Chris Young just celebrated his six-month anniversary as senior vice president of the recently formed Cisco Security Group reporting to Cisco CTO Padmasree Warrior. He brings an interesting perspective to the position, hailing as he does from VMware and RSA. Young was senior vice president and general manager for VMware’s end user computing solutions and, prior to that, senior vice president for products at RSA. After hearing Cisco CEO John Chambers proclaim in a recent teleconference that we could expect to see Cisco make big strides in security with Young onboard, Network World Editor in Chief John Dix tracked Young down for his vision and plans.
You’re the first senior vice president to head the Cisco security team and the company has integrated two existing security groups under you. Tell us about the shifts.
Before I came onboard there was a senior VP of networking and he owned a lot of our wireless networking, our routing business, and security was part of that grouping of products. And last fall Cisco decided to elevate security to a SVP role and brought me in. Cisco has many businesses today, we’re not only routing and switching. We have a data center business, we have a large collaboration business, and security needs to be more pervasive across everything we’re doing.
But there is also a vertical element as well, so the question is how much do we embed versus how much do we offer as a stand-alone product? We place a lot of value on integrated architectures as a way to bring value to customers as opposed to a laundry list of products, so my role is building the security value proposition in as integrated a fashion as possible. It doesn’t mean that we won’t sell stand-alone security products. We have to do that, but strategically we’ll be focusing on delivering a better-integrated security capability.
How much reorganization will you have to do to achieve that?
The good news is there were already a number of efforts underway to build security capabilities into other parts of the infrastructure, but there’s work that needs to be done. I need to beef up investment in certain areas, such as security baseline architectures, across everything we do. The baselines will be the foundational building blocks for some of the more interesting integrations we’ll do, like the firewall integrated into the switch or firewall integrated into the routing platform, or Web gateways integrated into the routing platform. And then moving up the layers of the network to offer more Layer 4 through 7 services.
So, for example, we just announced something we call our ASA CX, which is our context-aware firewall, so …
As part of the SecureX architecture announced last year?
It’s the second proof point of SecureX architecture. The first one would have been our Identity Services Engine, which provides access control based on user identity, location, device posture, etc., allowing for secure access to network infrastructure. The Identity Services Engine has been one of the core parts of our overall value proposition around wireless access and addressing BYOD needs, and we rolled that out last year.
BACKGROUND: Tablets, smartphones force Cisco to rethink how security works
The ASA CX was announced at the RSA Conference in February. It’s a context-aware firewall that lets customers not only make access control decisions at the application level, but also at the micro app level. So you can allow employees to use Facebook, for example, but block access to certain games on Facebook. The ASA CX [can also be used as] a software module in different parts of the infrastructure. So we’re working to make the CX run on routing infrastructure and to virtualize the CX so it can be part of a virtual data center architecture. You’re going to see us do more of that kind of delivery of products, to make capabilities more ubiquitous across the Cisco infrastructure. And then obviously we’ll have stand-alone appliances that can work in a heterogeneous architecture as well.
Will Cisco have multiple security architectures?
Go back to the idea that security for Cisco is a vertical and a horizontal opportunity. SecureX is a great example of security as a vertical. It’s a security architecture that’s about bringing visibility context and control to the infrastructure. What I think we have to do now is take the principles of the SecureX architecture and make those more a part of the core Cisco architectures, like enterprise networking, collaboration and data center.
There’s no monolithic security, right? Security has to be part of everything we’re doing. What we’ll have is a strong set of solutions and architectures that integrate with core parts of the infrastructure. So I’m looking to bring the SecureX principles into the core Cisco architectures, so there is a SecureX data center, SecureX networking, SecureX collaboration. Because I believe those principles of visibility, context and control are the right ones for making the security decisions we need to make given the challenges we see, whether you’re looking at macro trends like BYOD and changes around mobility at the end point, or whether you’re thinking about applications and workloads in the cloud, collaboration and even video.
That provides a good segue to BYOD. What are you doing there?
BYOD is probably one of the best examples of why integrated security can be powerful for a company, and we’ve got most of the pieces in place already and that’s why we’re seeing a lot of uptake from customers.
It’s going to be Father’s Day soon and a lot of iPads are going to get handed out and all those guys are going to show up at work the next day and try to connect to email and to wireless access points. And organizations are going to need to decide, “Do we allow access to the network? If so, how much access and to what resources?” [Also see: “Fear the tablet: Cisco survey”]
Now with our Identity Services, our AnyConnect client and the ASA firewall, we can give customers a full set of capabilities that allows them to discover a device when it tries to connect and, based on the user’s identity, make a policy decision on what resources you’ll allow that user and that device to access.
That could be anything from, “I’ll let the device on, I’ll let the user on, I’ll let them sync to ActiveSync and get their email,” to “Let’s take the user through a set of flows, register a user or register a device, and provision a profile to the device so there’s a secure VPN connection to corporate applications.” You can also provision other company-based applications as part of that workflow. And then the Identity Services Engine becomes the policy management point, and the router, switch and the firewall, depending upon whether you’re on network or off, become the control points that get leveraged.
And what’s great about that for a customer is they can leverage one policy server that works with an existing infrastructure deployment. They don’t have to go deploy another set of servers that are enforcing access control within the network. They’re just leveraging the network gear that’s already there.
How does this vision mesh with, say, the VDI efforts of companies such as VMware and Citrix?
When I was at VMware I ran the virtual desktop business, end user computing was my space, and what I just described doesn’t mean you wouldn’t have a VDI solution involved. I talked about going through a user registration flow, and part of that could be provisioning a VDI client. And then through that VDI client they get access to their Windows desktop that’s running in the data center, so we can provide the upfront access control and the security policy around provisioning that VDI client to the user. And then when they go off network and come back on network, we can continue to be the access control point for letting them into other VDI infrastructure. So they work very much in conjunction with each other. Our position is we’re trying to help customers allow their users to work the way they want to work.
OK. Let’s get to integration. Are there other legacy security pieces you’ll try to integrate into these different architectures?
Well, it depends on what you define as legacy. I mean Cisco is one of the biggest players in firewall, we’ve been that for years. And firewalling is probably one of the most mature segments of the security business, although it’s going through a renaissance because there’s a lot of convergence between network security, which is firewall and IPS, and content security, you know, email and Web gateways and that kind of thing.
Those worlds are coming together. We’re seeing more and more convergence between firewall, IPS, Web gateway and even anti-malware scanning that goes on in messaging traffic. And so what I see in the industry and what we’re doing as well, is trying to bring multiple services to the same platform, trying to make Web and cloud-based security services a part of the overall offering.
One of the reasons I believe our ScanSafe solution is so important is because you want to be able to give customers the ability to leverage the capabilities the cloud brings, such as real-time scanning for malware, real-time intelligence on threats that could be global in nature, the ability to protect users off network as well as on network. So there’s a lot of value in these kinds of integrated models and I think customers using the ScanSafe service are very pleased with the flexibility they get from that kind of a model.
Let’s stick with cloud for a minute, because it does seem to complicate security dramatically. What do you make of the challenges?
It is important to define the space because security in the cloud can mean a lot of things, everything from how we secure workloads that move between public and private clouds, to providing secure user access to SaaS applications, and even how to use cloud as a delivery model for security.
If you start with the first example, which is securing virtualized workloads, virtual data centers, whether those be public, private or hybrid models, this is where the data center security model becomes really important. And you’ve seen some of the things we’ve been doing on our Nexus 1000V with our virtual security gateways, bringing some of that segmentation capability to the virtualized data center. Because it’s based on the switch, the switching architecture can actually extend itself beyond a specific data center to a private or a hybrid cloud environment.
The second one is, how do I make sure that my users are connecting directly to SaaS applications? And that becomes more about managing user identities, managing single sign-on, managing compliance of those vendors that are using these different services. Also an important point here is that some users are working around IT by going out and using SaaS-based applications without IT’s permission, emailing files into their personal email accounts, using file syncing and sharing services.
When you have a PowerPoint document that has company data in it and you move it into one of those services, you’ve put corporate data in a place where it’s no longer controlled by the company. A lot of organizations are very concerned about how to manage data privacy in a world where users are moving information around cloud repositories in ways that are very difficult for the security teams to keep up with. So that vector is becoming more and more a focus area of a lot of security organizations and enterprises because they want to be able to get a handle on that.
The third piece is leveraging the cloud as a security delivery model, a la ScanSafe, our cloud security gateway that lets users securely browse the Web while we do things like URL filtering and block malware transmission. So ScanSafe is a good example of the ability to see across multiple domains. We see over 5 billion daily Web requests on the ScanSafe service alone.
In the case of SaaS, most customers simply rely on the service provider to secure the environment, don’t they?
With providers like Salesforce, a lot of the security model is focused on identify federation, so the corporation can provision and revoke user access to these different services. And then on the backend we’re seeing more requests for reporting so the enterprise that’s ultimately responsible for the users and data in these cloud models can prove compliance, they can go through security audits and understand how well their data is being protected. But a lot of the primary focus is on user provisioning and de-provisioning to these different services.
You mentioned virtualized workloads and data centers, and given your history with VMware you’re a perfect person to ask this question. It seems increasingly likely that all the security guys have to play nice with VMware. What kind of control do they have and what do you know about their security ambitions?
VMware, because of their increasing ubiquity in the infrastructure is, I would say, daily becoming more and more important as part of the security model. Just like servers used to be the front and center part of the infrastructure, now the VMware layer is taking that. And as VMware becomes more ubiquitous, I think their importance to security is increasing.
But we’ve been able to work with them at the switching layer with the Nexus 1000V to bring our zoning capabilities. And you’ll see us bring more of our ASA firewall capability to that virtual machine layer over the course of the next couple of months. And you’ll see us do more in the security virtualization area, primarily as it relates to protecting individual workloads and bringing policy-based enforcement.
Coming down to the end here, let’s go back to the big picture. Any gaps in the Cisco security portfolio you have to fill?
In security new gaps are always being created. There will never be a static model. We’re never done, right? Even in physical security, people still rob banks. We haven’t even perfected that security model. We don’t spend a lot of time thinking about it, but most of what happens in the cyber world is just a reflection of what happens in our physical world. It’s just things move faster and the scale can be bigger, and therefore, we have to think a little bit differently about that model.
So to answer your question about gaps, there’s consistently going to be new areas where we have to bring new threat intelligence capabilities. If we find superior solutions out in the marketplace that customers really want, obviously we’ll follow the Cisco process and bring things onboard where they make sense. But, for the most part, I think we have a very strong portfolio and I’m getting a lot of great feedback on the announcements we have made, in particular our context-aware firewall and the uptake we’re seeing in our Identity Services Engine and the relevance of that model to BYOD. And so I feel very good about where our portfolio is today.
Maybe we could close with your thoughts on an ancillary subject, the security of the national infrastructure. Have you, as a company, examined the problem?
We work closely with a lot of public sector entities around making sure the network infrastructure is resilient, is secure. That’s a big area of focus, and we’re working with public sector players in countries around the world. So it’s a big part of what we do, a big part of what we see as our responsibility. Our networks are such an important part of our lives in many ways, so we take that responsibility very seriously.
Do you have a sense of how vulnerable the nation’s critical infrastructure is?
I’ve been in security for a long time now. I’ve never been a naysayer about the level of security. I mean, think about all the great things we can do today, leveraging the power of the network. Most people transact online, and that’s in our personal lives as well as in our enterprise lives. Transactions flow throughout the network on a daily basis between and among institutions. We couldn’t do all of that if our security bar hasn’t been consistently raised along the way. So while there are risks and while there’s always more security that is necessary, we live our lives digitally today and are able to do so in a relatively safe and secure manner. None of us are resting on our laurels, but there’s no reason for panic either.
So the sky isn’t falling?
No, not at all. In fact, I think people should be encouraged by all the things that we can do as individuals, as organizations, because that’s only been enabled by the security model that’s grown up along with the network and the infrastructure that’s out there.
The country, thought, seems to be dragging its heels on the national infrastructure stuff and won’t get serious about it until something bad happens.
There are always examples of places where you can improve. What I will say is there’s a lot of activity that people aren’t able to talk about that is part of protecting national infrastructure. For critical infrastructure, there’s a lot more intelligence and monitoring that goes on behind the scenes that would enable governments or quasi-governmental entities to actually take action if they saw attacks happening. It doesn’t mean that targeted attacks don’t happen. Like we talked about physical virtual world, espionage happens in physical worlds and espionage can happen in the digital world as well, but I don’t think national infrastructure is as vulnerable as it might seem on its face. [Also see: “Researchers identify Stuxnet-like cyberespionage malware called ‘Flame'”]
Good to hear. Anything else that we didn’t touch on that you think is important?
The one thought I would leave you with is that, the days of IT handing you a device with all the security agents and controls in place is changing rapidly. Application access is changing, and even the structure of our applications is changing. Data is everywhere. But the one constant in all this is the network. And this is one of the reasons why, for me, coming to Cisco was a really compelling, because I think Cisco is really at a nexus point of being able to provide an integrated security model in a way that can really move the bar a lot higher and provide security in an integrated way.




