Cisco Secure Access Help

PDF

Cisco Secure Access Help

Manage App Risk Profiles

Want to summarize with AI?

Log in

Describes Manage App Risk Profiles in Cisco Secure Access. App risk profiles define the level of risk you are willing to accept in controllable internet applications users access.


App risk profiles define the level of risk you are willing to accept in controllable internet applications users access. The risk level associated with a profile is determined by a set of risk attributes you select, joined by the OR or AND operator (which you also select).

Once you have defined an app risk profile, you can apply it in an Internet Access Rule. The controllable applications impacted by the rule will be restricted by the app risk profile attributes. So, for example, if you create a rule citing social networking applications as the destination, and apply an app risk profile that stipulates allowing only applications that are FedRamp compliant, then Secure Access will block social networking applications that are not FedRamp compliant.

Be aware that the effect of a risk profile on a given application may change as the characteristics of that application change. For instance, if an app risk profile is defined to block applications that do not comply with FedRamp, an application that is not FedRamp compliant will be blocked; but if that application becomes FedRamp compliant, Secure Access will recognize this and the app risk profile will no longer cause the application to be blocked. Similarly, if an app risk profile is defined to block applications with a particular value for Label Status or Application Risk Score, and you manually change the Label or Risk Score from the App Discovery Report, the app risk profile will no longer cause the application to be blocked.


App Risk Profile Attributes

All app risk profile attributes are viewable in app details in the App Discovery Report.

  • Label Status

    The approval status of an app.

  • Application Risk Score

    The application risk score could be calculated by Secure Access (based on Business risk, Usage risk, Vendor compliance, and Community risk (if available)) or assigned by you. The possible values are Very Low, Low, Medium, High, and Very High. The application risk score is displayed in the Third-Party Apps Report and the App Discovery Report.

  • Business Risk Factors

    Business risks take into account factors such as usage type, web reputation, financial viability, and data storage risks.

  • Attribute Categories

    Security attribute categories include compliance standards, vulnerabilities, data security attributes, email authenticity assurance techniques, access control methods, and audit features.


Add an App Risk Profile

Configure an app risk profile to define acceptable risk factors for end-user devices connecting to controllable internet applications.

Before you begin

  • Full Admin role in Secure Access. For more information, see Manage Accounts.

Procedure

  1. Navigate to Secure > Profiles > App Risk Profiles and click Add profile.



  2. Give your profile a unique Name and a Description.


    The App Risk Name Description interface.
  3. For the Logic Operator option, choose And or Or to indicate how the system will evaluate multiple attributes in the profile.


    The App Risk Logical Operators interface.
  4. For Label Status, click Add Label Status and choose the matching conditions for an app's approval status from the App Discovery Report. Click Save when done.


    The App Risk Add Label Status interface.
  5. For Application Risk Score, click Add Application Risk Score and choose application risk scores to include or exclude from the profile. Click Save when done.

    The application risk score could be calculated by Secure Access (based on Business risk, Usage risk, Vendor compliance, and Community risk (if available)) or assigned by you.

    The possible values are Very Low, Low, Medium, High, and Very High.


    The App Risk Add Score interface.
  6. For Business Risk Factors, click Add Business Risk Factors and choose business risks from the following categories to include or exclude from the profile. Click Save when done.

    • Business Risk


      The App Risk Business Risk interface.
    • Usage Type


      The App Risk Usage Type interface.
    • Web Reputation


      The App Risk Web Reputation interface.
    • Financial Viability Risk


      The App Risk Financial Risk interface.
    • Data Storage


      The App Risk Data Storage interface.
  7. For Attribute Categories, you can choose to add characteristics and properties from the following categories to add to your profile:

    1. Click Add Compliance to select from a list of security standards with which an application must comply or standards with which an application need not comply.

      You may select a specific security standard (such as FEDRAMP or COBIT), or all standards presented in the list.


      The App Risk Add Compliance interface.
    2. Click Add Vulnerabilities to select from list of vulnerabilities to which an application must be resistant or need not be resistant.

      You may select a specific known vulnerabililty (such as DROWN or BEAST), or all known vulnerabilities.


      The App Risk Add Vulnerabilities interface.
    3. Click Add Data Security to select from a list of data security attributes an application must provide (such as HTTP Security Header Support) or exclude (such as weak ciphers).

      You may select specific attributes or all attributes offered.


      The App Risk Add Data Security interface.
    4. Click Add Email Authenticity to select from a list of email security attributes an application must support or exclude (DPF or DKIM).

      You may select specific attributes or all attributes offered.


      The App Risk Add Email Authenticity interface.
    5. Click Add Access Control to select from a list of access methods an application must support or exclude (MFA or SSO).

      You may select specific methods or all methods offered.


      The App Risk Add Access Control interface.
    6. Click Add Auditability to select from a list of auditing features an application must support or exclude.

      The App Risk Add Auditability interface.
  8. Click Save to save the app risk profile and make it available for use in Internet Access Rules.