0% found this document useful (0 votes)
57 views8 pages

Ise Solution Overview

Cisco's Identity Services Engine (ISE) provides organizations with the flexibility and choice needed to implement network access control workloads across multiple clouds, improving security resilience. ISE allows visibility and dynamic control over users and devices connecting to network resources. It helps integrate intelligence across security systems for continuous trusted access following a zero-trust model. ISE automates the deployment of network access services to accelerate secure access while reducing risk through uncertainty.

Uploaded by

Karim
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
57 views8 pages

Ise Solution Overview

Cisco's Identity Services Engine (ISE) provides organizations with the flexibility and choice needed to implement network access control workloads across multiple clouds, improving security resilience. ISE allows visibility and dynamic control over users and devices connecting to network resources. It helps integrate intelligence across security systems for continuous trusted access following a zero-trust model. ISE automates the deployment of network access services to accelerate secure access while reducing risk through uncertainty.

Uploaded by

Karim
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 8

Solution Brief

Cisco Public

ISE 3.x
Flexibility and choice power security
resilience for zero-trust architectures
What if IT and security operations could respond to change
and reduce risk with seamless access to network resources
from anywhere, to everywhere, and on anything? And, what
if controlling and managing access to the workplace was
radically simplified and modernized to build security
resilience into the network?

© 2022 Cisco and/or its affiliates. All rights reserved.


Solution Brief
Cisco Public

Resilience begins with securing the network connection Benefits


• Security resilience. Rapidly deploy Network
For the digitally connected organization, having security Cisco® Identity Services Engine (ISE) gives customers
Access Control workloads across multiple
resilience is paramount to maintain business continuity the flexibility and choice they require to tether Network
clouds and achieve security resilience for the
amidst unpredictable threats and change. The world has Access Control workloads to multiple clouds and
self-managed infrastructure
gone hybrid, and most, if not all of, business success maintain business continuity through uncertainty.
depends on secure, connected experiences. And with Customers gain a modernized way to deploy NAC • Pervasive visibility and dynamic control.
today’s IT operating across multiple environments, services. Moving from managing infrastructure in a See, know, and control what is connecting to
ensuring only trusted users and devices gain access box to leveraging infrastructure as code (IaC) across your network and ensure their posture doesn’t
to trusted network resources is more important than hybrid deployments, teams can accelerate the delivery jeopardize your business.
ever to protect the integrity of the business amidst the of pervasive visibility and dynamic control to secure • Fully mature zero trust. Integrate intelligence
expanding attack surface and unprecedented levels of access across the distributed network and preserve the from across your stack into policy enforcement
global uncertainty. integrity of the business. points throughout the network for continuous
trusted access.
• Automated threat containment. Don’t just
block threats—remove them with integrated
intelligence into enforcement points within
the network.
• Merge speed and agility. Move Ops
from managing infrastructure in a box to
infrastructure in code (IaC) with automated
deployments to accelerate secure
© 2022 Cisco and/or its affiliates. All rights reserved.
network access.
Solution Brief
Cisco Public

In today’s connected world


Uncertainty has become Resilience begins with securing Reducing risk, and IT is Hybrid—Don’t forget your
the new normal the network connection emerging stronger infrastructure in your network security
Because change comes faster than If organizations are to be resilient, they As uncertainty breeds risk, resilient The hybrid reality of IT is driving
ever, businesses are making massive require flexibility and choice in deploying organizations are reducing risk by closing resiliency. Organizations are demanding
investments across the enterprise to secure Network Access Control the gaps between siloed solutions and solutions that provide the flexibility and
strengthen resilience. From financial services to protect the integrity of the looking to activate intelligence across choice they need to tailor deploying
resilience to operations resilience, from business amidst unpredictable threats the entire security stack. Integrated network resources in line with reducing
organizational to supply chain resilience, and change. To emerge stronger from intelligence with a platform approach risk. In addition, the self-managed
these initiatives are designed to help security incidents, pervasive visibility and enables continuous trusted access infrastructure remains a critical
businesses operate in the new normal. dynamic control into users and endpoints that goes beyond building trust just at environment for IT as they look to
And these investments will fall short connecting to network resources is a top authentication and provides security secure their most prized IT assets from
without security resilience because concern for IT as they secure network throughout the entire session for mature unknown threat vectors and enable
security cuts through every aspect of access across multiple environments. zero-trust architectures. the connect-from-anywhere and
these initiatives. Security resilience is the connect-on-anything workforce.
ability to protect the integrity of every
aspect of your business to withstand
unpredictable threats, or changes, and
then emerge stronger.

© 2022 Cisco and/or its affiliates. All rights reserved.


Solution Brief
Cisco Public

How ISE enforces Zero Trust


Connecting trusted users and endpoints with trusted resources

Endpoint request access Endpoint classified, and


• Endpoint is identified and trust profiled into groups
is established • Endpoints are tagged w/SGTs
• Posture of endpoint verified to • Policy applied to profiled groups
meet compliance based on least privilege

Trust continually verified


Cisco ISE Endpoint authorized access
• Continually monitors and verifies based on least privilege
endpoint trust level • Access granted
• Vulnerability assessments to • Network segmentation achieved
identify indicators of compromise
• Automatically updates access policy

© 2022 Cisco and/or its affiliates. All rights reserved.


Solution Brief
Cisco Public

How it works “Without ISE, we would


Cisco Identity Services Engine (ISE) activates
intelligence from across the security stack to become
Network administrators can develop and maintain
dynamic risk-based polices to ensure that only trusted
be spending a lot more
the policy decision point in a zero-trust architecture for
the workplace. ISE enables an automated approach to
users and devices gain access to trusted resources,
moving protection beyond authentication and
time helping people
discover, profile, authenticate, and authorize trusted maintaining trust throughout the entirety of the session. connect. Now, we can
endpoints and users connecting to the self-managed With ISE, organizations are confidently moving from a
network infrastructure, regardless of access medium. point solution approach that only solves for a single, diagnose 90% of the
ISE has maintained market dominance for over ten immediate “compliance task” and aligning to strategic
years with its unique ability to receive and share context business objectives with a zero-trust policy enforcement problems in 10 minutes.
from the network as well as integrate intelligence. platform that will handle what’s now, and what’s next, in
With integrated intelligence, ISE builds zero-trust the self-managed infrastructure. Doing it the old-school
policy decision points into the network for continuous
trusted access and automated threat containment.
way would have taken a
lot more time.”
Network engineering services assistant
director, higher education
From the commissioned study conducted by Forrester Consulting on
behalf of Cisco, March 2022, “The Total Economic Impact™ of Cisco
Identity Service Engine (ISE)”

Read the report


© 2022 Cisco and/or its affiliates. All rights reserved.
Solution Brief
Cisco Public

“We now have better Use Cases


visibility, more granular Cisco ISE addresses these challenges with a broad set
of mission-critical NAC use cases to support zero trust
• Dynamic control. Confidently build security
into your network with visibility-driven network

segmentation, better across the distributed network. segmentation. Network segmentation builds zero
trust into the network with policy-based access to
• Pervasive visibility. See and know everything
policy enforcement, connecting. The first step to building a resilient security
contain and prevent the lateral movement of threats.
Organizations can shrink the attack surface, limit
posture is gaining the ability to see and know everything
and better identity and that is connecting to the network. ISE automates the
the spread of ransomware, and enable rapid threat
containment, all while continually assuring this level
access management.” discovery of devices connecting to the network. With
ISE, teams can identify, classify, and track endpoints
of protection will not disrupt business outcomes.
connected to the network to allow the automation of • Automated threat containment. Don’t just block
CIO, financial services organization
policy provisioning before allowing access to network threats—remove them. ISE integrates with Cisco
From the commissioned study conducted by Forrester Consulting on
behalf of Cisco, March 2022, “The Total Economic Impact™ of Cisco resources. IT teams have the flexibility they need to Security products and third-party ecosystem
Identity Service Engine (ISE)” balance business objectives with security and can partners through pxGrid and pxGrid Cloud to gain
choose between an agent or agentless approach to contextual information from on-prem and cloud-
Read the report gain the visibility required to look deep into the device native solutions. This open integration ecosystem
and ensure endpoint compliance. Any changes to brings an active arm of policy enforcement into
the overall posture of any endpoint automatically and your security stack to automate threat containment,
dynamically updates the policy to control access, remove threats, and reduce mean time to repair.
ensure compliance, reduce risk, and contain threats.

© 2022 Cisco and/or its affiliates. All rights reserved.


Solution Brief
Cisco Public

Forrester Consulting recently conducted an • Endpoint compliance. Business continuity relies on • Secure access. Accelerates value by simplifying
independent analysis of five organizations using a strong, resilient security posture. ISE continually the provisioning of policies and devices. ISE enables
ISE. The commissioned study conducted by verifies that device posture complies with your self-registration, automates device configuration
Forrester Consulting on behalf of Cisco, March security policy so that risky, unpatched, and outdated and manages certificates and mobile policy
2022, “The Total Economic Impact™ of Cisco devices cannot threaten the network. ISE 3.x compliance. With granular visibility and controls IT
Identity Service Engine (ISE),” highlighted: increases organizational posture with a customizable admins can confidently and quickly provision new
approach to gaining continuous posture assessments resources to allow connection to the network without
191% for endpoints connecting to your managed sacrificing protection.
ROI in first 3 years infrastructure. With a limitless number of posture
checks, customers can now customize and
50% enforce dynamic policy and gain continuous
Reduction in access-related security events trusted access to ensure business resiliency,
while limiting organizational risk without disrupting
11-month business objectives.
Payback period

66%
Avoided increasing NetOps headcount by 66%
with automation

88%
Uplift of additional benefits when deployed for SDA

Download and read the entire study to learn all the


business benefits of ISE.
© 2022 Cisco and/or its affiliates. All rights reserved.
Solution Brief
Cisco Public

Why ISE?
Other standalone solutions end up “bolting on” security to the network, often resulting in operational complexity and Check out ESG’s whitepaper on
performance issues. Cisco Identity Services Engine (ISE) has gained market dominance with a focus on security that
is built directly into the network. Our customers can provide secure network access to trusted users and endpoints
strategic zero trust:
through a flexible, simple solution that accelerates their value. “Zero Trust Must Include
Our key differentiators are: the Workforce, Workloads,
1. Security Resilience built into the network. Cisco 3. Unrivaled scalability. With the rise of the connected
AND Workplace”.
is the only vendor who leads in both enterprise everything, organizations need scale more than
networking and cybersecurity, and ISE builds ever before. ISE is the only solution that is proven
pervasive security directly into the network. With to support more than two million concurrent
flexibility and choice in deployment and purchasing, endpoint sessions. Visit the ISE webpage to learn
ISE enables organizations to tether secure network 4. Network admin access control. ISE is the only how we can enable your secure
access across the distributed network their way. NAC solution that includes TACACS+ for
2. Integrations and partner ecosystem. With integrated
network access initiatives, and
role-based administrative access control to
intelligence, ISE builds zero-trust policy decision networking equipment. SD Access webpage to learn
points into the network for continuous trusted access
and to automate threat containment. Effective
more about our complete secure
cyber programs require integrated technologies to access solution.
break down silos and reduce complexity. ISE has
the most extensive partner ecosystem for Cisco
Secure and third-party solutions through pxGrid and
© 2022 Cisco and/or its affiliates. All rights reserved. Cisco and the Cisco logo
pxGrid Cloud to bring a platform approach to secure are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S.
and other countries. To view a list of Cisco trademarks, go to this URL: www.
network access and zero trust. cisco.com/go/trademarks. Third-party trademarks mentioned are the property of
their respective owners. The use of the word partner does not imply a partnership
relationship between Cisco and any other company. 883227226 05/22

You might also like