CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and...

12
CISCO ZERO TRUST A COMPREHENSIVE APPROACH TO SECURE ACCESS FOR YOUR WORKFORCE, WORKLOADS, AND WORKPLACE © 2019 Cisco and/or its affiliates. All rights reserved.

Transcript of CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and...

Page 1: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

CISCO ZERO TRUSTA COMPREHENSIVE APPROACH TO SECURE ACCESS FOR YOUR WORKFORCE, WORKLOADS, AND WORKPLACE

© 2019 Cisco and/or its affi liates. All rights reserved.

Page 2: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

Modern enterprise challengesThere’s been a shift in the IT landscape—users, devices, and the cloud has moved control and visibility outside of the traditional network. As a result, there’s increased points of access, a larger attack surface, and more gaps in visibility.

Traditional security approach Zero-trust approach

Trust: Based on network location that an access request is coming from

As a result:• Attackers can move laterally to get to

an organization’s crown jewels• It doesn’t extend security to the

new perimeter

Trust: Established for every access request, regardless of where the request is coming from

As a result:• Secures access across your applications

and network• Ensures only the right users and devices

have access• Extends trust to support Bring Your

Own Device (BYOD), cloud apps, hybrid environments, and more

Cisco® Zero Trust is a comprehensive approach to securing all access across your networks, applications, and environment. It helps secure access from users, end-user devices, APIs, the Internet of Things (IoT), microservices, containers, and more.

2 © 2019 Cisco and/or its affi liates. All rights reserved.

Page 3: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

Zero Trust for the workforceEnsure only the right users and secure devices can access applications.

Duo Security: • Verifies users’ identities with MultiFactor

Authentication (MFA)• Allows you to gain device visibility and

establish trust with endpoint health and management status

• Enables you to enforce access policies for every app with adaptive and role-based access controls

Learn about Duo Security

Zero Trust for workloadsSecure all connections within your apps, across multicloud.

Cisco Tetration:• Gives you visibility into what’s running and

what’s critical by identifying workloads and enforcing policies

• Allows you to contain breaches and minimize lateral movement with application microsegmentation

• Alerts you or blocks communication in case of a policy violation by continuously monitoring and responding to indicators of compromise

Learn about Tetration

Zero Trust for the workplaceSecure all user and device connections across your network, including IoT.

Software-Defined (SD) Access:• Grants the right level of network access to

users and devices with network authentication and authorization

• Classifies and segments users, devices, and applications on your network with network segmentation

• Contains infected endpoints and revokes network access by continuously monitoring and responding to threats

Learn about SD-Access

Cisco Zero TrustSecure access across your applications and environment, from any user, device, and location.

Cisco Zero Trust allows you to:

• Consistently enforce policy-based controls• Gain visibility into users, devices, components, and more across your entire environment• Get detailed logs, reports, and alerts that can help you better detect and respond to threatsProvide more secure access, protect against gaps in visibility, and reduce your attack surface with Cisco Zero Trust.

Learn about Duo Securityhttps://duo.com/

Learn about Tetrationhttps://www.cisco.com/c/en/us/products/data-center-analytics/tetration-analytics/index.html

Learn about SD-Accesshttps://www.cisco.com/c/en/us/solutions/enterprise-networks/software-defi ned-access/index.html

3© 2019 Cisco and/or its affi liates. All rights reserved.

Page 4: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

© 0 9 C sco a d/o ts a ates g ts ese ed

Extend trustCisco Advanced Malware Protection (AMP)Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and remove malware.

Cisco Umbrella™Get visibility to protect Internet access across all devices on your network, all office locations, and roaming users.

Next-Generation FirewallsWith deep network and security visibility, you can detect and stop threats fast before they reach your workforce, workloads, and workplace.

AnyConnect®Provide secure access to the workforce and workplace, as well as more insight into user and endpoint behavior across your entire enterprise.

Email SecurityDefend against data loss and encrypt sensitive information with Cisco Email Security to protect against phishing, business email compromise, and ransomware.

Meraki® Systems ManagerUnified device management and control of mobile and desktop devices, allowing for seamless onboarding and automated application of security policies.

ACIApplication-Centric Infrastructure (ACI) allows for consistent, policy-based automation for connectivity and segmentation across on-premises and cloud.

Extended protectionDuo, Tetration, and SD-Access are the three primary products for workforce, workload, and workplace security. Cisco Zero Trust also integrates with a larger ecosystem of other products to provide complete zero-trust security for any enterprise.

Detect and respondCisco Stealthwatch®Find out who is on your network and what they are doing using network infrastructure telemetry. Detect threats and respond to them quickly with a scalable solution.

Cisco Threat ResponseAutomate integrations across Cisco security products to accelerate detection, investigation, and remediation.

4 © 2019 Cisco and/or its affi liates. All rights reserved.

Page 5: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

Extend to any integrationOur technical partnerships make it easy to integrate security with your existing platforms.

Any endpoint management platform Any infrastructure platform Any third party

Protect any endpoint management platform and integrate with Microsoft, Symantec, VMware, MobileIron, Jamf, and more.

Integrate with any infrastructure platform, such as Google, Kubernetes, Microsoft Azure, Amazon Web Services (AWS), VMware, and more.

Work with third parties like identity providers and Security Information and Event Management (SIEM) systems such as Exabeam, Okta, Splunk, IBM, Google, Dell, Ping Identity, Oracle, and others.

Learn more about Cisco partners > Duo partners > Duo integrationsLearn more about Cisco partners https://www.cisco.com/c/m/en_us/products/security/technical-alliance-partners.html

Learn more about Duo partners https://duo.com/partners

Learn more about Duo integrations https://duo.com/partners

5© 2019 Cisco and/or its affi liates. All rights reserved.

Page 6: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

Cisco Umbrella at a glance

Enterprise security and networking are facing a signifi cant transformation. Wide-scale adoption of cloud applications, an increase in remote workers, and expansion of branch offi ces has rendered the centralized, on-premises security model impractical. The convenience, cost savings, and performance benefi ts of going direct to the internet is driving a new decentralized approach to networking. Yet with change comes risk and a new set of security challenges. Organizations require a broader set of protection that not only improves security, but simplifi es management.

Integrated security from the cloud

Cisco Umbrella is a cloud-native platform that delivers the most secure, reliable, and fastest internet experience to more than 100 million users daily. Umbrella unifi es fi rewall, secure web gateway, DNS-layer security, cloud access security broker (CASB), and threat intelligence solutions into a single platform to help businesses of all sizes secure their network. As more organizations embrace direct internet access, Umbrella makes it easy to extend protection to roaming users and branch offi ces.

Better intelligence drives better security

Leveraging insights from Cisco Talos, one of the world’s largest commercial threat intelligence teams with more than 300 researchers, Umbrella uncovers and blocks a broad spectrum of malicious domains, IPs, URLs, and fi les that are being used in attacks. We also feed huge volumes of global internet activity into a combination of statistical and machine learning models to identify new attacks being staged on the internet.

Key benefi ts• Broad, reliable security coverage

across all ports and protocols

• Security protection on and off network

• Rapid deployment and fl exible enforcement levels

• Immediate value and low total cost of ownership

• Single dashboard for effi cient management

6 © 2019 Cisco and/or its affi liates. All rights reserved.

Page 7: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

Block malware easily

Built into the foundation of the internet, Umbrella processes 180 billion internet requests for more than 18,500 businesses every day. By enforcing security at the DNS and IP layers, Umbrella blocks requests to malware, ransomware, phishing, and botnets before a connection is even established — before they reach your network or endpoints. The cloud-delivered secure web gateway logs and inspects all web traffi c for greater transparency, control, and protection. The cloud-delivered fi rewall helps to log and block traffi c using IP, port, and protocol rules for consistent enforcement throughout your environment.

Speed up and improve incident response

Umbrella categorizes and retains all internet activity to simplify your investigation process and reduce incident response times. And, by using the Umbrella Investigate console and on-demand enrichment API, you have access to insights (historical and contextual) to prioritize incidents and speed up incident response. Plus, it easily integrates with other intelligence sources and security orchestration tools for better management.

Security Challenges

Gaps in visibility and coverage

Volume and complexity of security tools

Limited budgets and security resources

7© 2019 Cisco and/or its affi liates. All rights reserved.

Page 8: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

The Umbrella DNS Security Essentials package

includes core DNSlayer security capabilities, to block requests to malicious domains before they reach your network or endpoints. You gain off -network protection and mobile support in this base package, as well as access to Umbrella’s APIs (policy, reporting and enforcement), log exporting, the multi-org console, integration with Cisco Threat Response, and identity-based policies (virtual appliance + Active Directory connector). Additionally, this package provides discovery and blocking of shadow IT (by domain) with the App Discovery report.

The Umbrella DNS Security Advantage

package includes all the capabilities of DNS Security Essentials plus it enables organizations to proxy risky domains for URL blocking and fi le inspection using AV engines and Cisco AMP. For organizations looking for deeper context during incident investigations, DNS Security Advantage off ers unmatched threat intelligence in the Investigate console and on-demand enrichment API.

The Umbrella SIG Essentials package includes all of the capabilities of the DNS Security Advantage package plus access to a secure web gateway (full proxy), cloud-delivered fi rewall, sandbox fi le analysis with Cisco Threat Grid, and cloud access security broker (CASB) functionality. With a single, cloud platform, you can combine multiple security services and threat intelligence to secure your network and remote and roaming users with confi dence. Simplify management and get visibility to control and manage apps, anywhere.

Packaging OptionsOur packages were designed to provide the right fi t for all organizations. From small businesses without dedicated security professionals to multinational enterprises with complex environments, Umbrella provides more eff ective security and internet-wide visibility on and off your network. All packages can be integrated with your Cisco SD-WAN implementation to provide a combination of performance, security, and fl exibility that delights both your end users and security team.

Analyst and customer validationSee why Umbrella was named best secure web gateways software of 2019.

Read the reviews:

https://need.a.urltiny.for.this.link

Access direct research from

TechValidate customers:

https://www.techvalidate.com/product-research/cisco-umbrella/facts

8 © 2019 Cisco and/or its affi liates. All rights reserved.

Page 9: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

The Umbrella AdvantageUmbrella has a highly resilient cloud infrastructure that boasts 100% uptime since 2006. Using Anycast routing, any of our 30 plus data centers across the globe are available using the same single IP address. As a result, your requests are transparently sent to the nearest, fastest data center and failover is automatic.

Umbrella peers with more than 900 of the world’s top internet service providers (ISPs), content delivery networks (CDNs) and SaaS platforms to deliver the fastest route for any request — resulting in superior speed, eff ective security and the best user satisfaction.

Take the next stepRequest a demo or speak with sales representative about how Cisco Umbrella can help you defend against threat on the internet.

Visit signup.umbrella.com for a free 14 day trial of Umbrella.

9© 2019 Cisco and/or its affi liates. All rights reserved.

Page 10: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

Simple

AgileEconomical

Device reporting*, post-paid consumption based contract for SPs

Managed Service Provider

Freely move up and down product tiers and across functional offers

No up-front cost for software in the building of service offerings

Grow your Managed Services Practice with Umbrella MSP on MSLA!No up-front commitment with monthly postpaid billing, based on consumption.

Contact us now for more information!

Email: [email protected]

Broadest protections for businesses

10 © 2019 Cisco and/or its affi liates. All rights reserved.

Page 11: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

Team Details Cisco Account Management Team

Contact for [email protected]

Cisco Operations Team

Order placement & ETA [email protected]

Online Teams

Webexweb.ciscospark.com/signin

Skypelogin.skype.com/login?message=signin_continue

Ingram Micro Resources Cisco Engage

Partner focused platform with Cisco resources, events, training and sales enablement toolsingramciscoengage.com.au

Ingram Micro Partner Central

The one-stop source for all Ingram vendors, promotions and events ingrampartnercentral.com.au

IM Cloud Marketplace

Ingram Micro Cloud’s end-to-end cloud platform solutionsingrammicrocloud.com/au/en/

Ingram Micro Online

Ingram’s E-Commerce Site au.ingrammicro.com

Ingram Finance (ITaaS)

Ingram Technology as a Service. Allow resellers to bundle product & services on a single monthly billhttps://ingrampartnercentral.com.au/tools/services

Cisco Annuity Tracker

Stay on top of your Cisco Renewalsingrampartnercentral.com.au/tools/annuity-tracker

Cisco Resources Cisco SNAP

Sales New Hire Acceleration Program for Partnerssalesconnect.cisco.com/#/program/PAGE-1313

Cisco Partner Program Enrolment

Access to NFR, Refresh and other Cisco Rebate Programscisco.com/go/ppe

Cisco TPV

Total Portal Viewtpv.cloudapps.cisco.com/dashboard/scorecard.jsp

Cisco Support:

CCW issues or other “Back offi ce” Cisco [email protected]

Cisco SaaS Enablement

To know more about Cisco SaaS Off eringssalesconnect.cisco.com/#/briefcasedetails/137024

Cisco Refresh:

Fully Certifi ed Remanufactured Cisco equipmentcisco.com/c/en/us/products/remanufactured.html

Cisco Smart Accounts

Everything you need to know about smart accountscisco.com/c/en/us/products/software/smart-accounts.html

Partner Welcome KitFind the information you need to get up and running with Ingram Micro. From quotes to accessing your resources, to fi nancial solution – fi nd it all in your Ingram & Cisco Partner Kit.

11© 2019 Cisco and/or its affi liates. All rights reserved.© 2019 Cisco and/or its affi liates. All rights reserved. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affi liates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks.Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R)v

Page 12: CISCO ZERO TRUST...Cisco Advanced Malware Protection (AMP) Protect your endpoints, network, and email with AMP. Get deep visibility into network and endpoint threats, and block and

© 2019 Cisco and/or its affi liates. All rights reserved.