added second.
Two cautions belong with the enthusiasm. Single-vendor SASE gives you one policy model and one support relationship, and it also gives you a dependency whose outage is your outage and whose coverage is your ceiling. And the term is marketing before it is architecture, drawn differently by every vendor, so an evaluation should ask which specific controls run where and how policy is expressed, not which acronym appears on the datasheet.