Secure web gateway (SWG)

A control that inspects users' outbound web traffic and enforces policy on it, typically URL filtering, malware scanning and acceptable-use rules, on premises or as a cloud service.

A secure web gateway (SWG) stands between an organisation’s users and the internet and applies policy to their web requests. It is a forward proxy server extended with security functions: it checks each destination against URL categories and reputation, scans downloads for malware, enforces acceptable-use rules, and can apply data loss prevention to what users upload. It may run as an on-premises appliance or as a cloud service, which is why it appears as a component of secure access service edge offerings.

Two confusions are common. A web application firewall protects a web application from inbound requests, while an SWG protects users making outbound requests. A cloud access security broker focuses on the organisation’s use of specific cloud services, including their data and configuration through the providers’ interfaces, rather than general web browsing; the functions overlap and are often sold together. Much web traffic is encrypted, so an SWG commonly has to decrypt TLS sessions to see content, which requires endpoints to trust its certificate and raises privacy questions.

Exam relevance: a scenario about blocking malicious or unacceptable websites for remote and office users alike is likely to point to a secure web gateway. Candidates are expected to tell it apart from a WAF by direction of traffic, and from a CASB by scope.