Cisco Rapid Threat Containment – Halt Threats Before They Halt You

In addition, you can safeguard critical information in the smallest timeframe via the Threat-Centric NAC attribute of Rapid Threat Containment. Using this progressive network access control technology, you can manually or automatically modify your users’ access rights if their threat or susceptibility scores go up. Devices that are suspected of being infested can be deprived of access to important information while their users can keep working on less critical applications.

With Rapid Threat Containment you can transform your security intelligence and response technologies into an integrated operation to view and halt threats no matter where and when they happen inside your network.

What’s Included

Cisco Rapid Threat Containment includes the following:

Perspective and control: The Cisco Identity Services Engine gives circumstantial identity information (user, device type, and posture). It halts threats by using the network as an enforcer with VLANs or Cisco TrustSec security clusters.

Integration: Cisco Platform Exchange Grid (pxGrid) gives an open, highly protected system for security technologies to interchange intelligence, get circumstantial data from ISE, and instruct ISE to halt threats. Cisco pxGrid is in sync with Internet Engineering Task Force (IETF) standards.

Intelligence: Cisco pxGrid technology partners who are incorporated with pxGrid’s Rapid Threat Containment ability can share their information and utilize ISE to manage network access to hostile devices.

Cisco security technologies: With the Cisco Firepower Management Center and Stealthwatch activities scrutiny, you can share security intelligence and the capability to demand threat containments via ISE.

Threat-Centric NAC technologies: You can utilize the typical jargons of the Structured Threat Information Expression (STIX) for threats and the Common Vulnerability Scoring System (CVSS) for susceptibilities to help make sure of reliable classification and reactions. Today Qualys is incorporated with pxGrid for susceptibilities and Cisco AMP for threats.

The Rapid Threat Containment solution has been tested, documented, and supported by Cisco (CS) customer service.

For more information on Cisco’s support for multi-vendor solutions go to http://www.cisco.com/c/en/us/services/support/solution-support.html

For a complete listing of Cisco security technology partners who support ISE pxGrid and Rapid Threat Containment go to: www.cisco.com/go/csta.

For design and deployment guides go to: http://www.cisco.com/c/en/ us/support/security/identity-services-engine/products-implementation-design-guides-list.html

For more details about Cisco’s extensive and marketing-leading security technologies, go to: http://cisco.com/go/security

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.

Acquire real visibility with Cisco Stealthwatch and ISE

Even if staff are aware that their system is compromised, they don’t constantly know where it’s occuring and how, making them vulnerable to network exploitation and insider threats. Companies require a solution that gives them widespread network visibility heightened by rich user and device data to speed up threat detection and response times.

Only the combination of Stealthwatch and Cisco’s Identity Services Engine assists organizations in getting a 360° view, react to threats quicker, and protect a growing digital business.

Get a 360° view with Cisco Stealthwatch and ISE

Get matchless visibility and control with incorporation of Cisco Stealthwatch and ISE.

•  Unceasingly screen, examine, separate, classify, and store host and user data from your network with Stealthwatch.

•  Facilitate system administrators to view data about each distinct device – type, operating system, compliance status, connection method, geographical location and more with ISE.

•  Find irregular traffic in your environment. Implementing context-cognizant security scrutiny to automatically find irregular activities, Stealthwatch can find a wide range of attacks, like malware, zero-day attacks, distributed denial-of-service (DDoS) attempts, advanced persistent threats (APTs), and insider attacks.

•  Identify exactly when specific user activities become suspicious. Stealthwatch allows admins to set their own activities thresholds, once a user crosses the brink it activates an alert.

Respond with Rapid Threat Containment

•  Once Stealthwatch finds irregular traffic, it activates an alert, providing the admin an option to quarantine the user. pxGrid activates Stealthwatch to hand off the quarantine command straight to ISE.

•  Admins can make a judgement based on scrutiny, rescinding users access and isolating them through ISE with a single click. Admins don’t have to change or modify the whole system policies in place as ISE reallocates the access policy of the quarantined user.

•  Identify the root source of a breach with post-incident audit trails. Stealthwatch saves records of all network goings-on for months and years.

Protect your expanding digital business

To move ahead with novel initiatives or technologies assuredly, companies must know that they can scale without needing to create new security problems.

•  Stop worrying about security as a hindrance and supply a foundation for network subdivision for protected access & visibility.

•  Empower admins to prudently control access to delicate assets, know exactly when somebody attempts to access data, and spread out that visibility to any new area of the network, environment or the cloud.

•  Augment users, devices and business without the compromising of network visibility. Decrease the administrative load of setting up new devices with continually updating device profile feeds from Cisco ISE.

•  Scale the environment without the creation of blind spots. A deployment of Stealthwatch is able to process information from 50,000 flow sources at 6 million flows per second (fps) all while stitching and de-duplicating flows.

•  Minimize the managerial burden linked with silo’d management sources. Network-wide flow is centrally exhibited in the Stealthwatch Management Console. Simply assimilate third party technologies and services via a REST API.

To learn more visit www.cisco.com/go/Stealthwatch , www.cisco.com/go/ise

For more details contact our Cisco Licensing Specialists here.