About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

The Cost of Not Conducting a Network Infrastructure Risk Assessment: A Costly Gamble Oleg Tyschenko on February 27, 2024 at 1:00 pm

In today’s ever changing digital world, businesses rely on robust network infrastructures to function efficiently and operate securely. With the rise of cyber threats, however, organizations are at a… Read more on Cisco Blogs

​[[{"value":"

In today’s ever changing digital world, businesses rely on robust network infrastructures to function efficiently and operate securely. With the rise of cyber threats, however, organizations are at a critical point in time where vulnerabilities to their networks are at their highest. Organizations are playing a high-stakes game with their networks, and the consequences of an attack could result in big financial losses, falls in customer trust, and damaged reputations if network infrastructure risk assessments are not conducted. Data loss is another issue that could occur due to a severe outage which could lead to data protection implications that impact the business, its customers, suppliers, and the brand.

Based on a survey conducted by Information Technology Intelligence Consulting (Rock, 2023) an enterprise has an average of 15 unplanned outages a year where 91% of enterprises report downtime costs exceeding $300,000 per hour.

Enterprises face various risks that can disrupt their operations. A resilient organization is prepared to mitigate risks and quickly recover in the case of operational disruption, minimizing downtime, and the associated costs. However, there is still a decision to be made around the business case to identify and assess operational risks and the cost of mitigation activities.

The regulation spans even further, covering security. Robust cybersecurity measures must be in place, including firewalls, encryption, and intrusion detection systems, that can protect a business’s data and digital infrastructure, reducing the risk of cyber-attacks and ensuring continued operation.

Assessment of potential vulnerabilities of the network infrastructure and its critical components requires close collaboration of the enterprise with service providers and industry-leading experts. The infrastructure assessment exercise must take a holistic approach when it comes to the technology domain, resources and operation processes, and engagement models with service providers/service management vendors. Environmental factors need to also be accounted for and examples of all these include, the latest trends, economic and political developments that might target potential industry, customers, or country.

Some enterprises are considered as critical national infrastructure, and the question of risk assessment is part of their business model.

Before an enterprise can mitigate risks, it needs to understand what those risks are. This often involves conducting a risk assessment, which can include hiring external consultants, purchasing risk assessment software, and spending employee time on the assessment process. The cost of such activities could range from a few thousand dollars for smaller, less complex organizations to tens or even hundreds of thousands for larger, more complex organizations; especially those in highly regulated industries like finance or healthcare.

It’s fundamental to understand that risk mitigation should be viewed as an investment, as the costs of not taking preventative measures can be significantly higher.

Cisco brings a set of tooling and frameworks that accelerate the risk assessment exercise with industry-proven assets. We work with our customers across all industries and our experience is based on a proven track of successful delivery and lessons learnt. Our products and services handle enterprise challenges within the business and operational resiliency domain.

The goal of risk mitigation is to protect the business. The costs associated with a major disruption or loss can far exceed the costs of risk mitigation.

Technology unplanned outages and cyber incidents drive a need to upgrade technology architecture and the underlying infrastructure to reduce risk and build resiliency. In 2019, for example, the United Kingdom imposed a $230 million fine on a European airline for a 2018 breach caused by security vulnerabilities (Townsend, 2019). The same year the global computer system outage of another airline grounded flights for several hours, causing large-scale cancellations across several airlines.

Therefore, when considering the costs, it’s also important to consider the potential savings and benefits that risk mitigation can provide. While risk assessments can be expensive, the cost of not conducting them can be much greater.

Citations

Rock, T. (2023, March 27). Invenio IT – 25 Disaster Recovery Statistics. Retrieved from

https://invenioit.com/continuity/disaster-recovery-statistics/#:~:text=The%20ITIC%202021%20Hourly%20Cost,to%20more%20than%20%245%20million.: https://invenioit.com/continuity/disaster-recovery-statistics/#:~:text=The%20ITIC%202021%20Hourly%20Cost,to%20more%20than%20%245%20million. Townsend, K. (2019, June 11).

British Airways Faces $230 Million Fine for 2018 Breach. Retrieved from ITC Secure:

https://itcsecure.com/news/british-airways-faces-230-million-fine-for-2018-breach/

Share

"}]]  In today's ever changing digital world, businesses rely on robust network infrastructures to function efficiently and operate securely. With the rise of cyber threats, however, organizations are at a critical point in time where vulnerabilities to their networks are at their highest.  Read More Cisco Blogs 

By |2024-02-27T17:52:50+00:00February 27, 2024|Cisco: Learning|0 Comments

Evolution to 5G-Advanced and Beyond: A Blueprint for Mobile Transport Waris Sagheer on February 27, 2024 at 4:00 pm

The rapid rollout of 5G technology has marked a historic milestone in the evolution of mobile connectivity. According to research firm Omdia, 5G subscriptions surged from 1.4 billion in the middle of… Read more on Cisco Blogs

​[[{"value":"

The rapid rollout of 5G technology has marked a historic milestone in the evolution of mobile connectivity. According to research firm Omdia, 5G subscriptions surged from 1.4 billion in the middle of 2023 to a projected 8 billion by 2028, representing a compound annual growth rate (CAGR) of roughly 40%. Despite this impressive uptake, Omdia’s data also reveals that overall mobile revenue is growing at a modest rate of about 2%, and average revenue per user (ARPU) is experiencing a decline.

Wireless trends and opportunities

Communication service providers (CSPs) are responding by scaling their 5G networks to accommodate the soaring bandwidth demands, foster revenue growth, reduce total cost of ownership (TCO), and enhance network efficiency and agility.

The industry has seen significant investments from CSPs, with tens of billions of dollars spent on 5G spectrum and more on radio access network (RAN) infrastructure to support 5G. CSPs’ current focus is monetizing 5G for both consumer and enterprise services (see Figure 1).

Figure 1. Opportunities and Trends

On the consumer front, fixed wireless access (FWA) has emerged as a leading 5G application. For instance, in 2022, FWA accounted for 90% of net broadband additions in the U.S., surpassing traditional cable and DSL. However, this shift brings its own complexities, including the need for enhanced xHaul transport bandwidth, increased data center resources, and greater demand for spectrum resources.

For businesses, private wireless networks represent a crucial area of growth. These networks are particularly relevant in the manufacturing, transportation, logistics, energy, and mining sectors. The advent of 5G-Advanced technologies could help expand these opportunities further. Network slicing, introduced by the 3rd Generation Partnership Project (3GPP), will be pivotal in deploying private 5G networks and other differentiated services.

Partnerships are becoming increasingly important in network monetization strategies, especially with hyperscalers. Additionally, collaborations with satellite operators are gaining traction due to investment and dramatically reduced launch costs, enabling the deployment of low Earth orbit (LEO) constellations and satellite transition from proprietary silo towards integration with terrestrial and 5G networks. Driven by the need for comprehensive reachability and the development of standardized connectivity, as outlined in 3GPP Release 17, this collaboration allows mobile and fixed operators to expand coverage to remote locations and for satellite operators to tap into new customer bases.

Operators are also focusing on technical advancements to monetize their 5G networks effectively. This includes transitioning from non-standalone (NSA) to standalone (SA) mobile cores, which is essential for enabling advanced 5G capabilities. 5G SA cores are required to launch many capabilities supporting ultra-reliable low latency communications (URLLC), massive machine-type communications (mMTC), and network slicing.

Preparations are underway for 5G-Advanced (3GPP Release 18), with features like non-terrestrial networks (NTN), extended reality (XR), and advanced MIMO. The investment will be fundamental for advancing to 6G.

Another critical development is RAN decomposition and virtualization, which involves breaking down the RAN into individual components and running functions on commercial off-the-shelf hardware. Benefits include better utilization, greater scalability and flexibility, and cost reductions. Implementing decomposition and virtualization using O-RAN promises these benefits while breaking RAN vendor lock-in due to standardized, open interfaces.

Edge infrastructure investment is increasing to support new enterprise applications, integral to 5G SA and 5G-Advanced, by moving processing closer to end users, thereby reducing latency, and serving as a critical driver for cloud-native technology adoption. This approach requires flexible deployment of network functions either on-premises or in the cloud, leading to a decentralization of network traffic that was once concentrated. This evolving trend has become more pronounced with increasing traffic demands, blending network roles and boundaries, and creating a versatile network “edge” within the CSP’s framework.

Operational savings, including cost reduction and sustainability initiatives, are top priorities for CSPs to meet budgetary and carbon footprint goals.

Preparing your mobile transport for 5G Advanced and beyond

Mobile packet transport is critical in these initiatives and network transformation, leading to rapid changes in CSP transport networks. Traditionally, these networks relied on dedicated circuits and data communication appliances. However, modern transport is shifting toward a logical construct using any accessible hardware and connectivity services. Successful network architecture now hinges on the ability to seamlessly integrate a variety of appliances, circuits, and underlying networks into a unified, feature-rich transport network.

The Cisco converged, cloud-ready transport network architecture is a comprehensive solution designed to meet the evolving demands of 5G-Advanced and beyond. The architecture is particularly important for operators to navigate the complexities of 5G deployment, including the need for greater flexibility, scalability, and efficiency. Here’s a detailed look at its essential components:

Converged infrastructure: Cisco’s approach involves a unified infrastructure seamlessly integrating various network services across wireline and wireless domains. This convergence is essential for supporting diverse customer types and services, from consumer-focused mobile broadband to enterprise-level solutions. The infrastructure is designed to handle all kinds of access technologies on a single network platform, including 4G, 5G, FWA, and the emerging direct satellite-to-device connectivity outlined in 3GPP’s NTN standards.
Programmable transport and network slicing services: At the heart of Cisco’s architecture are advanced transport technologies like Border Gateway Protocol (BGP)-based VPNs and segment routing (SR), crucial for a unified, packet-switched 5G transport. These technologies enable a flexible services layer and an efficient underlay infrastructure. This layering provides essential network services like quality of service (QoS), fast route convergence, and traffic-engineered forwarding. Network slicing is also a key feature, allowing operators to offer customized, intent-based services to different user segments. This capability is vital for monetizing 5G by enabling diverse and innovative use cases.
Cloud-ready infrastructure: Recognizing the shift toward cloud-native applications and services, Cisco’s architecture is designed to support a variety of cloud deployments, including public, private, and hybrid models. This flexibility ensures that the transport network can adapt to different cloud environments, whether workloads are on-premises or colocated. Virtual routers in the public cloud play a significant role here, providing required IP networking functions (including BGP-VPN, SR, and QoS).
Secure and simplified operations model: Security and operational simplicity with service assurance are essential components in Cisco’s architecture. The network is designed for easy programmability and automation, which is essential for operational efficiency and cost reductions. This includes extensive telemetry and open APIs for easy integration with orchestration tools and controllers. Additionally, AI and machine learning technologies can potentially be used for real-time network visibility and actionable insights for optimizing user experience across both wireline and wireless networks.

The architecture is about current 5G capabilities and future readiness. Preparations for 5G-Advanced and the eventual transition to 6G are integral. The architecture’s design ensures operators can evolve their networks without major overhauls, thereby protecting their investment.

Cisco’s converged, cloud-ready transport network architecture offers a blend of technological innovation, operational efficiency, and flexibility, enabling operators to navigate the challenges of 5G deployment while preparing for the subsequent phases of network evolution.

Learn more on how to evolve 5G networks for future opportunities:

Heavy Reading: Transform Your Transport Network for 5G-Advanced & Beyond
Light Reading Webinar: 5G Cloud-Ready Converged Transport

Heavy Reading: Transform Your Transport Network for 5G-Advanced & Beyond

Share

"}]]  Monetizing 5G networks requires optimizing the mobile transport with cloud-ready, converged, programmable infrastructure that is simpler to operate.  Read More Cisco Blogs 

By |2024-02-27T17:52:49+00:00February 27, 2024|Cisco: Learning|0 Comments

Benefits of Ingesting Data from Amazon Inspector into Cisco Vulnerability Management Ahmadreza Edalat on February 27, 2024 at 1:00 pm

Co-authored by Tejas Sheth, Sr. Security Specialist, Amazon Web Services – AISPL.

Risk-based Vulnerability Management (RBVM) represents a strategic approach to cyber security that focuses on… Read more on Cisco Blogs

​[[{"value":"

Co-authored by Tejas Sheth, Sr. Security Specialist, Amazon Web Services – AISPL.

Risk-based Vulnerability Management (RBVM) represents a strategic approach to cyber security that focuses on identifying and prioritizing vulnerabilities based on the potential risk they pose to an organization. This approach builds upon traditional vulnerability management, which often involves scanning for and patching all vulnerabilities without considering their actual impact on the business. In RBVM, vulnerabilities are evaluated based on factors like the criticality of the affected system, the sensitivity of the data involved, and the likelihood of exploitation by threat actors. In doing so, organizations can more effectively prioritize vulnerabilities to focus on the risk the matters most in their environments.

In this blog, we’ll show you how you can ingest your cloud-specific vulnerability findings from Amazon Inspector into Cisco Vulnerability Management for a consolidated, risk-based approach to effectively address vulnerabilities.

First, let’s introduce you to both solutions and the value they bring.

Amazon Inspector

Amazon Inspector is a security assessment service designed to help AWS customers improve the security and compliance of their applications deployed on AWS. It automatically assesses applications for vulnerabilities or deviations from best practices. After performing an assessment, Amazon Inspector produces a detailed list of security findings prioritized by level of severity. These findings can be integrated with other services for in-depth vulnerability analysis and management, enabling AWS users to take actionable steps towards remedying potential security issues.

Amazon Inspector calculates its unique Inspector Score based on a variety of factors beyond the Common Vulnerability Scoring System (CVSS). This includes assessing whether the network is reachable from the internet, the CVSS score itself, and other proprietary parameters. which provides a numerical score reflecting the severity of a vulnerability based on its intrinsic qualities, the Inspector Score also considers the context of the AWS environment to prioritize issues more effectively.

Details provided by Amazon Inspector include:

Mapping of findings to MITRE ATT&CK techniques (TTPs),
Evidence details,
Information on known malware,
References to CISA advisories,
Resources affected,
Remediation steps, and
Affected packages.

Amazon Inspector also supports the export of Software Bill of Materials (SBOM), CIS (Center for Internet Security) benchmark scanning for EC2 instances, and offers scanning capabilities for AWS Lambda, container images in Amazon Elastic Container Registry (ECR), and Amazon EC2 instances without the need for agent installation or manual intervention, enhancing the security posture with minimal overhead.

Cisco Vulnerability Management

Cisco Vulnerability Management, a risk-based vulnerability management SaaS solution, prioritizes vulnerabilities that pose a real risk, enabling Security and IT teams to focus their limited resources on what matters most for efficient remediation and risk reduction. With risk scoring powered by data science—machine learning and patented approaches to predictive modeling—Cisco’s prioritization evaluates both enterprise data and a wealth of data on real-world exploit activity and then translates that context into actionable intelligence to guide remediation decisions and resource allocation. Data from tools like Amazon Inspector can be easily ingested into Cisco Vulnerability Management for a holistic approach to risk-based prioritization.

Cisco Vulnerability Management uses threat and exploit intelligence from 19+ feeds, including Cisco Talos, and uses the only dataset on volume and velocity of exploitation in the wild. These data sources build a machine learning model for vulnerability risk. This model is then combined with asset criticality that can be pulled automatically from a CMDB or manually inputted by a user, the asset’s position in the network, and the patch level aggregation to provide recommendations, risk assessments, and measure risk over time on the vulnerability, asset, and group of assets level.

Using the Amazon Inspector Toolkit Connector for Cisco Vulnerability Management

When Amazon Inspector asset and vulnerability data is ingested into Cisco Vulnerability Management, it enhances the vulnerability management process by integrating cloud-specific security insights into a broader vulnerability management strategy. Through this integration, organizations can take advantage of:

Data Aggregation: Amazon Inspector’s findings, which include identified vulnerabilities and their details, are imported into Cisco Vulnerability Management. This process consolidates data from various sources, including cloud environments, providing a unified view of security vulnerabilities across the organization’s infrastructure.
Risk Analysis and Prioritization: Cisco Vulnerability Management applies its risk-based vulnerability prioritization approach to the ingested data from Amazon Inspector and other sources. This means it assesses and prioritizes vulnerabilities based on various factors such as the severity of the vulnerability, the exploitability, the criticality of the affected asset, and the presence of known exploits in the wild. This prioritization helps in focusing remediation efforts where they are most needed.
Actionable Insights and Remediation Guidance: Cisco Vulnerability Management offers actionable insights and guidance on how to remediate identified vulnerabilities. It provides context and intelligence that helps security teams understand the potential impact on each vulnerability and the best steps to mitigate them.

Guided Steps on Configuring the Integration

The Amazon Inspector toolkit is a set of functions for data and API scripts you can use with the Cisco Vulnerability Management platform. It’s organized into tasks—units of functionality that can be called and used from the command line.

Step 1

Pull the latest image available on Docker Hub. See Running The Latest Image section for exact set of commands to perform this task.

Step 2

To bring in asset and vulnerability data from Amazon Inspector, start by running the Docker image with AWS Inspector as task and providing the correct AWS authentication method.  This integration supports several kinds of authentication methods provided by AWS SDK. You can find the list of supported authentication methods under AWS Authentication.

The below command is an example of running the Docker image with task as AWS_inspector2 and using IAM roles for authentication:

docker run -v ~/.aws:/root/.aws –env AWS_REGION=us-east-1 –env AWS_PROFILE=inspector_test –rm -it toolkit:latest
task=aws_inspector2 aws_role_arn=””arn:aws:iam::123456789012:role/Inspectorv2ReadOnly””

Step 3

Click the Data Importer connector under the Connectors tab in Cisco Vulnerability Management:

Create the connector by adding a Name and Asset Inactivity Limit and click Save:

Step 4

If you leave off the Cisco Vulnerability Management (formerly Kenna) API Key and Connector ID in step 2, the task will create a JSON file in the default or specified output directory. You can upload the JSON file manually to the connector created on the UI in Step 3 to verify the resulting data and diagnose any issues with the JSON file.

Step 5

Click into the newly created Connector and record the Connector ID (this Connector ID is needed for Step 7):

Step 6

In previous steps, we manually uploaded the JSON file on Cisco Vulnerability Management. Now, we can automate this process through the Command line using Cisco Vulnerability Management API Key and Connector ID. To generate an API Key, follow these steps.

Step 7

Run the task with your Cisco Vulnerability Management (formerly Kenna) API Key & Connector ID (IAM role authentication is used in the command below).

docker run -v ~/.aws:/root/.aws –env AWS_REGION=us-east-1 –env AWS_PROFILE=inspector_test –rm -it toolkit:latest
task=aws_inspector2 kenna_api_key=$KENNA_API_KEY kenna_connector_id=12345 aws_role_arn=””arn:aws:iam::123456789012:role/Inspectorv2ReadOnly””

For more details, check out this connector task on GitHub. Note: The task currently only handles package vulnerabilities, not code vulnerabilities (in AWS Lambda) or network reachability findings. Suppressed findings in Amazon Inspector don’t exactly map to “risk accepted” or “false positive” in Cisco Vulnerability Management, so they are treated as open vulnerabilities.

Ready to get started?

Reach out to your Cisco representative today to learn more about ingesting data from Amazon Inspector into Cisco Vulnerability Management for a consolidated view of risk and effective prioritization.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

"}]]  Learn how you can ingest your cloud-specific vulnerability findings from Amazon Inspector into Cisco Vulnerability Management for effective prioritization.  Read More Cisco Blogs 

By |2024-02-27T17:52:49+00:00February 27, 2024|Cisco: Learning|0 Comments

Where Is DevNet Going Over the Next 10 Years, and Beyond? Matt DeNapoli on February 27, 2024 at 4:30 pm

Wow! It’s been 6 months since I wrote my last DevNet 10-year blog, ruminating on the creation and history of Cisco DevNet. Since then, the marking of our 10 year anniversary has exploded with i… Read more on Cisco Blogs

​[[{"value":"

Wow! It’s been 6 months since I wrote my last DevNet 10-year blog, ruminating on the creation and history of Cisco DevNet. Since then, the marking of our 10 year anniversary has exploded with in-person events at Cisco Live! in Melbourne and Amsterdam and a virtual celebration coming up on March 14th. I want to start this blog by saying a big “THANK YOU!” to our community for helping us look back and recognize the wonderful accomplishments we have had over these 10 years.

With this blog, I’d really like to dig into the future. It seems that we are hitting a major inflection point within the broader high-tech industries; one that is potentially as influential and challenging as the introduction of cloud and microservices architectures 10-15 years ago. Organizations had to learn how to navigate that paradigm shift and deal with issues they had never encountered before. Issues like tool sprawl, hybrid application deployments, virtual networking, container orchestration, and increased security attack vectors. On top of those technical concerns there was an added operational challenge of optimizing costs across on-premises versus cloud deployments. Out of those challenges a burgeoning need for observability has presented itself.

Focus on AI and sustainability

This time, however, the focus is on AI and sustainability, and possibly more importantly the role that observability can play in supporting solutions in both areas. At points, implementations of AI and sustainability efforts may contradict each other in practical application. However, improvements in tooling, born of the cloud revolution mentioned above, allow us to dynamically build visibility directly into the solution at all technology layers. This provides the opportunity for both reactive, and more importantly proactive, actions to be taken to optimize activity at any of those layers individually or in concert with each other.

So now, you are at the point of reading this going “that all sounds fine and good Matt, but how does DevNet and the organization’s future factor into all of this?”

Excellent question. And to that I answer “DevNet will be the glue.”

For 10 years, DevNet has been the face of programmability and automation for Cisco. Infrastructure as Code, NetDevOps, etcetera, we were there with documentation, sandboxes, sample code, learning labs, live events , and practical experience supporting our community as they glued together various products to build out amazing solutions that changed the way we work. We are now in the midst of upleveling all of that to bring a solution focus to all of the content and experience we provide so that you can move even more quickly.

Ten years ago, we started with very little and had to ramp programmability and integration aspects of Cisco’s portfolio VERY quickly. This pushed us into a “more is better” mindset so that we could make sure we had full coverage for our partners and customers in any product space. That worked well for a while, but now there is so much out there that we need to boil down to the essentials.

Quality over quantity

Over the next few months, you will see a host of changes that reflect a “quality over quantity” mindset. You may have even noticed a few of them already!

We have redesigned our learning labs and documentation catalogs, and are in the midst of improving our API reference experience to make OAS specification documentation easier and clearer to use.
Our Sandbox team just migrated their overwhelmingly valuable service to a new platform.
We are also working on optimizing our search functionality and implementing AI into our tooling to promote content recommendations for individual areas of interest.
Dynamic content will abound as we provide the latest and greatest on our homepage and in our product Dev Centers.
Even our community is being revamped to be a more useful, insightful, and collaborative place to visit.

All of this is being done to help you navigate Cisco and DevNet, and make it easier to build your solutions.

As for AI, sustainability, and observability, keep an eye out for new Topic Hubs, documentation, learning labs, and sample codes in those spaces. We will be providing thought leadership and practical content that allows you to peek behind the curtain of AI and understand the nature of predictive and generative AI.

On the sustainability front, we will be curating solution focused material to allow you to realize energy usage optimization within your organization. As for observability, we will be showcasing solutions across the entire stack.

Finally, we will continue celebrating our community throughout the next 10 years, starting with our virtual 10th Anniversary Celebration on March 14. The event will celebrate milestones we’ve achieved throughout the past ten years, and expand on the ideas outlined in this blog like AI and Sustainability. As always, in June we hope to see you at Cisco Live in Las Vegas. In the meantime, stay tuned as we prepare to announce even more opportunities to learn, code, and build.

Share

"}]]  For 10 years DevNet has been helping developers address technical issues such as hybrid application deployment, virtual networking, container orchestration, and security. Now we'll be there as you tackle observability, AI, and sustainability challenges.  Read More Cisco Blogs 

By |2024-02-27T17:52:48+00:00February 27, 2024|Cisco: Learning|0 Comments

Sustainability 101: What are ecolabels? Klaus Verschuere on February 26, 2024 at 4:00 pm

Do you feel a bit lost when people refer to certain environmental sustainability topics and aren’t sure where to start when it comes to learning more? Sustainability 101 is a blog series that you can … Read more on Cisco Blogs

​[[{"value":"

Do you feel a bit lost when people refer to certain environmental sustainability topics and aren’t sure where to start when it comes to learning more? Sustainability 101 is a blog series that you can turn to for information about different environmental terms that may come up at work, during discussions with friends, and even at your annual holiday gathering.

Many companies want to show how they are making their products more sustainable. That’s where ecolabels come in. Ecolabels are marks indicating that the products meet objective environmental and sustainability criteria. Ecolabels are placed on product packaging, on the product itself, accompanying documentation, or on other means such as web based.

According to the U.S. Environmental Protection Agency (EPA), ecolabels can help consumers and institutional purchasers quickly and easily identify those products that meet specific environmental performance criteria and are therefore deemed “environmentally preferable”. Ecolabels can be owned or managed by government agencies, nonprofit environmental advocacy organizations, or private sector entities

Different types of ecolabels

According to Ecolabel Index, there are over 450 ecolabels available worldwide, covering different industry sectors (including carpets, cosmetics, or even coffee beans) and geographies. The International Organization for Standardization (ISO) has a series of international standards for environmental management that apply to ecolabels and divides them into categories. ISO 14020 classifies ecolabels as Type I, Type II, or Type III, as follows:

Type I (ISO 14024), commonly known as ecolabelling schemes: This category covers third-party certification processes to verify product or service compliance with a pre-selected set of criteria.
i.e.: THEY say my product has sustainability benefits.

Type II (ISO 14021): This category covers self-declared ecolabels, based on objective standards, that may cover environmental claims.
i.e.: I say my product has sustainability benefits.

Type III (ISO 14025): The third category covers self-declared conformance to predetermined categories of parameters based on ISO 14040, but without conclusions on whether that conformity means the product has sustainability qualities.
i.e.: Here are my results, it is up to YOU to judge if my product has sustainability benefits.

Type I ecolabels are considered comprehensive and ambitious. They are generally assigned to products that go beyond regulatory requirements, including in the areas of energy efficiency, resource consumption or greenhouse gas (GHG) emissions. These Type I ecolabels identify and promote products with reduced adverse impacts.

Ecolabels are not to be confused with an “energy” label, which is used to indicate the energy efficiency of a consumer product. In the European Union (EU), this energy label is mandatory for certain products such as refrigerators, washing machines or televisions and uses a scale from G (least efficient) to A+++ (most efficient) to indicate the energy efficiency of a product.

Ecolabels for electronic B2B equipment

Relevant ecolabels for electronic B2B equipment vary from focusing on energy only (80 PLUS®, ENERGY STAR®) to others that go further than this, by including more environmental and social aspects (EPEAT, TCO Certified, etc.).

1. 80 PLUS: A voluntary Type I certification program launched in 2004, intended to promote efficient energy use in power supply units (PSUs). The certification measures the energy efficiency at 10%, 20%, 50%, and 100% of rated load and a power factor. It offers six levels of certification: Standard, Bronze, Silver, Gold, Platinum, and Titanium.

2. ECMA 370: A Type II scheme that can be used by companies to declare if and which environmental attributes (such as recycling, reduction of hazardous substances, and energy consumption) are met and to show which measurement methods were applied for information and communication technology (ICT) and consumer electronics according to known standards, guidelines, and currently accepted practices.

3. ENERGY STAR: A voluntary program that is run and verified by the U.S. EPA and DOE. The program focuses on the energy consumption of products using standardized methods. It aims to help customers save money on their energy bills and reduce greenhouse gas emissions. There are ENERGY STAR programs available for, among other, enterprise servers, large networking equipment (LNE), small networking equipment (SNE) and Voice over Internet Protocol (VoIP) Phones.

4. EPEAT: A Type I ecolabel which is managed by the Global Electronics Council (GEC) based on criteria that evolve as sustainability evolves – measuring the social and environmental impacts of products from extraction to end of life.  EPEAT certification is recognized by several governments and large businesses in their procurement practices.

5. TCO Certified: TCO Certified is a global sustainability certification for IT products. It includes both social and environmental aspects and helps purchasing organizations and the IT industry address the most important sustainability challenges connected to electronics, such as climate, circularity, hazardous substances, and supply chain responsibility. All criteria are mandatory and compliance with all criteria is independently verified by accredited experts.

6. EU Ecolabel: The European Union’s (EU) ecolabel, managed by the European Commission and EU Member States, is a voluntary EU-wide Type I ecolabelling scheme. It covers many types of non-food products. The only product group covering electronics is electronic displays, and includes televisions, computer monitors, and signage displays.

7. Environmental Product Declaration (EPD): An EPD is a document that is based on ISO 14025 (Type III). As such, it is used to communicate the environmental performance of a product to stakeholders and provides quantified information about the environmental impact of a product or material over its lifetime. It is based on the Lifecycle Assessment (LCA) methodology, which evaluates the environmental impact of a product from raw material extraction to disposal.

Why are ecolabels important?

The public sector also uses ecolabels to encourage behavioral change. Due to Green Public Procurement rules, many government institutions prioritize procurement, where applicable, of products that meet specific sustainability requirements such as ENERGY STAR or EPEAT.

Ecolabels are also becoming more important given the global trend toward greater taxonomy frameworks and regulation regarding sustainability-related activities and Green Claims.

Lastly, under certain conditions, ecolabels may potentially be leveraged by stakeholders as a valid approach for self-regulation.

Where does Cisco stand regarding ecolabels?

At Cisco, we apply Circular Design Principles and strive to improve the energy efficiency of our products to reduce our environmental footprint. Ecolabels are one way to share some of the results of these efforts.

Ecolabels don’t apply to everything Cisco sells, but — where applicable — Cisco’s products are evaluated against the following Type I ecolabels: ENERGY STAR, EPEAT and 80 PLUS.

Cisco currently has products certified to the ENERGY STAR standard under the Enterprise Server and Telephones categories. We also have EPEAT-registered products under the Servers category listed in EPEAT´s online Registry.

And Cisco has power supply units (PSUs) certified to 80 PLUS listed on CLEAResults’s online database. The majority of our PSUs have achieved Platinum status, and our UCS servers are rated Titanium.

We’re continuously striving for transparency in our reporting on our environmental, social, and governance (ESG) initiatives, goals, and progress.

Learn more about our experience with ecolabels on our

ESG Reporting Hub.

Share

"}]]  Many companies want to show how they are making their products more sustainable. That’s where ecolabels come in.  Read More Cisco Blogs 

By |2024-02-27T04:52:01+00:00February 27, 2024|Cisco: Learning|0 Comments

DevNet Sandbox Has a New Look & Feel Mike Mackay on February 26, 2024 at 4:01 pm

If you’ve played in the DevNet Sandbox lately, you probably noticed some changes. Well, it’s a lot more than a repaint. It’s a full forklift upgrade. The changes you see are a complete re-fit of the e… Read more on Cisco Blogs

​[[{"value":"

If you’ve played in the DevNet Sandbox lately, you probably noticed some changes. Well, it’s a lot more than a repaint. It’s a full forklift upgrade. The changes you see are a complete re-fit of the entire sandbox automation platform from the ground up. At the top level we have our new home page, this has been rebuilt and now matches the rest of the DevNet sites look and feel, and ties in tighter with our metadata for searching, and with the future recommendations.

The Sandboxes

We have moved from a very custom and bespoke automation platform to a model driven approach. What does that mean?
A Sandbox Blueprint is now a Terraform based model. Each sandbox is made up of multiple components (e.g. DevBoxes, CML, NSO etc.). These are now a set of predefined components, expressed in YAML, that can be mixed and matched to build a sandbox. Of course there is no magic, so underlying the YAML model the usual components exist. However, being able to treat them as data makes mixing and matching easier. Aside from the fact this is cool, and makes our job easier, it means Sandbox users will receive updates faster.

Overall, you’ll find the UI to be cleaner and easier to use. Some specific changes include:

There is an option to ‘Favorite’ a Sandbox if you use the same one multiple times.
The resources tab shows a list of the resources available inside the reservation. (This is a work in progress, see upcoming changes below.)
We checked and updated all the instructions, hopefully they are cleaner and easier to read.
VPN, and in some cases other info, is available in the Quick Access tab.
When reserving a CML sandbox you can select a simulation.

Some known areas for improvement

In some situations the resources tab shows “No available resources” – this is very noticeable for Always On Sandboxes because the resources are shared. We will be implementing a tweak for this over the next few weeks.
Adding additional information into the Quick Access tab depending on the need.
In the old platform there were restrictions on the number of simultaneous instances of a specific sandbox, due either to a hardware limitation (number of hardware devices) or compute/storage capacity. We did not add new hardware, so these limitations continue to exist.
In addition, there were some Sandboxes that were limited due to capacity constraints. We started the new environment with these cranked down a little, CML is the most obvious. We will continue to increase this count until we reach capacity.
There is no reserve in the future feature, no current work around but it’s high on our hit list to resolve (ties into above)

Upcoming changes

The Resources Tab will have the available resources listed.
We will be adding a feature allowing direct access to a device from the GUI, Guacamole style. This means you will be able to SSH to a router for example. I have no doubt there will be quirks so this will be a phased rollout as we test each sandbox.
The error messages are confusing and technical. These will be cleaned up to make sense to the user, not just us.
We are actively increasing our capacity. Over the next 3-4 weeks we should be able to double our current, this will allow us to really ramp up the number of simultaneous sandboxes.

We have a roadmap of additional features we will be introducing over time, and they will be posted as we release them.

Share

"}]]  The ground up upgrade takes a model driven approach, with predefined components expressed in YAML. These can be mixed and matched to build a sandbox, so upgrades are available sooner to sandbox users.  Read More Cisco Blogs 

By |2024-02-27T04:52:00+00:00February 27, 2024|Cisco: Learning|0 Comments

The Quick and Easy Solution to Lagging 5G Monetization Bob Everson on February 26, 2024 at 11:18 pm

Looking for a quick and easy solution to lagging 5G monetization? Here’s a hint: it’s not just about the G. Initially hailed as a global savior, and more recently labeled a disappointment, the rea… Read more on Cisco Blogs

​[[{"value":"

Looking for a quick and easy solution to lagging 5G monetization? Here’s a hint: it’s not just about the G. Initially hailed as a global savior, and more recently labeled a disappointment, the reality of 5G exists somewhere in between these extremes. The truth is, these oversimplified perspectives tend to overshadow the true value and effort required, while keeping the focus on the wrong problems.

Building on lessons from 4G

Previous generations were primarily driven by clear, consumer-oriented benefits. To put it simply, 3G brought usable data to our phones, while 4G gave us true broadband speeds. Both saw considerable demand, with 4G unlocking a surge of innovative applications on smart phones, further boosting demand.

The arrival of 5G, promising even greater network speed and capabilities, was expected to follow the same trajectory. However, this failed to consider that despite 5G’s impressive potential, a more comprehensive ecosystem is required to fully exploit these capabilities. Otherwise, it isn’t clearly differentiated from 4G.

One vital lesson from the 4G era is that Service Providers (SPs) can easily be sidelined in the value equation. SPs, despite their significant investments, often found themselves on the outskirts of the most profitable aspects of the value chain, with most of that going to the application providers and device ecosystem. This was a result of multiple factors, not the least of which is that the complexity of traditional mobile networks makes it difficult to integrate with them and build on top, so they were built around instead. Additionally, the market was looking for global scale and less friction in business interactions which is difficult with traditional mobile architectures.

This 5G era offers a chance for SPs to get back in at higher value, and we are focused on enabling this as you’ll see below.

A new approach for 5G

The excessive hype and fixation on 5G as a panacea for all connectivity has created unnecessary confusion. This led to misunderstandings about 5G vs. Wi-Fi and even 5G vs 4G. The industry is gradually moving past this, with Enterprise IT and OT buyers making it clear that they want more focus on achieving their business outcomes supported by a heterogeneous network that allows them to choose the best connectivity solution for a given use case and environment.

Enterprise customers do view 5G as an important tool for connectivity, but it must coexist with Wi-Fi, 4G, Ethernet, and more. Each has its place, and the breakthrough that is needed is for an all-encompassing, access-agnostic approach empowering the mobile-first enterprise.

Separating 5G fact from fiction

We have all heard variations of the following statements about the promise of 5G:

Once we allocate spectrum, 5G will skyrocket!
5G radios will outperform 4G, driving demand!
Superior 5G smartphones will increase demand!
5G NSA is the easy transition to 5G we need!
5G SA, with its superior capabilities and efficiency, will drive demand!

While these are all necessary, they are not sufficient for true success.

So, how do we get there?

To fully address this, we must begin with the end customer in mind. Enterprises clearly see digital transformation as their goal, not adopting a specific technology. They need simple, unified solutions that provide seamless secure connectivity, and support value-added services for people, places, and things. This becomes even more crucial in the contemporary AI-driven landscape, which requires more data from an increasing number of devices and facilitates the development of countless applications.

Achieving this requires a broader ecosystem facilitated by a true platform-based approach that modernizes mobile service definition, integration, and delivery. This will enable rapid service development with flexible business models, democratizing IoT and connectivity while allowing all stakeholders to deliver value. It’s essential to remember that while we love to talk about “the technology,” it is only useful in service of business outcomes. Paramount among these is reducing business friction, and allowing global scale – build once, distribute everywhere, and monetize easily.

We’ve developed the Cisco Mobility Services Platform to increase the value of mobile services by making them more accessible and programmable, reducing the complexity of delivering new services while increasing speed and flexibility. Importantly for SPs – this presents an opportunity to move up the value chain from where they were largely relegated in the 4G era. This is the time to fully embrace and enable the mobile-first enterprise in a holistic and unified manner.

But don’t just take my word for it. Join us at Mobile World Congress Barcelona 2024,to see our Mobility Services Platform in action, along with demonstrations of how we’re uniting the ecosystem to simplify the process for all key stakeholders.

Specifically, you’ll see our developer ecosystem and how we’re enabling application developers by making it simple to build on top of mobile networks. You’ll also see how we’ve embraced an open approach to radios and devices.

We will have a live 5G system simulating a connected warehouse with our Mobility Services Platform enabling radios, devices, and applications from our ecosystem partners including Nokia and Zebra, along with Cisco Industrial IoT and Meraki devices. Elsewhere in the Fira, you will see our partners illustrating the power of the platform and ecosystem with some exciting use cases.

Intel – Cisco Private 5G using a Neutral Wireless radio, focusing on AI and manufacturing use cases
NTT DATA – Cisco Private 5G and AI driven vision
Deloitte – Cisco Private 5G using an Airspan radio, focusing on an AGV use case
Orange – Sport All IP
HCLTech –Cisco Private 5G with collaboration and expert on demand

Engage with us at MWC

Most importantly, we want to hear from you. We believe we’ve built something unique and would love to showcase our work, as well as listen to your ideas. There’s room in this ecosystem for everyone – MNOs, Enterprises, applications, devices, radios, integrators, and more.

Read our Mobility Services Platform Solutions Overview
and discover how we’re enabling the full potential of 5G

Catch our recent webinar: Unlock New 5G and IoT Revenue
Streams with Cisco Mobility Services

Share

"}]]  Initially hailed as a global savior, and more recently labeled a disappointment, the reality of 5G lies somewhere in between. The truth is, these oversimplified perspectives tend to overshadow the true value and effort required, while keeping the focus on the wrong problems.  Read More Cisco Blogs 

By |2024-02-27T04:51:59+00:00February 27, 2024|Cisco: Learning|0 Comments

The AI Threat Landscape: Tech Companies and Governments Must Unite Behind Cybersecurity in 2024 Cisco Newsroom: Security

Tech companies and governments will join forces to develop advanced [...]

By |2024-02-27T04:51:51+00:00February 27, 2024|​Cisco Newsroom: Security|0 Comments

Drive Your Cybersecurity Platform Transformation: Lead the Way With SSE Bill Mabon on February 26, 2024 at 1:00 pm

By shifting from point-solutions to a cybersecurity platform approach, IT and security teams significantly improve their efficiency and security outcomes. Security Service Edge (SSE) projects are… Read more on Cisco Blogs

​[[{"value":"

By shifting from point-solutions to a cybersecurity platform approach, IT and security teams significantly improve their efficiency and security outcomes. Security Service Edge (SSE) projects are often an excellent first step in taking a platform-centric security approach. SSE optimizes hybrid work with secure, high-performance, application access that is coupled with integrated threat defense and data protection. Cloud-delivered, it simplifies deployment its operational elasticity flexibly grows with you.

Guiding principles for successfully adopting a cybersecurity platform

Simplify According to Gartner, 75% of organizations are aiming to consolidate security vendors. Cisco supports this customer objective with its broad and tightly integrated cybersecurity platform. Our approach complements your existing security investments and honors your preferences. For proof of that commitment, look no further than the new Cisco XDR — it integrates with Cisco SSE and our Cisco Secure Endpoint EDR, as well as EDR capabilities from other vendors.
Address today’s realities — Business thinker Peter Drucker noted, “The greatest danger in times of turbulence is not the turbulence; it is to act with yesterday’s logic.” Managing poorly integrated point-security solutions is a dead end. Don’t let yesterday’s logic for bespoke point solutions, which heightens integration costs and creates visibility and policy gaps, dictate your go-forward security strategy. Our new User Protection Suite cost-effectively simplifies cybersecurity platform adoption with cloud-native SSE, plus Cisco Duo multi-factor authentication, Email Threat Defense, and our Secure Endpoint EDR.
Select tooling carefully — A cybersecurity platform must be built for the real world. Operational agility requires careful tool selection that accommodates your security maturity plan. With the dissolution of traditional perimeters, Cisco Secure Access SSE uniquely combines ZTNA with VPNaaS. Unlike competing solutions, it ensures workforce access to all required applications and resources, uniquely enabling an evolution to ZTNA on your timeline.

Think tightly integrated Swiss Army Knives

One way of thinking about Cisco’s cybersecurity platform approach in that it delivers a series of tightly integrated Swiss Army Knives. Cisco Secure Access SSE delivers ZTNA, VPNaaS, DNS-layer security, CASB, DLP, SWG, and more. The Cisco Secure Client that our SSE integrates with merges five installer packages into a single client, reducing IT overhead and enhancing your security framework. Modules include:

Cisco AnyConnect ZTNA/VPN
Cisco Secure Endpoint EDR
SSE Secure Web Gateway (SWG) + DNS-layer protection

Our approach reduces complexity in multiple ways: First, our SSE includes unified policies across security functions, then Cisco Secure Client reduces the number of endpoint installations you must test and deploy. Because of this investment, we’ve been able to recently announce the end-of-life of the Cisco Umbrella Roaming Client, as all roaming client functionality is now available in Secure Client’s Umbrella Roaming Module. Read more about the migration of Umbrella Roaming Client to Cisco Secure Client on our Umbrella blog.

The move to Cisco Secure Client is an opportunity to reduce complexity and enhance security, with a pathway for enabling Zero Trust Network Access (ZTNA).

ROI proven by Forrester

This year, Forrester Consulting interviewed Cisco customers and performed an independent Total Economic Impact study of Cisco SSE, reporting that Cisco SSE customers realized a:

231% return on investment over three years
65% reduction in the effort to deploy and enforce web and cloud security policies
30% security efficacy improvement that helped reduce data breaches by 21%

Case study: Homes England

Take the case of Homes England, where Justin Hannan, Head of Platforms & Infrastructure, experienced firsthand the benefits of security integration. By incorporating part of our Secure Access SSE portfolio, Cisco Umbrella, Hannan noted, “We have integrated the Cisco Umbrella solution, which helps us shift more to cloud delivered services and with the integration of these two solutions [Umbrella, AnyConnect VPN/ZTNA] it gives a more efficient management of both.”

Embracing a unified strategy and integrated future

Cisco’s XDR, SSE, the consolidated Secure Client, and our security suites demonstrate Cisco’s commitment to comprehensive cybersecurity that delivers better efficacy and business outcomes. For more information, talk with a Cisco User Protection expert today.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

"}]]  SSE projects are often an excellent first step in taking a platform-centric security approach, helping IT and security teams improve efficiency and outcomes.  Read More Cisco Blogs 

By |2024-02-26T15:50:45+00:00February 26, 2024|Cisco: Learning|0 Comments
Go to Top