This balance becomes even more difficult to maintain as employees bring their own mobile devices into the office and try to access network resources. How can companies handle these new production devices while still safeguarding the network from external and internal threats? Although network access policy is vital in averting unsanctioned access to networks, enterprises need to also find methods to protect the actual devices themselves in order to be able to impose endpoint compliance. The Cisco Identity Services Engine (ISE), with its assimilations with the leading mobile device management (MDM) and enterprise mobility management (EMM) software, serves as a critical bond amongst protecting devices and securing the network access.

Providing Device Visibility and Dynamic Access Control

As opposed to old-style corporate-provisioned endpoints, personal mobile devices are not provided to employees by the company. Consequently, the problem lies in ensuring that they conform with security policies prior to granting them network access. The key to safeguarding these devices to minimize global risk lies in increased visibility and expanded dynamic control: increased visibility into the mobile devices accessing your network and more dynamic control to correctly categorize and safeguard the devices to make sure that only compliant devices are able to get the right access to the company network.

Enterprises which use assimilations amongst Cisco ISE and MDM/EMM platforms obtain increased comprehension into the bearing of mobile devices to impose suitable network access policies.

How Cisco ISE Works

  • Cisco ISE screens mobile devices as they try to access the network. This detection process gives IT professionals the first step of network visibility. Mobile devices are subjected by Cisco ISE to a security posture assessment as outlines by the enterprise’s IT policy. Cisco ISE asks for posture data related with mobile devices as gathered by the MDM/EMM platforms.
  • Cisco ISE imposes access policy founded on the posture status conveyed by the MDM partner platforms. Access policy can be built on explicit features within Cisco ISE or at a global level of “in compliance” or “not in compliance” within the respective MDM/ EMM platform. End users are able to manage the status of their mobile devices via the Cisco ISE MyDevices portal. End users can lock, suspend, or unenroll devices if they lose or replace them. Cisco ISE can accomplish these processes natively or via MDM/EMM integrations.

Cisco ISE gathers and provides circumstantial information which includes the below:

  • User: User name, IP address, authentication status, location
  • User class: Authorization group, guest, quarantined
  • Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location
  • Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status (through MDM or MDM ecosystem partners)

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.