SlideShare a Scribd company logo
Securing the Next Generation Network and
Data Centre – Now and into the Future –
Vision, Roadmap, and Execution
B-EN-01-B
Bret Hartman
Vice President and Chief Technology Officer,
Cisco Security Business Group
Cisco and/or its affiliates. All rights reserved.Session FAQ Forum Cisco Public
House Keeping Notes – Wednesday April 16, 2014
Thank you for attending Cisco Connect Toronto 2014, here are a few
housekeeping notes to ensure we all enjoy the session today.
 Please ensure your cellphones are set on silent to ensure no one is disturbed
during the session
 Please hold all questions until the end of these session to ensure all material is
covered
2
Cisco and/or its affiliates. All rights reserved.Session FAQ Forum Cisco Public
Complete Your Paper Session Evaluation – Wednesday April 16
Give us your feedback and you could win 1 of 2
fabulous prizes in a random draw.
Complete and return your paper evaluation
form to the Room Attendant at the end of the
session.
Winners will be announced today at the end of
the session. You must be present to win!
Please visit the Concierge desk to pick up your
prize redemption slip.
Visit them at BOOTH# 407
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4
Recent Events Have Eroded Trust
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5
"We can trust the NSA
because without a doubt it is
history's most powerful,
pervasive, sophisticated
surveillance agency ever to
be totally pwned by a 29-
year-old with a thumb drive”
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6
The Industrialization of Hacking
20001990 1995 2005 2010 2015 2020
Viruses
1990–2000
Worms
2000–2005
Spyware and Rootkits
2005–Today
APTs Cyberware
Today +
Hacking Becomes
an Industry
Sophisticated Attacks,
Complex Landscape
Phishing, Low
Sophistication
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7
Any Device to Any Cloud
Public Cloud Private Cloud
Public Cloud
During the Next Generation Network and Data Centre – Now and into the Future – Vision, Roadmap and Execution
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9
The Security Problem
Changing
Business Models
Dynamic
Threat Landscape
Complexity
and Fragmentation
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10
Comprehensive Security Portfolio
IPS & NGIPS
• Cisco IPS 4300 Series
• Cisco ASA 5500-X Series
integrated IPS
Web Security
• Cisco Web Security
Appliance (WSA)
• Cisco Virtual Web Security
Appliance (vWSA)
• Cisco Cloud Web Security
Firewall & NGFW
• Cisco ASA 5500-X Series
• Cisco ASA 5500-X w/
NGFW license
• Cisco ASA 5585-X w/
NGFW blade
Advanced Malware
Protection
NAC +
Identity Services
• Cisco Identity Services
Engine (ISE)
• Cisco Access Control
Server (ACS)
Email Security
• Cisco Email Security
Appliance (ESA)
• Cisco Virtual Email
Security Appliance (vESA)
• Cisco Cloud Email
Security
• Cisco
UTM
• Meraki MX
VPN
• Cisco AnyConnect VPN
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11
The New Security Model
BEFORE
Discover
Enforce
Harden
AFTER
Scope
Contain
Remediate
Attack Continuum
Network Endpoint Mobile Virtual Cloud
Detect
Block
Defend
DURING
Point in Time Continuous
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12
Network-Integrated,
Broad Sensor Base,
Context and Automation
Continuous Advanced Threat
Protection, Cloud-Based
Security Intelligence
Agile and Open Platforms,
Built for Scale, Consistent
Control, Management
Strategic Imperatives
Network Endpoint Mobile Virtual Cloud
Visibility-Driven Threat-Focused Platform-Based
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13
Visibility-Driven
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14
Need Both Breadth and Depth
Network Endpoint Mobile Virtual Cloud
BREADTH
DEPTH
Who What Where When How
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15
Cisco Fabric Provides Pervasive Visibility
Network
Servers
Operating
Systems
Routers and
Switches
Mobile
Devices
Printers
VoIP
Phones
Virtual
Machines
Client
Applications
Files
Users
Web
Applications
Application
Protocols
Services
Malware
Command
and Control
Servers
Vulnerabilities
NetFlow
Network
Behavior
Processes
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16
?
Threat-Focused
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17
Detect, Understand, and Stop Threats
?
Collective Security
Intelligence
Threat
Identified
Event History
How
What
Who
Where
When
ISE + Network, Appliances (NGFW/NGIPS)
Context
AMP, CWS, Appliances
Recorded
Enforcement
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18
Continuous Advanced Threat Protection
ISE + Network, Appliances (NGFW/NGIPS)
How
What
Who
Where
When
Collective Security
Intelligence
AMP, CWS, Appliances
Enforcement
Event History
AMP, Threat Defense
Continuous AnalysisContext
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 19
Today’s Security Appliances
WWW
Context-
Aware
Functions
IPS
Functions
Malware
Functions
VPN
Functions
Traditional
Firewall
Functions
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20
Management
Security
Services and
Applications
Security
Services
Platform
Infrastructure
Element
Layer
Platform-Based Security Architecture
Common Security Policy & Management
Common Security Policy and Management
Orchestration
Security
Management APIs
Cisco ONE
APIs
Platform
APIs
Cloud Intelligence
APIs
Physical Appliance Virtual Cloud
Access
Control
Context
Awareness
Content
Inspection
Application
Visibility
Threat
Prevention
Device API: OnePK™, OpenFlow, CLI
Cisco Networking Operating Systems (Enterprise, Data Center, Service Provider)
Route–Switch–ComputeASIC Data Plane Software Data Plane
APIs APIs
Cisco Security Applications Third-Party Security Applications
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21
The Security Perimeter in the Cloud
The
Distributed
Perimeter
Cloud
Connected
Network
Collective
Security
Intelligence
Telemetry Data Threat Research Advanced Analytics
Mobile Router Firewall
3M+
Cloud Web
Security Users
6 GB
Web Traffic
Examined,
Protected
Every Hour
75M
Unique Hits
Every Hour
10M
Blocks Enforced
Every Hour
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22
Develop Ecosystems for Cisco Security
Cisco Current
Partner Ecosystem
Mobility (MDM), Threat (SIEM), Cloud
Partner to Deliver Complete Solutions
Open Platform Architecture Enables
Develop SSP Partner Ecosystem
ISE as “Context Directory Service”
Embed Security in Broader IT Solutions
Lancope, Network as a Sensor
Drive the Value of the Network
© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25
Visibility and Context
Firewall
NGFW
NAC + Identity Services
VPN
UTM
NGIPS
Web Security
Email Security
Advanced Malware Protection
Network Behavior Analysis
Covering the Entire Attack Continuum
BEFORE
Discover
Enforce
Harden
AFTER
Scope
Contain
Remediate
Attack Continuum
Detect
Block
Defend
DURING
Questions?
26
During the Next Generation Network and Data Centre – Now and into the Future – Vision, Roadmap and Execution

More Related Content

PDF
TechWiseTV Workshop: Encrypted Traffic Analytics
PDF
AHMED+MORSY+ABD+EL+BAKI+v1.1+updated+2016
PDF
Considerations for a secure enterprise wlan data connectors 2013
PPTX
Cisco Connect 2018 Indonesia - Cybersecurity Strategy
PPTX
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
PDF
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformation
PDF
[Cisco Connect 2018 - Vietnam] Brian cotaz cyber security strategy
PPTX
Call for Papers - International Journal of Network Security & Its Application...
TechWiseTV Workshop: Encrypted Traffic Analytics
AHMED+MORSY+ABD+EL+BAKI+v1.1+updated+2016
Considerations for a secure enterprise wlan data connectors 2013
Cisco Connect 2018 Indonesia - Cybersecurity Strategy
Cisco Connect 2018 Indonesia - software-defined access-a transformational ap...
Cisco Connect 2018 Malaysia - SDNNFV telco data center transformation
[Cisco Connect 2018 - Vietnam] Brian cotaz cyber security strategy
Call for Papers - International Journal of Network Security & Its Application...

What's hot (18)

DOCX
PPT
Windows 7 - A New Wireless Risk to the Enterprise
PPTX
Ccna security
PDF
Samsung and Android Security brochure
PPTX
BYOD without Compromise
PPTX
DSS ITSEC 2013 Conference 07.11.2013 - HeadTechnology - IT security trends 2014
PDF
Cisco Connect 2018 Vietnam - data center transformation - vn
PDF
Cisco Connect 2018 Malaysia - Cisco services-guiding your digital transformation
PDF
UL TS - CSA NL SUMMIT
PPTX
i7 pregerine7 - Agentless byod security for Enterprises
PPTX
Signature Presentation(10062011) Vc 3 Full
PDF
Integra Customer Presentation
PDF
Webinar: Secure Offline and Online Updates for Linux Devices
PDF
Mạng chuyển mạch thế hệ mới
PDF
BlockchainLAB Hackathon
PPTX
Next-generation Zero Trust Cybersecurity for the Space Age
PDF
Zero Day Plus Anti Malware LTD 2016 sales pdf
DOC
Vikash_mani
Windows 7 - A New Wireless Risk to the Enterprise
Ccna security
Samsung and Android Security brochure
BYOD without Compromise
DSS ITSEC 2013 Conference 07.11.2013 - HeadTechnology - IT security trends 2014
Cisco Connect 2018 Vietnam - data center transformation - vn
Cisco Connect 2018 Malaysia - Cisco services-guiding your digital transformation
UL TS - CSA NL SUMMIT
i7 pregerine7 - Agentless byod security for Enterprises
Signature Presentation(10062011) Vc 3 Full
Integra Customer Presentation
Webinar: Secure Offline and Online Updates for Linux Devices
Mạng chuyển mạch thế hệ mới
BlockchainLAB Hackathon
Next-generation Zero Trust Cybersecurity for the Space Age
Zero Day Plus Anti Malware LTD 2016 sales pdf
Vikash_mani
Ad

Viewers also liked (20)

PPTX
The Seven deadly sins of approval
PPTX
Deloitte Data Blitz
PDF
SAP Big Data Tour
PPTX
Sun Ray diagram
PPTX
McKinsey Big Data Overview
PDF
TNR2013 David Rock, The Neuroscience of Engagement
PDF
Accenture Case Competition 2010
PPTX
In-Memory Computing with SAP HANA™
PPT
Emerging giants
PDF
Lightning talk Accenture
PDF
McKinsey Global Institute - Big data: The next frontier for innovation, compe...
PDF
5 reasons why leaders fail | London Business School
PPTX
Polymorphism of Agile Project and Program Managers
PDF
Curse of the Benchmarks
PDF
Dr Harvey Lewis - Trends in Big Data, Key Challenges for Skills
PPTX
Developing a Road Map and Business Case – Deloitte Sponsor Session
PDF
Deloitte & Mulesoft : The Right Mix
PDF
Dev ops in agile - 1st Conference Melbourne
PDF
7 Deadly Sins of Agile Software Test Automation
PDF
AGILE@DELOITTE AGILE LANDSCAPE v02
The Seven deadly sins of approval
Deloitte Data Blitz
SAP Big Data Tour
Sun Ray diagram
McKinsey Big Data Overview
TNR2013 David Rock, The Neuroscience of Engagement
Accenture Case Competition 2010
In-Memory Computing with SAP HANA™
Emerging giants
Lightning talk Accenture
McKinsey Global Institute - Big data: The next frontier for innovation, compe...
5 reasons why leaders fail | London Business School
Polymorphism of Agile Project and Program Managers
Curse of the Benchmarks
Dr Harvey Lewis - Trends in Big Data, Key Challenges for Skills
Developing a Road Map and Business Case – Deloitte Sponsor Session
Deloitte & Mulesoft : The Right Mix
Dev ops in agile - 1st Conference Melbourne
7 Deadly Sins of Agile Software Test Automation
AGILE@DELOITTE AGILE LANDSCAPE v02
Ad

Similar to During the Next Generation Network and Data Centre – Now and into the Future – Vision, Roadmap and Execution (20)

PDF
Cisco Live Cancun PR Session
PDF
Next Generation Security
PPTX
Scalar Security Roadshow - Vancouver Presentation
PPTX
Scalar Security Roadshow - Calgary Presentation
PDF
The Network as a Sensor, Cisco and Lancope
PDF
BGA SOME/SOC Etkinliği - Tehdit Odaklı Güvenlik Mimarisinde Sourcefire Yakla...
PDF
Proteja seus clientes - Gerenciamento dos Serviços de Segurança
PPTX
Two for Attack: Web and Email Content Protection
PDF
Network as a sensor
PDF
Scalar Security Roadshow - Toronto Presentation
PDF
The Next Generation Security
PDF
Using Your Network as a Sensor for Enhanced Visibility and Security
PPTX
Idc security roadshow may2015 Adrian Aron
PDF
Building a Security Architecture
PPTX
Isday 2017 - Atelier Cisco
PDF
Protegendo sua rede
PPTX
Network Security v1.0 - Module 1.pptx
PDF
Advanced Web Security Deployment
PPTX
apl5iy2ftxiwofbhsmxj-signature-584e2459f99b5370bda435f09b42cc84cc8c063b8cd454...
PDF
Cisco Content Security
Cisco Live Cancun PR Session
Next Generation Security
Scalar Security Roadshow - Vancouver Presentation
Scalar Security Roadshow - Calgary Presentation
The Network as a Sensor, Cisco and Lancope
BGA SOME/SOC Etkinliği - Tehdit Odaklı Güvenlik Mimarisinde Sourcefire Yakla...
Proteja seus clientes - Gerenciamento dos Serviços de Segurança
Two for Attack: Web and Email Content Protection
Network as a sensor
Scalar Security Roadshow - Toronto Presentation
The Next Generation Security
Using Your Network as a Sensor for Enhanced Visibility and Security
Idc security roadshow may2015 Adrian Aron
Building a Security Architecture
Isday 2017 - Atelier Cisco
Protegendo sua rede
Network Security v1.0 - Module 1.pptx
Advanced Web Security Deployment
apl5iy2ftxiwofbhsmxj-signature-584e2459f99b5370bda435f09b42cc84cc8c063b8cd454...
Cisco Content Security

More from Cisco Canada (20)

PDF
Cisco connect montreal 2018 net devops
PDF
Cisco connect montreal 2018 iot demo kinetic fr
PPTX
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
PDF
Cisco connect montreal 2018 secure dc
PDF
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
PDF
Cisco connect montreal 2018 vision mondiale analyse locale
PDF
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
PDF
Cisco connect montreal 2018 collaboration les services webex hybrides
PDF
Integration cisco et microsoft connect montreal 2018
PDF
Cisco connect montreal 2018 compute v final
PDF
Cisco connect montreal 2018 saalvare md-program-xr-v2
PDF
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
PDF
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
PDF
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
PDF
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
PDF
Cisco Connect Toronto 2018 DevNet Overview
PDF
Cisco Connect Toronto 2018 DNA assurance
PDF
Cisco Connect Toronto 2018 network-slicing
PDF
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
PDF
Cisco Connect Toronto 2018 sixty to zero
Cisco connect montreal 2018 net devops
Cisco connect montreal 2018 iot demo kinetic fr
Cisco connect montreal 2018 - Network Slicing: Horizontal Virtualization
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018 enterprise networks - say goodbye to vla ns
Cisco connect montreal 2018 vision mondiale analyse locale
Cisco Connect Montreal 2018 Securité : Sécuriser votre mobilité avec Cisco
Cisco connect montreal 2018 collaboration les services webex hybrides
Integration cisco et microsoft connect montreal 2018
Cisco connect montreal 2018 compute v final
Cisco connect montreal 2018 saalvare md-program-xr-v2
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 an introduction to Cisco kinetic
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 DevNet Overview
Cisco Connect Toronto 2018 DNA assurance
Cisco Connect Toronto 2018 network-slicing
Cisco Connect Toronto 2018 the intelligent network with cisco meraki
Cisco Connect Toronto 2018 sixty to zero

Recently uploaded (20)

PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Approach and Philosophy of On baking technology
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Electronic commerce courselecture one. Pdf
PDF
KodekX | Application Modernization Development
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Empathic Computing: Creating Shared Understanding
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Approach and Philosophy of On baking technology
The Rise and Fall of 3GPP – Time for a Sabbatical?
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Electronic commerce courselecture one. Pdf
KodekX | Application Modernization Development
Advanced methodologies resolving dimensionality complications for autism neur...
MYSQL Presentation for SQL database connectivity
Mobile App Security Testing_ A Comprehensive Guide.pdf
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Reach Out and Touch Someone: Haptics and Empathic Computing
Spectral efficient network and resource selection model in 5G networks
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
“AI and Expert System Decision Support & Business Intelligence Systems”
Empathic Computing: Creating Shared Understanding
Review of recent advances in non-invasive hemoglobin estimation
20250228 LYD VKU AI Blended-Learning.pptx
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
Build a system with the filesystem maintained by OSTree @ COSCUP 2025

During the Next Generation Network and Data Centre – Now and into the Future – Vision, Roadmap and Execution

  • 1. Securing the Next Generation Network and Data Centre – Now and into the Future – Vision, Roadmap, and Execution B-EN-01-B Bret Hartman Vice President and Chief Technology Officer, Cisco Security Business Group
  • 2. Cisco and/or its affiliates. All rights reserved.Session FAQ Forum Cisco Public House Keeping Notes – Wednesday April 16, 2014 Thank you for attending Cisco Connect Toronto 2014, here are a few housekeeping notes to ensure we all enjoy the session today.  Please ensure your cellphones are set on silent to ensure no one is disturbed during the session  Please hold all questions until the end of these session to ensure all material is covered 2
  • 3. Cisco and/or its affiliates. All rights reserved.Session FAQ Forum Cisco Public Complete Your Paper Session Evaluation – Wednesday April 16 Give us your feedback and you could win 1 of 2 fabulous prizes in a random draw. Complete and return your paper evaluation form to the Room Attendant at the end of the session. Winners will be announced today at the end of the session. You must be present to win! Please visit the Concierge desk to pick up your prize redemption slip. Visit them at BOOTH# 407
  • 4. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4 Recent Events Have Eroded Trust
  • 5. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5 "We can trust the NSA because without a doubt it is history's most powerful, pervasive, sophisticated surveillance agency ever to be totally pwned by a 29- year-old with a thumb drive”
  • 6. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6 The Industrialization of Hacking 20001990 1995 2005 2010 2015 2020 Viruses 1990–2000 Worms 2000–2005 Spyware and Rootkits 2005–Today APTs Cyberware Today + Hacking Becomes an Industry Sophisticated Attacks, Complex Landscape Phishing, Low Sophistication
  • 7. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7 Any Device to Any Cloud Public Cloud Private Cloud Public Cloud
  • 9. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9 The Security Problem Changing Business Models Dynamic Threat Landscape Complexity and Fragmentation
  • 10. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10 Comprehensive Security Portfolio IPS & NGIPS • Cisco IPS 4300 Series • Cisco ASA 5500-X Series integrated IPS Web Security • Cisco Web Security Appliance (WSA) • Cisco Virtual Web Security Appliance (vWSA) • Cisco Cloud Web Security Firewall & NGFW • Cisco ASA 5500-X Series • Cisco ASA 5500-X w/ NGFW license • Cisco ASA 5585-X w/ NGFW blade Advanced Malware Protection NAC + Identity Services • Cisco Identity Services Engine (ISE) • Cisco Access Control Server (ACS) Email Security • Cisco Email Security Appliance (ESA) • Cisco Virtual Email Security Appliance (vESA) • Cisco Cloud Email Security • Cisco UTM • Meraki MX VPN • Cisco AnyConnect VPN
  • 11. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11 The New Security Model BEFORE Discover Enforce Harden AFTER Scope Contain Remediate Attack Continuum Network Endpoint Mobile Virtual Cloud Detect Block Defend DURING Point in Time Continuous
  • 12. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12 Network-Integrated, Broad Sensor Base, Context and Automation Continuous Advanced Threat Protection, Cloud-Based Security Intelligence Agile and Open Platforms, Built for Scale, Consistent Control, Management Strategic Imperatives Network Endpoint Mobile Virtual Cloud Visibility-Driven Threat-Focused Platform-Based
  • 13. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13 Visibility-Driven
  • 14. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14 Need Both Breadth and Depth Network Endpoint Mobile Virtual Cloud BREADTH DEPTH Who What Where When How
  • 15. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15 Cisco Fabric Provides Pervasive Visibility Network Servers Operating Systems Routers and Switches Mobile Devices Printers VoIP Phones Virtual Machines Client Applications Files Users Web Applications Application Protocols Services Malware Command and Control Servers Vulnerabilities NetFlow Network Behavior Processes
  • 16. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16 ? Threat-Focused
  • 17. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17 Detect, Understand, and Stop Threats ? Collective Security Intelligence Threat Identified Event History How What Who Where When ISE + Network, Appliances (NGFW/NGIPS) Context AMP, CWS, Appliances Recorded Enforcement
  • 18. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18 Continuous Advanced Threat Protection ISE + Network, Appliances (NGFW/NGIPS) How What Who Where When Collective Security Intelligence AMP, CWS, Appliances Enforcement Event History AMP, Threat Defense Continuous AnalysisContext
  • 19. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 19 Today’s Security Appliances WWW Context- Aware Functions IPS Functions Malware Functions VPN Functions Traditional Firewall Functions
  • 20. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20 Management Security Services and Applications Security Services Platform Infrastructure Element Layer Platform-Based Security Architecture Common Security Policy & Management Common Security Policy and Management Orchestration Security Management APIs Cisco ONE APIs Platform APIs Cloud Intelligence APIs Physical Appliance Virtual Cloud Access Control Context Awareness Content Inspection Application Visibility Threat Prevention Device API: OnePK™, OpenFlow, CLI Cisco Networking Operating Systems (Enterprise, Data Center, Service Provider) Route–Switch–ComputeASIC Data Plane Software Data Plane APIs APIs Cisco Security Applications Third-Party Security Applications
  • 21. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21 The Security Perimeter in the Cloud The Distributed Perimeter Cloud Connected Network Collective Security Intelligence Telemetry Data Threat Research Advanced Analytics Mobile Router Firewall 3M+ Cloud Web Security Users 6 GB Web Traffic Examined, Protected Every Hour 75M Unique Hits Every Hour 10M Blocks Enforced Every Hour
  • 22. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22 Develop Ecosystems for Cisco Security Cisco Current Partner Ecosystem Mobility (MDM), Threat (SIEM), Cloud Partner to Deliver Complete Solutions Open Platform Architecture Enables Develop SSP Partner Ecosystem ISE as “Context Directory Service” Embed Security in Broader IT Solutions Lancope, Network as a Sensor Drive the Value of the Network
  • 23. © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25 Visibility and Context Firewall NGFW NAC + Identity Services VPN UTM NGIPS Web Security Email Security Advanced Malware Protection Network Behavior Analysis Covering the Entire Attack Continuum BEFORE Discover Enforce Harden AFTER Scope Contain Remediate Attack Continuum Detect Block Defend DURING