Integrate Device Security with Nozomi CMC
Focus
Focus
Device Security

Integrate Device Security with Nozomi CMC

Table of Contents

Integrate Device Security with Nozomi CMC

Integrate Device Security with the Nozomi Central Management Console (CMC) to import OT and IoT asset inventory and vulnerabilities from all of the Nozomi Guardian appliances that CMC manages into Device Security.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
One of the following Cortex XSOAR setups:
  • A free, cohosted, limited-featured Cortex XSOAR instance
    AND
    A free Cortex XSOAR Engine (on-premises integration)
  • A full-featured Cortex XSOAR server
Nozomi Networks offers the Nozomi Central Managment Console (CMC), an on-premises appliance that aggregates multiple Nozomi Guardian appliances into a single management console. Nozomi Guardian collects and analyzes traffic locally in each of your operational technology (OT) and IoT environments, and CMC consolidates their data so that you can monitor and manage many Guardians from one place. Integrating Nozomi CMC with Device Security lets Device Security learn about the OT and IoT assets that your Guardians discover, further consolidating your OT, IoT, and IT device inventories and their management operations together in Device Security.
Because CMC already aggregates data from every Guardian it manages, a single Device Security integration instance for CMC covers all of the Guardians behind it. You don't need to configure a separate integration instance for each Guardian appliance. If you connect directly to Nozomi Vantage cloud, or to a single Nozomi Guardian appliance without CMC, see Integrate Device Security with Nozomi Vantage instead.
Through the Nozomi CMC integration, Device Security can ingest the following data:
  • Device inventory: Information about your OT and IoT devices, such as device type, vendor, model, operating system, firmware version, MAC address, IP address, and last-seen timestamp.
  • Vulnerabilities: Information about known vulnerabilities that Nozomi identified on your devices, mapped to the corresponding assets. Vulnerability details include information such as CVE, criticality, and detection time on a given asset.
Bringing Nozomi CMC asset data into Device Security gives you a consolidated view of your OT, IoT, and IT devices in a single inventory. You can then apply Advanced Device-ID policies to Nozomi-sourced devices, correlate their vulnerabilities with other risk signals in Device Security, and act on them alongside the rest of your connected devices.
If you create Advanced Device-ID policies for Nozomi-sourced devices, you need to understand the MAC-IP binding source for those devices. If the MAC-IP binding source is not traffic observed by the NGFW then there is risk that policies may be applied to the wrong IP if a device’s IP changes between runs of Nozomi integration jobs.
To integrate with Nozomi CMC, Device Security uses REST API queries with an API key that you generate in Nozomi CMC. The Nozomi CMC API is a distinct endpoint from the Nozomi Vantage API, which is why Nozomi CMC and Nozomi Vantage are configured as two separate integrations instead of a single integration.
To control which data Device Security receives, you configure jobs in Cortex XSOAR with the appropriate playbook:
  • Import Device Details From Nozomi CMC To Device Security — imports device inventory records and their attributes.
  • Import Vulnerabilities From Nozomi CMC To Device Security — imports vulnerability findings mapped to the corresponding devices.
You can run each job on-demand or schedule it to run on a recurring interval.
For a full list of attributes that Device Security can learn through the integration, see Nozomi CMC Attribute Reference.
Integrating with Nozomi CMC requires either a full-featured Cortex XSOAR server or the activation of a Device Security free cohosted Cortex XSOAR instance. Because Nozomi CMC is always on-premises, you also need a free Cortex XSOAR engine when you use a cohosted Cortex XSOAR instance so that Cortex XSOAR can reach the CMC appliance on your network.