Cisco ISE employs Cisco Platform Exchange Grid (pxGrid) technology to share circumstantial information with leading SIEM and TD partner solutions. The amalgamation of these incorporated technologies provides security analysts the capability to quickly and easily evaluate the importance of security events by associating expanded context with the security alerts. Cisco ISE enables the SIEM and TD system management consoles to display contextual information pulled from the engine about each security event.
The data can include the characteristics and level of access for each user and the kind of device which has been used. This data allows the analyst to more quickly find out where this event is originating from, whether it requires more investigation, and, if so, how critical is the threat. Cisco ISE can then be employed to undertake extenuation actions. Cisco ISE integrations with SIEM and TD platforms also enable improved security monitoring, like mobility-aware security analytics. The improved capabilities from Cisco ISE with SIEM and TD integration restructure the process of threat identification, make easy the execution of responses by IT teams, and vastly minimize the time needed for remediation of any network security threats.
How Cisco ISE Assimilations with SIEM and TD Solutions Works
The Identity Services Engine gives its user identity and device contingent data to SIEM and TD partner platforms. Then:
• Make new security investigation classes for high-risk user populations or devices, like policies adapted to mobile devices or users with access to exceedingly sensitive data.
• Appended to associated events in the SIEM and TD partner solutions to provide the extra circumstance of the user, device, and access level. The data assists analysts improved decode the importance of a security incident.
• Take extenuation steps within the Cisco network infrastructure. ISE can assume a quarantine action on users and devices.
• Log and report within the SIEM and TD products, giving cohesive, network-encompassing security reporting.
A few of the main features of the Identity Services Engine obtainable for use SEIM and TD for user- and device-related context are:
- User: User name, IP address, authentication status, location
- User class: Authorization group, guest, quarantined
- Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location
- Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status through mobile device management (MDM) ecosystem partners.
For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.
