Cisco Web Security Appliance with the Cisco Identity Services Engine

advertisement
At-a-Glance
Cisco Web Security
Appliance with
the Cisco Identity
Services Engine
Needed: A Better Approach to Web Security
Benefits
• Single source of identity and
contextual data
• Rich identity awareness (who,
what, where, and when) for web
security policy
• Consistent user experience
across multiple endpoints that
is perfect for bring-your-owndevice (BYOD) initiatives
• More detailed reporting to
understand how, when, and
from what devices users access
web resources
The risk of security threats and data breaches has been increasing due
to an expanding attack surface. Employees now use an array of mobile
devices that open up new vulnerabilities. Virtualization technology has
spread data and resources to different infrastructure layers that add
complexity and potential security weaknesses. Advanced threats use
multiple threat vectors, and to combat them you need improved visibility,
more detailed identification of users and devices, consistent control, and
faster remediation once a threat is identified.
Many organizations deploy multiple security point solutions across the
enterprise network. These products have one big problem: they don’t
provide enough contextual information to map complex deployments
or to gather enough detail on users and devices to help you sufficiently
understand the threat vectors that may leave your organization vulnerable
to a breach or an attack. What you need is an integrated approach to
help disparate security point solutions to work together, to triangulate
information for faster identification, and to more effectively mitigate and
remediate threats. That’s what you get with the Cisco® Web Security
Appliance together with the Cisco Identity Services Engine.
Figure 1. Web Security Appliance Integration with Identity Services Engine: Examples of
Varying Access
Confidential
Patient Records
Who: Doctor
What: Laptop
Where: Office
Internal
Employee Intranet
Who: Doctor
What: iPad
Where: Office
Who: Guest
What: iPad
Where: Office
WSA
Cisco Identity
Services Engine
Consistent Secure
Access Policy
© 2015 Cisco and/or its affiliates. All rights reserved.
Internet
nce
At-a-Glance
“Our goal is to get as many
people on our network as
quickly, securely, and reliably
as possible without our
involvement. ISE enables us to
do that.”
Rob Tavoularis
Network Administrator,
William Paterson University
Heightened Web Security and Identity Management
for Greater Visibility and Control
The Web Security Appliance provides industry-leading web security and
control for the distributed enterprise. The integration of this appliance
with the Identity Services Engine allows it to supplement web security
policy attributes with identity and network context information, providing
a better user experience through better visibility as well as finer control
over user access to specific websites.
The Identity Services Engine gathers in-depth contextual information
and uses Cisco pxGrid technology to share it across multiple technology
partner applications and platforms. The unique set of information shared
for faster correlation, improved user and device context, and reduction
of unknown devices provides IT managers with the ability to more
quickly identify, mitigate, and remediate threats and network issues.
Enhance Web-Access Policy with User
and Device Awareness
• Develop a better end-user content-delivery experience by utilizing
Identity Services Engine device-type and network-access contextual
information to understand how, when, and from what devices users
access web resources.
• Improve web-access policy based on user role or user device.
Gain better control over granting user access to approved or
sensitive content.
• Create device-specific web-access policies that allow or deny
access to web-based content with an understanding of whether the
endpoint is compliant with IT usage policies.
These are just a few of the ways you can use the Cisco Identity Services
Engine and Web Security Appliance to heighten your web and device
security. Once the products are deployed, the integration is simple and
the benefits far reaching.
Next Steps
Find out how to take advantage of Cisco Web Security Appliance and
Identity Services Engine integration by contacting your Cisco account
manager or Cisco partner. Or get more information about the products
at www.cisco.com/go/wsa and www.cisco.com/go/ise.
© 2015 Cisco and/or its affiliates. All rights reserved. Cisco and the Cisco logo are trademarks or registered trademarks of
Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/
go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner
does not imply a partnership relationship between Cisco and any other company. (1110R)
C45-735654-00 08/15
Download