Cisco Secure Workload
Cisco Secure Workload provides comprehensive workload protection by bringing security closer to applications and tailoring the security posture based on application behavior.
This document defines some of the terminology used for Cisco Secure Workload.
Cisco Secure Workload terminology
agent
A Secure Workload software agent is a lightweight piece of software that you install on your workloads. The agent collects host information, monitors and collects network flow information, and enforces security policies.
ADM (Automatic Policy Discovery)
ADM uses existing traffic flows and other data to:
-
suggest allow policies based on existing successful network activity
-
group workloads into clusters based on similar computing behavior
The goal of the suggested policies is to identify the traffic that the organization needs and block all other traffic.
cluster (Secure Workload deployment)
A cluster is the configuration and monitoring domain for Secure Workload. Supported physical cluster form factors are 8 RU and 39 RU.
concrete policies
Policies that are actually programmed on each workload. These are the policies deployed on the workload.
Connector
A Cisco Secure Workload integration that connects to external resources, such as network switches, routers, firewalls, and endpoint management systems, to collect telemetry, ingest flow observations, and enrich inventory or endpoint context.
conversation mode
A lightweight agent reporting mode in which agents report conversations instead of detailed flows. A conversation is derived from flow data by removing the ephemeral client port and aggregating traffic by consumer, provider, provider port, and protocol.
data tap
A configured data destination used by Cisco Secure Workload to send alerts from the Secure Workload cluster. Data Tap Admin users can configure and activate data taps. They are viewed and managed per tenant.
endpoint
A user device, such as a desktop, laptop, or smartphone, that is reported to Cisco Secure Workload through endpoint connectors such as AnyConnect or ISE. These connectors register endpoints in Secure Workload and provide endpoint inventory, interface, flow, label, or user-attribute context.
exclusion filter
A filter used to exclude matching flows from automatic policy discovery clustering and policy generation. Use it to specify traffic that should not be considered when Secure Workload discovers clusters and suggests policies.
external orchestrator
A Cisco Secure Workload configuration that connects to an external system to gather metadata describing workloads on the network. Some external orchestrators can also enforce segmentation policy.
enforcement alert
Enforcement alerts include Agent Reachability, Workload Firewall, and Workload Policy alerts. These alerts detect conditions such as an unreachable agent, a workload firewall that is off when enforcement is configured, or firewall rules that differ from the Secure Workload policies applicable to the workload.
Forensic Profile
A collection of forensic rules that can be applied to groups of agents using forensic intents. Forensic profiles can include Secure Workload rules or MITRE ATT&CK rules, depending on the profile configuration.
policy request
A request generated for the provider scope when a cross-scope policy is created and the provider’s primary workspace needs a corresponding policy. The request alerts the provider application owner to allow dependent applications to access the provider service.
Primary Workspace
The enforceable workspace for a scope. Only a primary workspace can be enforced, and features such as cross-scope policy management, live policy analysis, compliance reporting, and collaborative security policy definition are available only for primary workspaces.
scope
A Secure Workload classification framework that organizes inventory into a hierarchy, supports dynamic query matching for inventory categorization, and provides an anchor point for policy control and role-based access control.
scope tree
A hierarchical map of the workloads in the network, created from workload labels and scopes. The scope tree helps organize workloads so policies can be created, applied, and managed across branches of the hierarchy.
Secure Connector
A Secure Workload function that creates a reverse tunnel from the Secure Workload cluster to the internal network, allowing Secure Workload to connect to internal resources when needed for connector or external orchestrator communication.
Secure Workload Edge Appliance
The edge appliance is used for alert-related connector services. The guide describes it as the appliance used for Secure Workload Alert Notifier and alert notification connectors such as Email, Syslog, Slack, PagerDuty, Kinesis, Webex, and Discord.
Secure Workload Ingest Appliance
The Ingest appliance exports flow observations to Secure Workload from various connectors. It is used by connectors that collect or forward flow telemetry into Secure Workload.
Virtual Appliance
The virtual appliance is used to host and deploy connectors. Most connectors are deployed on Secure Workload virtual appliances, which are deployed on ESXi or KVM-based hypervisors using OVA or QCOW2 images. After the appliance becomes active, connectors can be enabled and deployed on it.
Feedback