The Cisco Security Manager (CSM) helps achieve consistent policy enforcement, quickly troubleshoot security incidents, and provides summary reports for the entire security deployment. It uses a centralized interface to facilitate the effective expansion and management of a large number of Cisco security equipment, while visibility has also been further improved.
The Cisco Security Manager provides a comprehensive security management solution for the following devices:
Cisco ASA 5500 Series Adaptive Security Appliance
Cisco IPS 4200 (US) and 4500 Series Sensors
Cisco AnyConnect Secure Mobility Client (US)
It has the following advantages:
Policy and Object Management
Assist in reusing security rules and objects
Implement process compliance and zero defect deployments
Increase the ability to monitor security threats
Event Management
Supports syslog messages created by Cisco security devices
Enables the viewing of real-time and historical events
Provides fast navigation from event to source policy
Built-in pre-bounded view for firewall, intrusion prevention system (IPS) and VPN, can be customized
Reporting and troubleshooting
Provides system reports and custom reports
Reports can be exported or scheduled via e-mail (in CSV or PDF format)
You can use advanced tools such as ping, traceroute, and packet tracer for advanced troubleshooting
Image management
You can use an intuitive wizard to simplify the direct upgrade of the firewall software image
You can schedule image upgrade work during network maintenance time
Import images from the Cisco online software website or local file system
You can run automated updates individually or in groups on each firewall
Condition and Performance Monitoring (HPM)
Expand visibility into firewalls, Intrusion Prevention System (IPS), and VPN status and performance.
Thresholds can be set for various parameters
An alarm can be issued when a pre-defined threshold is reached
API access
Share information with other basic network services, such as compliance systems and advanced security analysis systems
You can access data directly from any security device that is managed by the Cisco Security Manager using an external firewall compliance system
Compatible with various security compliance vendors such as Tufin, Algosec and Skybox
Other functions
Depth presentation of Cisco Security Intelligence Operations (SIO) recommendations
Helps administrators fine-tune their environment before deploying signature updates
For information about using security management software to manage smaller, simpler deployments, e-mail, and Web security devices, see the Network Security Management page.
Specifications
Reuse security rules and objects to monitor security threats and reduce potential errors
Integrated end-to-end tools for consistent policy enforcement and rapid troubleshooting
Integrated event management that helps you view real-time and historical events
In-depth coverage of Cisco SIO guidelines