Threat Defense for ISR with Cisco FirePOWER Services

You can accomplish this by employing Cisco’s industry-leading threat defense abilities, which now run on a supplementary platform: Cisco Integrated Services Routers (ISRs). Cisco FirePOWER Threat Defense for ISR ranges enterprise-level threat defense beyond old-style network edge and data center placements to assist in protecting your DIA traffic.

Now you can take advantage of the cost savings and enhanced user experiences of branch DIA, while providing better protection for your devices and hosts against unconventional threats anywhere they exist in: in branche offices, partner site locations, and other remote or inaccessible sites.

Aim for ‘Security Everywhere’

Cisco FirePOWER Threat Defense for ISR is a component of the Cisco “security everywhere” strategy. The goal is to give you the continuous visibility and control you need to defeat advanced threats across your environment. An incorporated combination of protection features work in tandem to assist in keeping your remote operations protected:

  • Cisco FirePOWER Next-Generation Intrusion Prevention System (NGIPS) sets the standard for cutting-edge threat defense, incorporating real-time circumstantial cognizance, clever protection automation, and industry leading threat deterrence.
  • Cisco Application Visibility and Control reduces the possible attack surface via accurate management and control of thousands of applications and by imposing mobile application, social media application, and acceptable use rules and policy frameworks.
  • Cisco Advanced Malware Protection (AMP) for Networks defends against highly advanced, targeted, zero-day attacks and tenacious cutting-edge malware threats.
  • Cisco Reputation-based URL Filtering alleviates highly advanced client-side attacks by managing access to over 280 million URLs in 80 plus categories, reducing risks linked with doubtful and undesirable domains.
  • Cisco FireSIGHT Management Center supplies you with centralized event and policy management in addition to visibility inside the devices, operating systems (OS), applications, and users accessing your corporate network.

Contact your local sales rep to schedule a demo and request for pricing details. For additional information, visit the Cisco FirePOWER Threat Defense for ISR web page.

To speak with one of our Licensing Specialists, please click here.

Cisco ISE with Integrated Security, Event Management and Threat Defense

Cisco ISE employs Cisco Platform Exchange Grid (pxGrid) technology to share circumstantial information with leading SIEM and TD partner solutions. The amalgamation of these incorporated technologies provides security analysts the capability to quickly and easily evaluate the importance of security events by associating expanded context with the security alerts. Cisco ISE enables the SIEM and TD system management consoles to display contextual information pulled from the engine about each security event.

The data can include the characteristics and level of access for each user and the kind of device which has been used. This data allows the analyst to more quickly find out where this event is originating from, whether it requires more investigation, and, if so, how critical is the threat. Cisco ISE can then be employed to undertake extenuation actions. Cisco ISE integrations with SIEM and TD platforms also enable improved security monitoring, like mobility-aware security analytics. The improved capabilities from Cisco ISE with SIEM and TD integration restructure the process of threat identification, make easy the execution of responses by IT teams, and vastly minimize the time needed for remediation of any network security threats.

How Cisco ISE Assimilations with SIEM and TD Solutions Works

The Identity Services Engine gives its user identity and device contingent data to SIEM and TD partner platforms. Then:

• Make new security investigation classes for high-risk user populations or devices, like policies adapted to mobile devices or users with access to exceedingly sensitive data.

• Appended to associated events in the SIEM and TD partner solutions to provide the extra circumstance of the user, device, and access level. The data assists analysts improved decode the importance of a security incident.

• Take extenuation steps within the Cisco network infrastructure. ISE can assume a quarantine action on users and devices.

• Log and report within the SIEM and TD products, giving cohesive, network-encompassing security reporting.

A few of the main features of the Identity Services Engine obtainable for use SEIM and TD for user- and device-related context are:

  • User: User name, IP address, authentication status, location
  • User class: Authorization group, guest, quarantined
  • Device: Manufacturer, model, OS, OS version, MAC address, IP address, network connection method (wired or wireless), location
  • Posture: Posture compliance status, antivirus installed, antivirus version, OS patch level, mobile device posture compliance status through mobile device management (MDM) ecosystem partners.

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.