What is our primary use case?
We use it for identity services, profiling, and locking down devices.
We're an airport, so when anybody plugs in a device, it's obviously a really big security point for us.
How has it helped my organization?
We have a lot of different devices that get plugged in and we really don't have the manpower to address each one individually, as far as our network goes. Cisco ISE has really cut down a lot on the size of our ticket queues and the manpower. My boss is extremely happy about that.
The solution has also eliminated trust from our organization's network architecture and that has actually been positive because we have to meet PCI compliance. It is very important for us to be able to take cards. It has also helped to improve our pen-testing scores at the end of the year.
Resilience, in cyber security, is at the top of the list. It's one of the most valuable aspects and has been extremely important for us. Before, we had mid-range scores, but over the last couple of years, between implementing ISE and a few other technologies and SIEMs, we've gotten into the 90th percentile with our pen-testing scores. We were sitting at about 75 to 80, so this is a pretty huge jump for us.
What is most valuable?
Profiling is one of the most valuable features. We have a lot of different devices between cameras, access points, and laptops that get plugged in.
Establishing trust for every access request, no matter where it comes from, is extremely important for us, especially because we are an airport entity. We do have port security implemented throughout our airport, but on the more sensitive side of things, it's a little bit more hardcore regarding what we need to allow, per security zone.
What needs improvement?
There are always some things that I would request.
For how long have I used the solution?
I first started using Cisco ISE (Identity Services Engine) in about 2015, but we recently just spun it up here at my current job.
What do I think about the stability of the solution?
The stability of the solution is a 10 out of 10.
What do I think about the scalability of the solution?
The scalability is also a 10 out of 10.
How are customer service and support?
For this particular solution, the technical support has been pretty good.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I've worked with ISE before, and it was actually my suggestion that we buy the license for it.
How was the initial setup?
The initial deployment was pretty straightforward only because I had done it before. I worked on it with a colleague and taught him everything about it, just in case I was incapacitated.
From the start, including getting to an agreement, budgeting, and scheduling, the deployment took about three months.
In terms of an implementation strategy, once we got the licensing, we just stood the nodes up. Then we did the features one-by-one, with proper RFCs done, just to see, in a break-fix manner, if each thing we implemented would break something.
What about the implementation team?
We used a consultant. The deployment required two people on our side. I was in charge of the initial rollout and implementation, and I'm in charge of managing it. However, if I'm not there, we have another network guy who does the day-to-day tasks and checks the logs to see if he needs to approve anything.
What was our ROI?
We have definitely seen return on investment. We have so many different security solutions in place, and ISE just works really seamlessly with them. I get to keep my job, so that's a pretty ROI from my point of view.
What's my experience with pricing, setup cost, and licensing?
The pricing is fair for what it does. The only time I've really not been too crazy about the price is for Cisco Prime, which is a management solution for Cisco products.
Which other solutions did I evaluate?
We implemented a request for purchase and talked to a few different companies. One of the companies was Presidio. There was another company close by called Net Solutions. Three out of the five companies that we talked to were outsourcing the work to pretty much just bring in an ISE solution, so we just decided to do it in-house.
What other advice do I have?
If you are on the fence about it, and you don't have someone on your team who has worked with the product before, definitely reach out to a company or a certified Cisco entity to help with the rollout. It's pretty painful if you don't know what you're doing.
Resilience is never a bad idea and it's never too late to start working towards it or to begin the journey to Zero Trust. It's very important in this day and age.
I'm the only cyber security administrator that we have currently, so if we hadn't gotten this solution in place, I highly doubt that I would have been able to make it here to Cisco Live 2021, so it's excellent.
From 2015, when I first started using it, until now, there's not really a lot that I would ask be changed. They've been hard at it ever since I first started using it.
It's been incredible ever since we got it in place.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.