Cloud-Delivered Security For The Digital Workspace
Cloud-Delivered Security For The Digital Workspace
With the adoption of hybrid cloud and the rise in comprehensive, cloud-delivered security services
remote work, traditional connectivity models like for direct internet access. It includes Secure Web
VPN and MPLS are no longer meeting performance Gateway, Firewall-as-a-Service, and Cloud Access
and security requirements. Distributed employees Security Brokers, Data Loss Prevention, and Sandboxing
need reliable access to their apps, yet disparate functionality. Globally distributed across 100+ points
networking and security infrastructure makes it of presence (PoP), with each PoP consistently offering
hard for IT to meet expectations. all services, SIA protects employees with a full security
stack, regardless of their location. The service includes:
Traditionally MPLS has been the primary mode of
connectivity for the data-centric model because Secure Web Gateways (SWG) are enterprise security
it provides predictable performance. However, solutions intended to protect users from web-based
MPLS can be expensive especially if you have cyber threats. They provide the following capabilities:
idle backup links. Adopting direct internet access
• URL filtering – Allows or blocks website access by
(DIA) allows users to connect faster to cloud
comparing requested URLs with a filtering database
applications, but also requires edge computing
that’s defined per organizational policy.
services, local access points, and centralized policy
• Anti-malware protection – Inspects encrypted and
management for this new access paradigm. To
unencrypted web content to identify and block all
become more agile, businesses need a new, more
threats.
modern architecture that simplifies complexity,
• Application control – Offers visibility into applications
mitigates security threats, and delivers a better
being accessed and allows granular control to ensure
user experience.
security and compliance.
Converging Network and Security for a Consistent McKinsey states, “Agility has the
Workspace Experience: Bringing networking and potential to improve the customer
security together at the edge gives businesses the
experience by up to 30 percent
opportunity to simplify their workspace delivery. As a
result, a new trend has emerged that brings SD-WAN and can lead to a potential 20 to 30
and security together as a unified cloud-delivered percent improvement in employee
solution. The secure access service edge (SASE)
engagement.1”
architecture converges comprehensive networking and
cloud-delivered security capabilities, in a single-pass
architecture with unified management, to: Introducing the Citrix Secure Access
• Make IT operations more agile through consolidation Service Edge
of fragmented solutions that are complex to manage, Citrix Secure Access combines Citrix SD-WAN with
limit elasticity and scale, and impede IT agility. In fact, Citrix Secure Internet Access (SIA), Citrix Secure
McKinsey states Agility has the potential to improve Workspace Access (SWA), and Citrix SD-WAN for a
the customer experience by up to 30 percent and can fully integrated secure access service edge (SASE)
lead to a potential 20 to 30 percent improvement in solution. It allows users anywhere to securely access
Citrix | Cloud-delivered security for the digital workspace 3
any virtual, web, or SaaS app, from any personal Use Cases:
or corporate device. All users can securely access
• Users clicking on links
applications sanctioned within the Citrix Workspace
• Users accessing personal applications from a BYO
and unsanctioned SaaS and web applications to ensure
device
a secure and consistent experience, regardless of
employee location.
Citrix Secure Internet Access Features
• Citrix Secure Internet Access (SIA) offers
comprehensive, cloud-delivered security services. The cloud-delivered service offers:
This includes Secure Web Gateway, Next-Generation
Firewall and Cloud Access Security functionality. • A comprehensive security service consisting of 100+
• Secure Workspace Access (SWA) provides identity- PoPs each offering SIA services giving consistent
aware, zero trust access for all corporate-sanctioned protection for all users, regardless of location.
applications within Citrix Workspace. • Lower latency and improved employee experience
• Citrix SD-WAN is a next-generation WAN edge with availability close to users with no need to
solution delivering secure, automated, reliable backhaul traffic to centralized hubs/data centers.
connectivity to improve performance of SaaS, cloud, • Auto-scale and built-in resiliency via a cloud-delivered
and virtual applications and desktops. It reduces architecture that allows on-demand scale as traffic
network complexity, centralizes orchestration and volume increases.
monitoring, and speeds cloud and on-premises • Inspection and protection for all encrypted and
connectivity to applications for users in branches or compressed traffic for compliance, malware
working from home. and data loss prevention without performance
limitations typically associated with appliance-based
approaches.
• Intelligence from 10+ Threat Engines with highly Selectively Encrypt Logs
effective malware, ransomware and signature-less
Encrypt fields such as username, source IP and group
threat protection.
prevents loss of confidential information.
• Privacy and compliance through data segregation
based on enterprise and location. Export to Templates, SIEMs
• Increased performance and lower latency with a
Built-in, schedulable executive reporting templates or
single-pass architecture, unlike service-chained
real-time export to SIEMs via built-in connectors.
architectures.
Endnotes
1 Enterprise agility: Buzz or business impact?
Enterprise Sales
North America | 800-424-8749
Worldwide | +1 408-790-8000
Locations
Corporate Headquarters | 851 Cypress Creek Road, Fort Lauderdale, FL 33309, United States
Silicon Valley | 4988 Great America Parkway, Santa Clara, CA 95054, United States
©2020 Citrix Systems, Inc. All rights reserved. Citrix, the Citrix logo, and other marks appearing herein are property
of Citrix Systems, Inc. and/or one or more of its subsidiaries, and may be registered with the U.S. Patent and
Trademark Office and in other countries. All other marks are the property of their respective owner(s).