Enterprise Mobility Management Integrations with Cisco ISE

This balance becomes even more difficult to maintain as employees bring their own mobile devices into the office and try to access network resources. How can companies handle these new production devices while still safeguarding the network from external and internal threats? Although network access policy is vital in averting unsanctioned access to networks, enterprises need to also find methods to protect the actual devices themselves in order to be able to impose endpoint compliance. The Cisco Identity Services Engine (ISE), with its assimilations with the leading mobile device management (MDM) and enterprise mobility management (EMM) software, serves as a critical bond amongst protecting devices and securing the network access.

Providing Device Visibility and Dynamic Access Control

As opposed to old-style corporate-provisioned endpoints, personal mobile devices are not provided to employees by the company. Consequently, the problem lies in ensuring that they conform with security policies prior to granting them network access. The key to safeguarding these devices to minimize global risk lies in increased visibility and expanded dynamic control: increased visibility into the mobile devices accessing your network and more dynamic control to correctly categorize and safeguard the devices to make sure that only compliant devices are able to get the right access to the company network.

Enterprises which use assimilations amongst Cisco ISE and MDM/EMM platforms obtain increased comprehension into the bearing of mobile devices to impose suitable network access policies.

How Cisco ISE Works

  • Cisco ISE screens mobile devices as they try to access the network. This detection process gives IT professionals the first step of network visibility. Mobile devices are subjected by Cisco ISE to a security posture assessment as outlines by the enterprise’s IT policy. Cisco ISE asks for posture data related with mobile devices as gathered by the MDM/EMM platforms.
  • Cisco ISE imposes access policy founded on the posture status conveyed by the MDM partner platforms. Access policy can be built on explicit features within Cisco ISE or at a global level of “in compliance” or “not in compliance” within the respective MDM/ EMM platform. End users are able to manage the status of their mobile devices via the Cisco ISE MyDevices portal. End users can lock, suspend, or unenroll devices if they lose or replace them. Cisco ISE can accomplish these processes natively or via MDM/EMM integrations.

Cisco ISE gathers and provides circumstantial information which includes the below:

  • User: User name, IP address, authentication status, location
  • User class: Authorization group, guest, quarantined
  • Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location
  • Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status (through MDM or MDM ecosystem partners)

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco ISE with Integrated Security, Event Management and Threat Defense

Cisco ISE employs Cisco Platform Exchange Grid (pxGrid) technology to share circumstantial information with leading SIEM and TD partner solutions. The amalgamation of these incorporated technologies provides security analysts the capability to quickly and easily evaluate the importance of security events by associating expanded context with the security alerts. Cisco ISE enables the SIEM and TD system management consoles to display contextual information pulled from the engine about each security event.

The data can include the characteristics and level of access for each user and the kind of device which has been used. This data allows the analyst to more quickly find out where this event is originating from, whether it requires more investigation, and, if so, how critical is the threat. Cisco ISE can then be employed to undertake extenuation actions. Cisco ISE integrations with SIEM and TD platforms also enable improved security monitoring, like mobility-aware security analytics. The improved capabilities from Cisco ISE with SIEM and TD integration restructure the process of threat identification, make easy the execution of responses by IT teams, and vastly minimize the time needed for remediation of any network security threats.

How Cisco ISE Assimilations with SIEM and TD Solutions Works

The Identity Services Engine gives its user identity and device contingent data to SIEM and TD partner platforms. Then:

• Make new security investigation classes for high-risk user populations or devices, like policies adapted to mobile devices or users with access to exceedingly sensitive data.

• Appended to associated events in the SIEM and TD partner solutions to provide the extra circumstance of the user, device, and access level. The data assists analysts improved decode the importance of a security incident.

• Take extenuation steps within the Cisco network infrastructure. ISE can assume a quarantine action on users and devices.

• Log and report within the SIEM and TD products, giving cohesive, network-encompassing security reporting.

A few of the main features of the Identity Services Engine obtainable for use SEIM and TD for user- and device-related context are:

  • User: User name, IP address, authentication status, location
  • User class: Authorization group, guest, quarantined
  • Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location
  • Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status through mobile device management (MDM) ecosystem partners.

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco Rapid Threat Containment – Halt Threats Before They Halt You

In addition, you can safeguard critical information in the smallest timeframe via the Threat-Centric NAC attribute of Rapid Threat Containment. Using this progressive network access control technology, you can manually or automatically modify your users’ access rights if their threat or susceptibility scores go up. Devices that are suspected of being infested can be deprived of access to important information while their users can keep working on less critical applications.

With Rapid Threat Containment you can transform your security intelligence and response technologies into an integrated operation to view and halt threats no matter where and when they happen inside your network.

What’s Included

Cisco Rapid Threat Containment includes the following:

Perspective and control: The Cisco Identity Services Engine gives circumstantial identity information (user, device type, and posture). It halts threats by using the network as an enforcer with VLANs or Cisco TrustSec security clusters.

Integration: Cisco Platform Exchange Grid (pxGrid) gives an open, highly protected system for security technologies to interchange intelligence, get circumstantial data from ISE, and instruct ISE to halt threats. Cisco pxGrid is in sync with Internet Engineering Task Force (IETF) standards.

Intelligence: Cisco pxGrid technology partners who are incorporated with pxGrid’s Rapid Threat Containment ability can share their information and utilize ISE to manage network access to hostile devices.

Cisco security technologies: With the Cisco Firepower Management Center and Stealthwatch activities scrutiny, you can share security intelligence and the capability to demand threat containments via ISE.

Threat-Centric NAC technologies: You can utilize the typical jargons of the Structured Threat Information Expression (STIX) for threats and the Common Vulnerability Scoring System (CVSS) for susceptibilities to help make sure of reliable classification and reactions. Today Qualys is incorporated with pxGrid for susceptibilities and Cisco AMP for threats.

The Rapid Threat Containment solution has been tested, documented, and supported by Cisco (CS) customer service.

For more information on Cisco’s support for multi-vendor solutions go to http://www.cisco.com/c/en/us/services/support/solution-support.html

For a complete listing of Cisco security technology partners who support ISE pxGrid and Rapid Threat Containment go to: www.cisco.com/go/csta.

For design and deployment guides go to: http://www.cisco.com/c/en/ us/support/security/identity-services-engine/products-implementation-design-guides-list.html

For more details about Cisco’s extensive and marketing-leading security technologies, go to: http://cisco.com/go/security

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Acquire real visibility with Cisco Stealthwatch and ISE

Even if staff are aware that their system is compromised, they don’t constantly know where it’s occuring and how, making them vulnerable to network exploitation and insider threats. Companies require a solution that gives them widespread network visibility heightened by rich user and device data to speed up threat detection and response times.

Only the combination of Stealthwatch and Cisco’s Identity Services Engine assists organizations in getting a 360° view, react to threats quicker, and protect a growing digital business.

Get a 360° view with Cisco Stealthwatch and ISE

Get matchless visibility and control with incorporation of Cisco Stealthwatch and ISE.

•  Unceasingly screen, examine, separate, classify, and store host and user data from your network with Stealthwatch.

•  Facilitate system administrators to view data about each distinct device – type, operating system, compliance status, connection method, geographical location and more with ISE.

•  Find irregular traffic in your environment. Implementing context-cognizant security scrutiny to automatically find irregular activities, Stealthwatch can find a wide range of attacks, like malware, zero-day attacks, distributed denial-of-service (DDoS) attempts, advanced persistent threats (APTs), and insider attacks.

•  Identify exactly when specific user activities become suspicious. Stealthwatch allows admins to set their own activities thresholds, once a user crosses the brink it activates an alert.

Respond with Rapid Threat Containment

•  Once Stealthwatch finds irregular traffic, it activates an alert, providing the admin an option to quarantine the user. pxGrid activates Stealthwatch to hand off the quarantine command straight to ISE.

•  Admins can make a judgement based on scrutiny, rescinding users access and isolating them through ISE with a single click. Admins don’t have to change or modify the whole system policies in place as ISE reallocates the access policy of the quarantined user.

•  Identify the root source of a breach with post-incident audit trails. Stealthwatch saves records of all network goings-on for months and years.

Protect your expanding digital business

To move ahead with novel initiatives or technologies assuredly, companies must know that they can scale without needing to create new security problems.

•  Stop worrying about security as a hindrance and supply a foundation for network subdivision for protected access & visibility.

•  Empower admins to prudently control access to delicate assets, know exactly when somebody attempts to access data, and spread out that visibility to any new area of the network, environment or the cloud.

•  Augment users, devices and business without the compromising of network visibility. Decrease the administrative load of setting up new devices with continually updating device profile feeds from Cisco ISE.

•  Scale the environment without the creation of blind spots. A deployment of Stealthwatch is able to process information from 50,000 flow sources at 6 million flows per second (fps) all while stitching and de-duplicating flows.

•  Minimize the managerial burden linked with silo’d management sources. Network-wide flow is centrally exhibited in the Stealthwatch Management Console. Simply assimilate third party technologies and services via a REST API.

To learn more visit www.cisco.com/go/Stealthwatch , www.cisco.com/go/ise

For more details contact our Cisco Licensing Specialists here.

Cisco Identity Services Engine Portal Builder

You can give visitors hotspot access to your branded site, complete with commercials, while providing corporate company staff with a self-service bring-your-own-device (BYOD) portal. It doesn’t matter what type of portal you require, Cisco ISE makes it really easy to include your branding reliably across the enterprise.

Tailor Your Portals with Expert Tools

Simple-to-use features make easy the design and administration of your portals. Edit the typescript — with font size, type, and color — and make modifications to an image file’s location and size to help ensure a faultless fit. The color selector allows you to select from a palette and even make customized colors. Implement your designs, images, and color choices to all the portals inside a project. You also have the flexibility to modify each page. Once you are done, you are able to save, copy, share, or delete   your portals.

See Your Designs Come to Life

The Cisco ISE Portal Builder “what you see is what you get” (WYSIWYG) visual editor eliminates conjecture from the design procedure. Just drag and drop objects on the screen and view how the designs will be viewed on smartphones and laptops. Notwithstanding all the progressive functionality, the portal builder keeps the workflow extraordinarily easy so that nearly anybody can become skillful at designing and creating.

Keep Your Images in One Location for Simple Access

Simply import and save pictures, logos, banners, photographs, and commercials in the image manager. All pertinent pictures can be simply accessed and utilized every time you need to make a modification to your portals.

Rapidly Make Changed as Often as Needed

Since virtually any IT generalist can become skillful at making or changing portals, anybody on your team can update the guest and BYOD portals on a recurrent basis to make declarations, transfer offers, or just modify the look and feel of your portals.

Share Design Projects, Pool resources as a Team

You will be able to share your designs with other team members so that they can appraise, comment, and even make edits. In addition, you can also share your designs with the larger public and get stimulated by their ideas in return.

Eradicate Configuration Difficulties, Systematize Portal Uploads to Cisco ISE

How can you ensure that your constituted portal remains true to your design and workflow process? Aligning and exporting custom portals can be complex, but this tool removes the conjecture. It comprises an easy to use browser plug-in to simplify the alignment and exporting of your portals in Cisco ISE. It is done right the first time, every time.

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco Identity Services Engine Security Technical Alliance

However, numerous solutions from multiple vendors also generate disconnected sources of data. All these dissimilar systems produce incongruent information that needs to be manually pieced together to precisely locate a network threat and define which remediating step should be taken.

Cisco ISE can help in streamlining this process. ISE gathers valuable circumstantial information from across the network. This information can then be combined and shared across manifold systems and vendors by the Cisco Platform Exchange Grid (pxGrid). You can get answers quicker. And you can utilize the Cisco ISE Rapid Threat Containment feature to halt security threats by using the network as an enforcer.

In addition, ISE allows Security Technical Alliance partner technologies to utilize Structured Threat Information Expression (STIX) threat scores and the Common Vulnerability Scoring System (CVSS) to modify or diminish the access status founded on a threat score. You can assign access to devices that have a lower risk score while rejecting access to devices with a high risk score.

Cisco pxGrid

Cisco pxGrid is an open, scalable, and IETF standards-powered information-sharing and data-control platform. It enables numerous security products to work in tandem. Security operations can systematize to get answers quickly and control threats faster.

How pxGrid Increases Your Protection

Easier integration: You can use one API for open, automated data sharing and control among more than 50 security products. Cisco pxGrid helps in enabling a complete ecology of different IETF standards-compliant technologies to work in tandem. You need to manage and sustain only a singular interface as a substitute of a group of unrelated APIs.

Immediate visibility: Seeing all circumstantial and pertinent data on a single screen improves time and staff efficiencies. Tailor the methods in which you share and view security information. See your security position more visibly and succinctly, including challenging events on your network. Improve your staff efficiency.

Faster investigations: Perform a complete analysis on one system for faster answers. Security intelligence is able to be shared automatically between almost any pxGrid-integrated technologies. You don’t need to perform long investigations. Your security operations can come up with solutions.

Even faster responses: Stop threats immediately using the network as an enforcer. Cisco pxGrid enables any unified and proficient technology on a pxGrid instance to educate ISE to contain a threat by using the network as an enforcer so that any attack anywhere in the network can be instantly halted.

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco Identity Services Engine and Check Point Integration

Cisco ISE gives a wealth of user identity, endpoint device, and network context data that is beneficial to multiple IT platforms for customers around the globe. To bring more insight to hazardous user activities on the network, Cisco ISE employs Cisco Platform Exchange Grid (pxGrid) technology to share identity, device, and network information. The IT infrastructure can aid more use cases and function more effectively by becoming identity, device, and network conscious. Cisco pxGrid is a cohesive framework that provisions multivendor, cross-platform network system cooperation among IT infrastructures such as security monitoring and detection structures, network policy platforms, identity and access management platforms, and almost any other IT operations platform.

This integration delivers Check Point gateways with improved visibility of user actions while improving management of corporate resources. ISE assists the Check Point console to show circumstantial data associated with an incident, such as the user’s characteristics and level of access. This ability enables your security team to make access policy judgments by using identity information which provides far more policy information than traditional firewalls, which are restricted to data like IP addresses or port numbers. This improved level of detail from ISE can decrease threats and data loss by limiting access to resources by users and devices. The resolution is composed of Cisco ISE running pxGrid context-exchange abilities, an ISE Plus or Advanced Feature license, and the Check Point Identity Awareness Software Blade.

How Cisco ISE & Check Point Integration Work

• Cisco ISE supplies its user identity and device data to Check Point Identity Awareness

• Identity Awareness utilizes the precise, real-time user identity context given by ISE in its firewall rule base

• ISE circumstantial information is also added to related events in Check Point to give the supplementary context of the user, device, and access level, assisting analysts to better comprehend the consequence of a security incident

• All of these utilities can be recorded and reported on within the Check Point console, which gives unified user activities for security threat reporting

Some of the chief ISE attributes obtainable for use by Check Point for user-related context include:

• User: user name, IP address, authentication status, location

• User class: authorization group

• Cisco TrustSec: security group tag (SGT)

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Cisco ISE Integration with Vulnerability Assessment Platforms

It was once considered adequate to analyze network vulnerabilities by the use of broad identifiers like an IP address. However, the upsurge in mobile traffic and devices, bring-your-own-device (BYOD) enterprises, software as a service (SaaS), and virtualization have all contributed to the requirement for profounder network security visibility and more fine-grained scrutiny. Susceptibility assessment tools allow the audit of operating systems, servers, network devices, databases, and web applications for recognized or possible susceptibility threats.

Cisco Identity Services Engine (ISE) gives precise circumstantial data, like user identity, user privilege levels, endpoint device type, and endpoint security posture via the engine’s Cisco Platform Exchange Grid (pxGrid) technology, with susceptibility assessment platforms.

Together, they give in-depth network susceptibility visibility along with pertinent identity and device circumstance. The incorporation of these cutting-edge security solutions provides security analysts the capability to assess the importance of a susceptibility event by associating the context of the incident within a susceptibility management platform console. This outlines a thorough picture of the hazards each vulnerability signifies and the aptitude to take instant action on the most egregious ones.

How the Cisco ISE Platform Works

• Cisco ISE supplies user identity and device/circumstantial data to susceptibility assessment platforms.

• Cisco ISE circumstantial information is used to produce a comprehensive view of susceptibility incident, identity, and device information. The data is used to rate the severity of susceptibilities, which then allows susceptibility incidents and responses to be prioritized.

• Users of susceptibility valuation partner products can then utilize the Identity Services Engine to take extenuation steps within the Cisco network structure. The engine can perform a quarantine or block admission to specific users and devices based on rules definite by the engine for such actions.

• All of these functions are able to be recorded and reported upon within the susceptibility valuation platform, giving unified, network wide security logging.

Some of the main Identity Services Engine attributes accessible for use by susceptibility valuation platforms for user- and device-related circumstance are:

• User: User name, IP address, authentication status, location

• User class: Authorization group, guest, quarantined

• Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location

• Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status through mobile device management (MDM) ecosystem partners

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Secure and Manage Your Evolving Network with the Cisco ISE

Flexibility, digitization, and the Internet of Things (IoT) are rapidly changing the way and manner in which we live and work. Enterprises are tested with supporting a wide array of network-enabled devices even as innumerable security threats and highly broadcasted data breaches exhibit the significance of defending access to the ever changing enterprise network.

As the modern network continues to expand, so does the difficulty of arranging resources, handling incongruent security solutions, and regulating risk. Then you need to take in to account the pervasive connectivity of non-corporate devices with already constrained IT resources. The likelihood of being unable to find and fix security threats becomes huge indeed. A different approach is needed to both manage and protect the ever changing enterprise network. It’s called the Cisco Identity Services Engine (ISE).

Important ISE 2.2 updates and enhancements allow you to:

• View and share rich user and device details: Get additional user and endpoint visibility all the way from all the guest users in the network right down to the endpoint application level.

• Manage access all over the network using next-level control for endpoints. Coupled with even richer endpoint and application visibility, Cisco ISE is able to enforce extremely granular user behavior and device compliance.

• Use the simple wireless setup tool. Enterprise-grade network access security can now be attained with industry-leading swiftness and simplicity of use with the new built-in ISE setup tool. The zero-day wireless installation with Cisco Wireless LAN Controllers can be attained in under 10 minutes for protected access, guest services, and BYOD.

• Halt and contain network threats: Develop a next-level segmentation tactic with ISE DEFCON. You can set multiple policy scenarios predefined within numerous Cisco TrustSec matrixes. You can dynamically install software-defined segmentation instantaneously based on your company’s threat climate.

Furthermore, ISE uses Cisco Platform Exchange Grid (pxGrid) technology to share rich circumstantial data with incorporated technology partner solutions. pxGrid is an Internet Engineering Task Force (IETF) standards-based method to quicken your ability to find, alleviate, and fix security threats all across your extended network. Overall, the access control is consolidated and mad easy to deliver important business services much more securely, augment infrastructure protection, impose compliance, and make more efficient IT operations.

Via its integrations with principal networking and threat defense solutions, its profound network visibility, and its protected access control abilities, ISE plays an essential role in the Rapid Threat Containment, network-as-a-sensor, and network-as-an-enforcer solutions which empower the Cisco Digital Ready Network.

To learn more about the Cisco ISE, visit http://www.cisco.com/go/ise or contact our Cisco Licensing Specialists here.