Cisco Secure Access Help

PDF

Cisco Secure Access Help

Assess and Monitor Configurations in Secure Access

Want to summarize with AI?

Log in

The deployment insights report provides a cumulative score and detailed checks for your organization configurations, including a breakdown by domain and severity.


Secure Access assesses your organization's configurations to identify security risks, errors, or configuration gaps. Assessments can be run manually by an administrator. Secure Access assesses only the configuration domains and checks that apply to your organization based on your enabled services, subscriptions, and available configuration data. Checks for services that are not licensed or enabled do not affect your assessment score.

The platform assigns severity labels—Critical, High, Medium, or Low—to checks needing action, which contribute to the cumulative posture score.

Secure Access monitors the following applicable configuration domains:

  • Certificates: Identifies expiring RAVPN, SAML SP, and custom CA certificates before they cause authentication, VPN, or private access disruptions.

  • Client Profiles: Checks ZTNA client profile safeguards, including auto-enrollment for roaming users and trusted-network definitions that could accidentally bypass enforcement.

  • Network Connectivity: Validates tunnel presence, tunnel health, split-tunnel steering, region or IP pool consistency, and cipher strength to reduce outage and routing-risk conditions.

  • Data Loss Prevention: Ensures DLP rules are enabled, cover sensitive data such as PII, use blocking actions where required, and apply broadly across identities.

  • Security Controls: Identifies overly broad access rules, missing threat-category blocks, weak default internet policy, and missing posture checks for sensitive private resources.

After reviewing the assessment checks, you can take direct action to modify your configuration settings and resolve identified security gaps.

Before you begin

You must have a full admin user role to access the deployment insights report. For more information, see Manage Accounts.

Procedure

  1. Navigate to Monitor > Deployment Insights.

  2. Click Run Assessment to get the latest assessment score for the configurations in the organization.

    • If your organization has add-on features such as data loss prevention enabled, select the add-ons you want to include in the assessment.

    • If data loss prevention is not enabled, the assessment runs for the four standard domains.

    • If data loss prevention is not subscribed, the assessment runs for the four standard domains and the add-on selection modal does not appear.

      Note

      Only add-on products appear in the Run Assessment dialog as default products are included automatically. Add-ons not selected for a run are excluded from the cumulative score.

    Secure Access reviews the configurations in the organization, assigns severity-labeled assessment checks, scores the configurations, and reports on the assessments. To export the latest report of the assessments, click Export and then choose Export PDF or Download CSV.

    The Export button provides options to export the report as a PDF or download it as a CSV file.
  3. Review the Assessment Summary to view the cumulative score, status gauge, last assessed date, and a per domain breakdown of the score, status, and needs action count for each domain.

    The assessment summary displays the score, status, and checks needing action for each domain.

    Understanding assessment results

    • Cumulative score: The summary provides an overall posture score on a scale of 0 to 100, which helps you track improvement over time and benchmark your deployment against recommended baselines.

    • Status labels: Secure Access assigns the following labels to your organization posture:

      • Excellent: 85 to 100

      • Good: 70 to 84

      • Fair: 50 to 69

      • Poor: 30 to 49

      • At risk: 0 to 29

    • Domain breakdown: Assessment checks are categorized by domain to help you identify specific areas of risk, such as certificates, network connectivity, client profiles, security controls, and data loss prevention.

    • Actionable checks: Checks are sorted by severity to help you prioritize remediation. Each check includes a description of the impact and a direct link to the relevant dashboard page to facilitate quick resolution.

  4. Click a domain card to filter the checks needing action for that specific domain.

    Note

    Click the information icon next to any domain to view a tooltip that explains the assessment criteria for that domain.

    The Checks needing action section displays results organized by severity or domain. Each check shows the severity, category, and recommended action.

    Note
    Click the information icon next to any check to view tooltips that explain the criteria for the check status.
    The Checks needing action section displays results organized by severity or domain. Each finding shows the severity, category, and recommended action.
    1. Under Group By, choose whether to filter the checks by Severity or Domain.
    2. (Optional) Choose the severity level: Critical, High, Medium, or Low.

      Secure Access filters checks by the selected severity level.

    3. Choose Domain to filter the checks for that specific domain.
  5. Navigate to an assessment under Checks needing action to view the list of configuration gaps.

    • Current result: Displays the current configuration state that triggered the check.

    • Recommended action: Provides the steps required to resolve the security gap.

  6. Click the action button to open the relevant Secure Access configuration page where you can resolve the check.

    The checks needing action card displays the current configuration state, recommended actions to resolve the security gap, and an action button that opens the relevant configuration page.
    Note

    The action button does not enable inline editing from the Checks needing action card but directs you to the appropriate configuration page within Secure Access to modify settings.

  7. Expand Passed checks to review successful configurations.

    Note

    Click the information icon next to a passed check to view tooltips that explain the criteria for the successful status. This information helps you maintain a consistent security posture and provides context for future troubleshooting if a check fails.

    The Passed checks section lists successful configuration assessments. The information icon next to a check displays the criteria for its successful status.