TrustRadius: an HG Insights company

Cisco Security Cloud Control

Score9.8 out of 10

10 Reviews and Ratings

What is Cisco Security Cloud Control?

Cisco Security Cloud Control helps the user consistently manage policies across Cisco security products. It is a cloud-based application that cuts through complexity to save time and keep your organization protected against the latest threats.

Categories & Use Cases

Top Performing Features

  • Policy planning and rule management

    Monitor the effectiveness of network security infrastructure

    Category average: 8.9

  • Vulnerability Scans

    Network scans to pinpoint vulnerable locations for remediation

    Category average: 8.4

  • Automated Policy Orchestration

    Automatically brings together all security controls in one place, automates changes and collapses risks

    Category average: 7.8

Areas for Improvement

  • Firewall Rule Cleanup

    Ability to detect and cleanup rules that are either partially or completely unused, expired or shadowed

    Category average: 8.9

  • Anomalous Event or Behavior Deviation

    Ability to pinpoint unusual events or trends

    Category average: 8.6

  • Attack Path Simulation Testing

    Simulation of potential attack paths to expose network exposure

    Category average: 7.9

Powerful software for rapid security policy management and ideal for network intrusion detection.

Use Cases and Deployment Scope

Cisco Defense Orchestrator is a powerful and important software for our company, this is because we use this solution throughout our company to help us with the administration and implementation of security policies in a simpler way, by being able to achieve this we obtain easy management and being able to put aside the hard work of having to implement security policies one by one to keep our infrastructure protected. This Cisco software allows us to control and view all devices from one place, as well as keep informed about whether the security policies work correctly or not.

Pros

  • It allows an easy and correct administration of corporate security policies.
  • Being based on the cloud, its management is not complex, since its console is totally centralized, which gives the advantage of viewing all the devices from a single place.
  • It has remote management which makes it possible to manage the devices from anywhere, that is, the location does not matter.
  • It provides templates that are ideal for implementing business security policies, they are very helpful when you do not have the knowledge of this type of software.

Cons

  • Their costs can be high, so when it comes to small or medium-sized companies they are limited to their acquisition due to their price. That is why plans tailored to these companies can help them to have this protection option.
  • Its configuration can be somewhat confusing, so knowledge and skills are required.
  • Have more configurable templates so that protection is not limited.
  • Its implementation in the cloud is innovative and ideal for those who trust it, however not all companies trust it, so being able to implement this software locally would also be a great option.

Return on Investment

  • It is a powerful software to implement security policies properly since it allows us to be aware of whether the policies are working correctly or not.
  • Being in the cloud is not only a form of savings but also a way to facilitate the administration of all firewalls.
  • Your policies can be implemented for all devices so it is not necessary to apply them one by one, which is a great time saver.
  • Its protection allows you to put aside network intrusions.

Alternatives Considered

McAfee ePolicy Orchestrator

Other Software Used

Cisco SecureX, Panda Security for Desktops, Zoom, AlertBot Website Monitoring, Proofpoint E-discovery & Data Analytics

CDO - A Great Product!

Pros

  • Single plane of management.
  • VPN monitoring.
  • Remote management via external IP.
  • Cost.

Cons

  • Better templates like pushing config. when a particular firewall checks in with CDO.
  • Compliance checking for configurations would be great. For example: make sure http is shut and https is open.

Return on Investment

  • Much faster management.
  • Can access firewall without having to go on site if the VPN tunnel is down.

Other Software Used

Cisco Identity Services Engine (ISE)

Cisco Defense Orchestrator the best management platform for the Cisco Firewalls

Use Cases and Deployment Scope

The main issue was a scalable solution to manage our fleet of Cisco firepower threat defense firewalls. They are managed locally and manage via FMC. The Cisco Defense Orchestrator was the most financially likeable option. The price point per firewall was great with most features of the FMC on prem device. There were only a handful of features that were not moved to the cloud.

Pros

  • Upgrade OS
  • Manage changes at scale
  • Group like configurations
  • Clone configs for other firewalls
  • Migrate from on prem to cloud

Cons

  • FMC in the cloud needs more features like the on prem version
  • A way of managing the firewalls both on box and with FMC at the same time
  • A way to log local for users not wanting to log all events to the cloud

Return on Investment

  • Positive ROI with enhanced functionality that FDM doesn't have
  • We continue to use it today

Alternatives Considered

Cisco Firepower 1000 Series

Other Software Used

Splunk Enterprise, Graylog