Mais conteúdo relacionado
Semelhante a Accelerating Incident Response in organizations of Any Size (20)
Mais de Cisco Canada (20)
Accelerating Incident Response in organizations of Any Size
- 1. © 2017 Cisco and/or its affiliates. All rights reserved. 1
Accelerating Incident
Response in
organizations
of Any Size
Cisco
Connect
Sean Earhard
Advanced Threat Solution Specialist
October, 2017
Jean-Paul Kerouanton
Advanced Threat Solution CSE
- 3. 3© 2017 Cisco and/or its affiliates. All rights reserved.
How does your current security
infrastructure help you respond to
incidents?
- 4. 4© 2017 Cisco and/or its affiliates. All rights reserved.
ANTIVIRUS
ANTIVIRUS
Vendors pumping out update
after update after update after
update…
Firewall
Web filter
Email filter
ANTIVIRUS SERVER
consoles pumping out alert after
alert after alert after alert…
! ! ! !
- 5. 5© 2017 Cisco and/or its affiliates. All rights reserved.
Typical Incident Response workflow
- 6. 6© 2017 Cisco and/or its affiliates. All rights reserved.
INVESTIGATE
INCIDENTS
RECOVER
IMPROVE
DEFENSE
REDUCE THE
ATTACK
SURFACE
ALERTS
SECURITY
ARCHITECTURE
BLOCK
- 7. 7© 2017 Cisco and/or its affiliates. All rights reserved.
What we will show today
- 9. 9© 2017 Cisco and/or its affiliates. All rights reserved.
Email
Security
Cisco ISE
ThreatGrid
Umbrella
SIG
Cisco ISE
NextGen
Firewall
Email
Security
AMP for
Endpoints
CISCO
TALOS
AMP
AMP
AMP
AMP
Cisco ISE
Umbrella
Investigate
AMP AMP
- 10. 10© 2017 Cisco and/or its affiliates. All rights reserved.
Cisco ISE
NextGen
Firewall
Cisco ISE
Email
Security
AMP for
Endpoints
Cisco ISE
Cisco ISE
ThreatGrid
Umbrella
SIG
Cisco ISE
NextGen
Firewall
Email
Security
AMP for
Endpoints
CISCO
TALOS
AMP
AMP
AMP
AMP
Umbrella
Investigate
AMP AMP
30+ day recordedhistory=
acceleratedIR
Continuousanalysis ofthat
recordedhistory= automated
hunting
- 11. 11© 2017 Cisco and/or its affiliates. All rights reserved.
EMAIL
WEB
FIREWALL
MERAKI
UMBRELLA
THREATGRID
Blocking
AMP
AMP
COGNITIVE
THREAT
ANALYTICS
- 12. 12© 2017 Cisco and/or its affiliates. All rights reserved.
Today’s IR scenarios
- 13. 13© 2017 Cisco and/or its affiliates. All rights reserved.
Want to try it out yourself?