<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE prescriptive guide for IOT in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-prescriptive-guide-for-iot/m-p/4312733#M566383</link>
    <description>&lt;P&gt;Is there a prescriptive guide on ISE for IOT devices ?&lt;/P&gt;</description>
    <pubDate>Wed, 24 Mar 2021 04:18:06 GMT</pubDate>
    <dc:creator>damode</dc:creator>
    <dc:date>2021-03-24T04:18:06Z</dc:date>
    <item>
      <title>ISE prescriptive guide for IOT</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prescriptive-guide-for-iot/m-p/4312733#M566383</link>
      <description>&lt;P&gt;Is there a prescriptive guide on ISE for IOT devices ?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 04:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prescriptive-guide-for-iot/m-p/4312733#M566383</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2021-03-24T04:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE prescriptive guide for IOT</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prescriptive-guide-for-iot/m-p/4313035#M566396</link>
      <description>&lt;P&gt;Link for ISE/NAC resources:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-amp-nac-resources/ta-p/3621621#Design" target="_blank"&gt;Cisco ISE &amp;amp; NAC Resources - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 12:15:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prescriptive-guide-for-iot/m-p/4313035#M566396</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-03-24T12:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE prescriptive guide for IOT</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-prescriptive-guide-for-iot/m-p/4313494#M566410</link>
      <description>&lt;P&gt;No prescriptive guide - It's really a process depending on your tools, environment (IT, OT, your specific vertical) and politics (Layer 8!). The Prescription is to identify and minimize (eliminate!) all unknown endpoints using whatever you've got (or can afford). Identify the areas you believe present the biggest risk(s) to the business and start there.&lt;/P&gt;
&lt;P&gt;You will never have 100% automation. Just because you know &lt;STRONG&gt;What&lt;/STRONG&gt; something is (according to a tool) doesn't tell you &lt;STRONG&gt;Who&lt;/STRONG&gt; owns it, exactly &lt;STRONG&gt;Where&lt;/STRONG&gt; it is located, &lt;STRONG&gt;When&lt;/STRONG&gt; it was put there, or &lt;STRONG&gt;Why&lt;/STRONG&gt; it is there at all. There will still be a strong need for some sort of asset management database or registration tool for various department owners or even individuals to add, update and maintain inventories of devices. &lt;/P&gt;
&lt;P&gt;From top to bottom, more automation to least automation.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ISE Profiles and Profiling Libraries
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-automation-and-control-profile-library-v1-0/ta-p/3637957" target="_self"&gt;Automation &amp;amp; Control Profiles&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-industrial-network-director-ind-iot-profile-library-v1/ta-p/3638113" target="_self"&gt;Industrial Network Director (IND) Profile Library&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-medical-nac-profile-library-v2-0/ta-p/3638736" target="_self"&gt;Medical NAC Profiles&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-windows-workstation-embedded-iot-profile-library-v1-0/ta-p/3637975" target="_self"&gt;Windows Embedded Profiles&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Traffic based analytics
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/networking-documents/cisco-ai-endpoint-analytics-deployment-guide/ta-p/4266702" target="_self"&gt;Endpoint Analytics&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.cisco.com/c/en/us/products/cloud-systems-management/industrial-network-director/index.html" target="_self"&gt;Industrial Network Director&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.cisco.com/c/en/us/products/security/cyber-vision/index.html" target="_self"&gt;Cybervision&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.cisco.com/go/stealthwatch" target="_self"&gt;Stealthwatch&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216128-cisco-ise-ecosystem-partner-integration.html" target="_self"&gt;Cisco Security Technology Partners&lt;/A&gt; (using pxGrid to share context-in)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Analysis of ISE Endpoint attribute database - using Excel or EAT tool (&lt;A href="https://iseeat.cisco.com" target="_self"&gt;iseeat.cisco.com&lt;/A&gt;) - to build your own custom profiles&lt;/LI&gt;
&lt;LI&gt;Existing sources of truth that may either push to &lt;A href="https://community.cisco.com/t5/security-documents/ise-ers-api-examples/ta-p/3622623#toc-hId--972098705" target="_self"&gt;ISE via REST APIs&lt;/A&gt; or ISE may query (LDAP, SQL) for MAB authorization:&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;Network Tools&lt;/LI&gt;
&lt;LI&gt;CMDB&lt;/LI&gt;
&lt;LI&gt;Existing network inventory / asset management database&lt;/LI&gt;
&lt;LI&gt;Control Systems&lt;/LI&gt;
&lt;LI&gt;custom device registration systems&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;ISE Device Registration Portal for BYOD devices&lt;/LI&gt;
&lt;LI&gt;Direct Inspection (trace the cable!)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/107261iBADD13452AC86B7E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 00:51:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-prescriptive-guide-for-iot/m-p/4313494#M566410</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-03-25T00:51:03Z</dc:date>
    </item>
  </channel>
</rss>

