This weblog will discover how monetary establishments (FIs) can use totally different Cisco applied sciences to assist meet regulatory necessities, be they FFIEC, OCC, PCI, or others. Prior blogs on this sequence enumerated on the regulatory our bodies and rules, in addition to how organizations can dwell in a multi-controller world. That is elementary to the varied know-how necessities seen throughout an IT group’s span of management. This weblog will concentrate on a number of the capabilities WITHIN every of those controllers, and the way they may also help resolve the challenges confronted inside their respective domains. Of be aware is all of those applied sciences expose the northbound API which may enable for multi-domain orchestration, and multi-domain orchestration instruments that leverage these instruments had been evaluated within the prior weblog.
Throughout these regulatory audit standards a variety of elementary constructs stay constant. These key tones permeate the steerage that Cisco applied sciences may also help with are having the ability to
- know your surroundings,
- patch your surroundings, and
- section and safe delicate knowledge in your surroundings
Particular inside some rules, you can find superior steerage on evolving applied sciences, particularly with the 2021 replace to the FFIEC operations e book. These rules will proceed to evolve, and having the ability to harness the facility of the automation programs can save organizations operational prices in assembly them.
Cisco DNA Middle
Cisco DNA Middle is a strong community controller and administration dashboard that allows you to take cost of your community, optimize your Cisco funding, safe your distant workforce, and decrease your IT spending. It gives a variety of advantages for FIs, together with serving to them meet regulatory necessities by means of its intensive automation capabilities. These advantages embody:
- Community Segmentation: One of many key regulatory necessities for FIs is to make sure community segmentation to isolate delicate knowledge and programs. Cisco DNA Middle may also help with the provisioning of SDA or different applied sciences (L3 and L2) persistently throughout the surroundings.
- Visibility and Management: Cisco DNA Middle can present the flexibility to centralize and filter on occasions and supply superior analytics.
- Compliance Reporting: FIs are required to take care of compliance experiences to display their adherence to regulatory necessities. Cisco DNA Middle gives compliance experiences that may be simply generated and shared with regulators.
- Automation and Orchestration: Cisco DNA Middle automates community administration duties resembling configuration administration, machine provisioning, and community coverage enforcement. By means of superior composite templates, configlets for options will be stitched collectively throughout units and machine sorts in order that consistency will be maintained for the varied options that exist in an enterprise community.
- Enhanced Safety: By means of superior options like integration with Talos and endpoint classification, in addition to automated workflows for the provisioning of superior safety sources like encrypted visitors analytics, DNA Middle helps FIs implement the insurance policies to satisfy their regulatory necessities.
Cisco SD-WAN
Cisco SD-WAN is a cloud-delivered or on-premise managed software-defined wide-area community answer that permits FIs to attach any consumer to any software. It has built-in capabilities resembling multicloud, safety, enhanced visibility, and analytics constructing towards a Safe Entry Service Edge (SASE)-enabled structure. Some capabilities Cisco’s SD-WAN answer may also help with embody:
- Community Segmentation: Provisioning safe segmentation and simplifying advanced topologies is likely one of the strengths of the Cisco SD-WAN answer. It may assist FIs to declaratively and systematically isolate delicate knowledge and programs. That is intrinsic to the overlay and naturally can prolong the campus to the information heart and cloud utilizing requirements primarily based segmentation constructs.
- Safe Connectivity: One of many improvements Cisco SD-WAN dropped at market was the wedding of the routing topology with the encryption overlay to cut back the normal complexity round managing each individually. It makes use of patented improvements round safe key distribution to facilitate an automatic overlay which may safe any workload from any endpoint to any cloud utilizing software conscious routing.
- Compliance Reporting: Cisco SD-WAN is a PCI compliant answer that can be utilized to assist FIs meet their compliance wants. PCI-DSS experiences can be found and will be shared with regulators.
- Automation and Orchestration: Cisco SD-WAN automates community administration duties resembling configuration administration, machine provisioning, and community coverage enforcement, decreasing the danger of errors and inconsistencies that may result in compliance violations.
- Enhanced Safety: Cisco SD-WAN gives superior safety features resembling risk detection and response, application-level safety, and entry management, which may also help FIs meet regulatory necessities round knowledge safety.
Cisco Meraki
Cisco Meraki is the world main cloud-managed networking answer that gives the complete stack of enterprise merchandise managed persistently by way of centralized administration of community units and functions. It gives a variety of advantages for FIs, together with serving to them meet regulatory necessities. A number of the advantages of Cisco Meraki for FIs on this regard embody:
- Cloud Administration: With a PCI and GPDR compliant cloud administration answer, FIs can safely handle their community infrastructure from a single cloud-based dashboard. The intuitive capability to quickly provision and keep giant networks to incorporate SD-WAN, switching, wi-fi, sensors and cameras, and persistently and based on predefined requirements, prevents configuration drift and inherent danger. The native API permits straightforward integration with current safety instruments and programs for auditing and validation.
- Community Segmentation: Cisco Meraki helps intrinsic and simplified SD-WAN at low complexity to make a straightforward to take care of, safe, and audit surroundings. It has the flexibility to do full stack safety marrying the wi-fi SSID to Layer 2 swap segmentation and preserving that by means of the SD-WAN answer, presenting this all in a single elegant answer.
- Compliance Reporting: FIs are required to take care of compliance experiences to display their adherence to regulatory necessities. Cisco Meraki gives compliance experiences that may be simply generated and shared with regulators.
- Superior Safety: Cisco Meraki gives superior safety features resembling risk detection and response, content material filtering, and entry management, which may also help FIs meet regulatory necessities round knowledge safety.
Cisco ACI
Cisco Utility Centric Infrastructure (ACI) is a software-defined networking answer that gives centralized automation and policy-driven software profiles for knowledge heart networking. It gives a variety of advantages for FIs, together with serving to them meet regulatory necessities. A number of the advantages of Cisco ACI for FIs on this regard embody:
- Community Segmentation: Implicit in ACI is the assemble of software primarily based consciousness and segmentation into requirements primarily based group coverage. This allows a framework for macro and micro-segmentation utilizing conventional community primarily based constructs or extra superior software classification. By means of utilizing a mannequin pushed method to segmentation it permits FIs to make sure that segmentation constructs are constant throughout a category of functions and enforced both in ASIC or by way of service home equipment stitched into the community cloth.
- Compliance Reporting: As a part of Cisco’s reference design for safe knowledge facilities ACI affords the flexibility to report on {hardware} and software program variations in addition to safety constructs used throughout the cloth both by way of native instruments, or by means of created toolkits, and even by means of third-party audit options.
- Automation and Orchestration: Cisco ACI was constructed from the highest down as a mannequin pushed orchestration platform to permit all constructs of the community to be programmed and orchestrated as objects within the mannequin. ACI has implicit automation and orchestration, and exposes all this performance by way of API to permit third-party merchandise to seamlessly match into the answer.
- Enhanced Safety: Cisco ACI gives superior safety features resembling community segmentation, policy-based entry management, and risk detection and response, which may also help monetary establishments meet regulatory necessities round knowledge safety.
- Scalability and Efficiency: Cisco ACI has line price efficiency and distinctive scalability to satisfy probably the most demanding environments. Evolutions resembling multi-pod and multi-site enable materials to not solely span geography however will increase scalability by permitting mobility between a number of availability zones.
In Conclusion
The FFIEC weblog sequence has been centered round summarizing and evaluating the regulatory surroundings confronted by IT organizations by means of the lens of the way it impacts these organizations, and corresponding applied sciences to assist. In my 15 years serving the monetary providers area, the regulatory world has solely gotten tougher, however that is because of the actual world danger and evolution of industrialization of the risk panorama into viable and worthwhile enterprise fashions. The extent of technical danger confronted by FIs is at an all time excessive and can proceed to evolve as long as FIs are “the place the cash is.” The regulatory surroundings doesn’t resolve this however is an try to make sure some degree of management and consistency. To assist meet these necessities Cisco has invested billions of {dollars} into the safety and into the safety of our platforms.
The extensibility of those platforms right into a northbound API permits for the perfect at school performance of all these programs from the campus to the WAN, whereas having the ability interoperate utilizing requirements primarily based protocols and apply a multi-domain coverage. This method promotes flexibility and performance with out compromise, serving to organizations unlock the utmost potential of their investments to resolve their present and future enterprise issues.
Share: