It was once considered adequate to analyze network vulnerabilities by the use of broad identifiers like an IP address. However, the upsurge in mobile traffic and devices, bring-your-own-device (BYOD) enterprises, software as a service (SaaS), and virtualization have all contributed to the requirement for profounder network security visibility and more fine-grained scrutiny. Susceptibility assessment tools allow the audit of operating systems, servers, network devices, databases, and web applications for recognized or possible susceptibility threats.

Cisco Identity Services Engine (ISE) gives precise circumstantial data, like user identity, user privilege levels, endpoint device type, and endpoint security posture via the engine’s Cisco Platform Exchange Grid (pxGrid) technology, with susceptibility assessment platforms.

Together, they give in-depth network susceptibility visibility along with pertinent identity and device circumstance. The incorporation of these cutting-edge security solutions provides security analysts the capability to assess the importance of a susceptibility event by associating the context of the incident within a susceptibility management platform console. This outlines a thorough picture of the hazards each vulnerability signifies and the aptitude to take instant action on the most egregious ones.

How the Cisco ISE Platform Works

• Cisco ISE supplies user identity and device/circumstantial data to susceptibility assessment platforms.

• Cisco ISE circumstantial information is used to produce a comprehensive view of susceptibility incident, identity, and device information. The data is used to rate the severity of susceptibilities, which then allows susceptibility incidents and responses to be prioritized.

• Users of susceptibility valuation partner products can then utilize the Identity Services Engine to take extenuation steps within the Cisco network structure. The engine can perform a quarantine or block admission to specific users and devices based on rules definite by the engine for such actions.

• All of these functions are able to be recorded and reported upon within the susceptibility valuation platform, giving unified, network wide security logging.

Some of the main Identity Services Engine attributes accessible for use by susceptibility valuation platforms for user- and device-related circumstance are:

• User: User name, IP address, authentication status, location

• User class: Authorization group, guest, quarantined

• Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location

• Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status through mobile device management (MDM) ecosystem partners

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.