Integrate Device Security with Nozomi Vantage
Integrate Device Security with Nozomi Vantage to import OT and IoT asset
inventory, software details, and vulnerabilities from your Nozomi deployment into
Device Security.
| Where Can I Use This? | What Do I Need? |
|
|
One of the following subscriptions:
Device Security subscription
Precision AI bundle subscription
Device Security X subscription
One of the following Cortex XSOAR setups:
A free, cohosted, limited-featured
Cortex XSOAR instance
AND
A free Cortex XSOAR Engine (on-premises integration)
A full-featured Cortex XSOAR server
|
Nozomi Vantage, a cloud-based SaaS platform from Nozomi Networks, provides
visibility, threat detection, and risk monitoring for operational technology (OT) and
IoT environments. Integrating Nozomi Vantage with Device Security lets
Device Security learn about the OT and IoT assets that Nozomi discovers, so that
you can manage your OT, IoT, and IT device inventories together in
Device Security.
The same integration also supports Nozomi Guardian, the on-premises Nozomi appliance
that collects and analyzes traffic locally. Nozomi Guardian exposes the same API
structure as Nozomi Vantage, so a single Cortex XSOAR integration can work
for either deployment. You choose which system to connect to by entering the
Nozomi Vantage cloud URL or the Nozomi Guardian appliance URL as the Domain URL when
you configure the integration instance in Cortex XSOAR.
Through the Nozomi Vantage integration, Device Security can ingest the following data:
Device inventory: Information about your OT and IoT
devices, such as device type, vendor, model, operating system, firmware
version, MAC address, IP address, and last-seen timestamp.
Software inventory: Software components installed on
each device, such as product name, version, and vendor.
Vulnerabilities: Information about known vulnerabilities
that Nozomi has identified on your devices, mapped to the corresponding assets.
Vulnerability details include information such as CVE, criticality, and
detection time on a given asset.
Bringing Nozomi Vantage asset data into Device Security gives you a consolidated view of
your OT, IoT, and IT devices in a single inventory. You can then apply Advanced
Device-ID policies to Nozomi Vantage devices, correlate their vulnerabilities with
other risk signals in Device Security, and act on them alongside the rest of your
connected devices.
If you create Advanced Device-ID policies for Nozomi-sourced devices, you need
to understand the MAC-IP binding source for those devices. If the MAC-IP binding
source is not traffic observed by the NGFW then there is risk that
policies may be applied to the wrong IP if a device’s IP changes between
runs of Nozomi integration jobs.
Device Security queries Nozomi Vantage over
its REST API using an API key that you generate in the Nozomi Vantage console.
To control which data Device Security receives, you configure jobs in
Cortex XSOAR with the appropriate playbook:
Import Device Details From Nozomi Vantage To Device
Security — imports device inventory records and their
attributes.
Import Devices With Softwares Details From Nozomi Vantage To Device
Security — imports device records together with their
installed software components.
Import Vulnerabilities From Nozomi Vantage To Device
Security — imports vulnerability findings mapped to the
corresponding devices.
You can run each job on-demand or schedule it to run on a recurring interval.