Constructing community and workload safety architectures generally is a daunting process. It includes not solely selecting the best answer with the suitable set of capabilities, but in addition making certain that the options supply the best degree of resilience.
Resilience is commonly thought-about a community perform, the place the community should be sturdy sufficient to deal with failures and supply alternate paths for transmitting and receiving information. Nevertheless, resilience on the endpoint or workload degree is incessantly neglected. As a part of constructing a resilient structure, it’s important to incorporate and plan for situations wherein the endpoint or workload answer would possibly fail.
Once we study the present panorama of options, it often boils down to 2 completely different approaches:
Agent-Based mostly Approaches
When selecting a safety answer to guard software workloads, the dialogue usually revolves round mapping enterprise necessities to technical capabilities. These capabilities usually embrace security measures corresponding to microsegmentation and runtime visibility. Nevertheless, one facet that’s usually neglected is the agent structure.
Usually, there are two foremost approaches to agent-based architectures:
- Userspace putting in Kernel-Based mostly Modules/Drivers (in-datapath)
- Userspace clear to the Kernel (off-datapath)
Safe Workload’s agent structure was designed from the bottom as much as defend software workloads, even within the occasion of an agent malfunction, thus stopping crashes within the software workloads.
This robustness is because of our agent structure, which operates utterly in userspace with out affecting the community datapath or the applying libraries. Subsequently, if the agent have been to fail, the applying would proceed to perform as regular, avoiding disruption to the enterprise.
One other facet of the agent structure is that it was designed to provide directors management over how, when, and which brokers they wish to improve by leveraging configuration profiles. This strategy offers the pliability to roll out upgrades in a staged trend, permitting for obligatory testing earlier than going into manufacturing.
Agentless-Based mostly Approaches
The easiest way to guard your software workloads is undoubtedlythrough an agent-based strategy, because it yields the most effective outcomes. Nevertheless, there are cases the place putting in an agent shouldn’t be doable.
The principle drivers for selecting agentless options usually relate to organizational dependencies (e.g., cross-departmental collaboration), or in sure instances, the applying workload’s working system is unsupported (e.g., legacy OS, customized OS).
When choosing agentless options, it’s essential to know the constraints of those approaches. For example, with out an agent, it isn’t doable to realize runtime visibility of software workloads.
However, the chosen answer should nonetheless present the mandatory security measures, corresponding to complete community visibility of site visitors flows and community segmentation to safeguard the applying workloads.
Safe Workload provides a holistic strategy to getting visibility from a number of sources corresponding to:
- IPFIX
- NetFlow
- Safe Firewall NSEL
- Safe Shopper Telemetry
- Cloud Move Logs
- Cisco ISE
- F5 and Citrix
- ERSPAN
- DPUs (Knowledge Processing Models)
… and it provides a number of methods to implement this coverage:
- Safe Firewall
- Cloud Safety Teams
- DPUs (Knowledge Processing Models)
Key Takeaways
When selecting the best community and workload microsegmentation answer, all the time take note the dangers, together with the risk panorama and the resilience of the answer itself. With Safe Workload, you get:
- Resilient Agent Structure
- Utility runtime visibility and enforcement with microsegmentation
- Various characteristic set of agentless enforcement
Be taught extra about Cisco Safe Workload
We’d love to listen to what you assume. Ask a Query, Remark Under, and Keep Related with Cisco Safety on social!
Cisco Safety Social Channels
Share: