View Security Dashboard
This chapter provides information on the Security score, Security score categories, and Scope-Level score details that are presented under the Security dashboard. The chapter centers on the Security Dashboard's role in Cisco Secure Workload, emphasizing its capability to evaluate the security position of workloads through a comprehensive scoring system. The scoring system integrates signals from various aspects of Secure Workload, offering a foundation for deeper analyses like flow search, inventory search, policy discovery, and forensics. A key feature is the Security score, which ranges from 0 to 100, where a higher score indicates a better security posture. This score is determined by factors such as software vulnerabilities, process hash consistency, open ports, forensic events, network anomalies, and policy compliance.
The chapter explains the six categories of security scores, each addressing different workload security dimensions: Vulnerability Score, which assesses software risks using the Common Vulnerability Scoring System (CVSS), the Process Hash Score that checks for hash consistency; the Attack Surface Score that identifys risks from unused open ports; the Forensics Score that is based on forensic event severity; the Network Anomaly Score that assessing network anomalies; and the Segmentation Compliance Score, monitoring policy violations. The chapter also provides practical guidance on using the Security Dashboard to monitor and enhance security scores over time. The Security Dashboard not only aids in monitoring but also guides corrective actions like patch application and policy refinement, ultimately enhancing organizational security and compliance.
|
Due to recent GUI updates, some of the images or screenshots used in the user guide may not fully reflect the current design of the product. We recommend using this guide in conjunction with the latest version of the software for the most accurate visual reference. |