About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

Climate Finance Tracker: Mapping the Climate Finance Ecosystem Peter Tavernise on August 15, 2023 at 1:00 pm

This blog was prepared with deep thanks to Cisco employee volunteer Haitham Al-Shabibi.

Climate change is an issue we can’t solve alone, yet it seems like very few of those working to solve it have a… Read more on Cisco Blogs

This blog was prepared with deep thanks to Cisco employee volunteer Haitham Al-Shabibi.

Climate change is an issue we can’t solve alone, yet it seems like very few of those working to solve it have a big picture view of who is already working on what or where their work fits into the broader solutions landscape. Without a collaborative approach, effectiveness of private philanthropic and impact investment capital is severely limited. Climate funders need transparency, effective tools, and a holistic view of the landscape in order to make better decisions to set high-impact priorities.

The Climate Finance Tracker (CFT) is a suite of visual interfaces engineered by Vibrant Data Labs (VDL), an organization housed in Berkeley, California, that combines data and network theory into flexible tools, to tackle systemic social challenges like climate change. The CFT visualizes climate funding flows to organizations and companies on the ground. What started as a simple United States finance tracker is now poised to scale into Europe, Africa, and Latin America.

In 2021, VDL became a recipient of a grant via Cisco Foundation’s Climate Impact & Regeneration commitment to build out an initial prototype of the CFT. Since launching the CFT fall of 2022 in partnership with One Earth & Impact Alpha, they have been overwhelmed by the positive response. It has led to active collaborations with Climate Policy Initiative, ClimateWorks Foundation, Elemental Excelerator, Forbes, Global Commons Alliance, Summit Impact, and TED.

The partnership between Vibrant Data Labs and Cisco Foundation is built on the shared belief that by building capacity, improving transparency, and supporting funders and decision makers, efforts addressing the climate crisis can be much more effective.

We recently caught up with Eric Berlow, founder of Vibrant Data Labs and co-creator of the CFT, who was awarded an Emerson Collective Climate Fellowship. He shared more about his background, philosophy, and goals.

Can you tell us a bit more about your background?

Eric and other students surveying threatened alpine amphibians in Yosemite National Park.

Eric: Yes, so I have a PhD in marine ecology and in particular I work to understand nature as a complex system. You can’t do that kind of work in nature without being able to deal with noisy data and statistics, so as a result I had to develop a strong background in data science and network theory.

I worked in Yosemite National Park for five years for the University of California running a research institute, trying to bridge science, policy, and natural resource management for evidence-based decision making. We had a big, collaborative project synthesizing satellite and on-the-ground data to predict where threatened amphibian species were breeding. The data helped prioritize where limited park resources should be allocated to protect the species.

How does your background in ecology help inform the CFT?

Eric: Well, that is exactly how the CFT works — we use data to see the big picture and to help prioritize where funding efforts should go, given that resources are limited.

Another way to think about it is: If you map out who eats who in an ecosystem, you have complex flows of energy that comprise an entire food web. Turns out, those network structures are not random. They’re really critical for how those systems persist, and why they don’t crash. Instead of analyzing who eats whom, we’re using the same statistics to analyze who funds whom. Now, we have a funding ecosystem.

My passion over the past decade has been thinking about how ecological theory can inform solutions to complex problems, like climate. It requires a big picture of understanding multiple causality. There is no one silver bullet, there’s no one moon shot.

If you could sum up what the CFT is trying to solve, what would it be?

Eric: The public CFT is a visual Rolodex. It’s about overcoming myopia, which I think is the root cause of so many of those complex problems. But the main goal is to promote discovery and foster collaboration so people can see who’s doing what, avoid duplication, and fill in gaps where funding is missing.

We are also hoping to help people see that the success of an investment is dependent on other investments, too. Let’s say you have great investments with electric vehicles (EVs), but not with chargers or grid upgrades, that investment could fail. It will be critical to fill those gaps.

At the end of the day, we want to make it easy for someone to poke around and paint a picture of where money is flowing in different climate spaces.

You mentioned “silver bullets” and “funding gaps,” can you explain this a bit further?

Eric: Imagine you are in a community that is trying to grow a tree. You know it needs sun, water, nitrogen and phosphorous to grow. If any one of these is missing, it dies. If everybody just gives it water, it dies. Everyone needs to know what that tree is getting, and what is missing. The most important thing to contribute is always whatever is missing.

Here in the US, we have a “silver bullet” mentality, where one thing will solve it. This idea of, ‘Just give the tree water, and it lives’, which isn’t the case. Let’s take the renewable energy and mobility transition. You could have great investments in renewable power generation like solar and electric vehicles. But if you don’t have upgrades in distribution through our aging grid, it doesn’t matter. If you don’t have your charging infrastructure, it won’t work, and those other investments fail.

It wasn’t until pulling together data on who is funding what and where that I realized what a huge opportunity for impact is this issue of filling gaps. If one thing is missing, we fail. If we want to have an impact, we need to find where funding is lacking. And the only way to find those gaps is to see where the money is flowing.

To identify those gaps, you’d have to have tags and categories in the first place, correct? How does that work?

Eric: We currently start with philanthropy and investment data from Candid and Crunchbase (with more on the way!). We then gather, from online sources, more data on how the grantees and investees describe their work. This allows us then — using various methods, including natural language processing and machine learning — to categorize the organizations and let them self-organize into themes — all based around who is working on similar things.

A key challenge has been to develop a method for searching for ‘climate relevant’ investments and grants.  To do that we start with broad topic searches — for things like ‘climate’ and ‘agriculture,’ but then we need to filter these results because not all agricultural solutions are climate-positive, or some may mention ‘climate’ but in the wrong context. To do that we manually review a random subset of the results and use that to ‘fine-tune’ a Large Language Model to identify in the remaining results which are actually relevant to climate — for example, companies that are addressing things like regeneration, soil health, and sustainable water usage.

How data is visualized with the Climate Finance Tracker.

Can you give an example of a helpful action that can be done with CFT data?

Eric: Yes! Let’s stick with food systems and agriculture. If you’re new to the space, the CFT allows you to see who is funding regenerative agriculture. More so, you can use those tags to see who, and what, is being funded. This is how we improve transparency and increase efficiency. If you’re looking for funding — or if you are a funder who is new to a topic — you can quickly see who you should be talking to!

We can also go deeper to see where organizations mention language related to social equity and justice. For example, who states an intent to address energy poverty in low-income and rural communities. We can see financial flows into community-based conservation, restoration of land and community resiliency, equitable resourcing for the clean energy transition, and the intersection of climate solutions with general livelihood improvement.

We can help optimize funding and investments so resources can better flow to high-quality organizations, initiatives, or companies that are traditionally overlooked or underserved by the existing financial system.

Really it just comes down to the fact that engaging communities in the solution is actually the solution. It’s not just a moral thing to do, to improve the livelihoods of vulnerable communities, but it’s how you can truly scale and build out markets. For example, if you support energy independence for everyone, it creates more demand for electric mobility, which creates more demand for charging infrastructure, and so on.

What parting thoughts would you say to people who are interested in the CFT?

Eric: Part of our goal with the CFT was to show that climate solutions are not just solar panels and electric cars, those are just tiny corners of the landscape. If we can move beyond that silver bullet mentality, we can see that there are so many ways to contribute: you don’t need to become an electrical engineer.

We want to change the conversation, bring a positive tone that brings everyone along. There are so many things we can do to help more people. Of course, we’ll have to make sacrifices, but how cool is it that we get to build a whole new world? We get to make a renewable and regenerative transition. And we have to do it together.

It doesn’t matter how well-funded one company is, it will never solve every climate problem.

It doesn’t matter how rich one donor is, they will never solve it alone.

It doesn’t matter how big an investment fund is, it never will work alone.

We need to empower everyone to be part of the solution.

With thanks to Eric Berlow and Vibrant Data Labs for sharing their story with us, we invite you to learn more about the Climate Finance Tracker here!

Share

  Cisco Foundation grantee Climate Finance Tracker (CFT) is combining data and network theory into flexible tools to tackle climate change.  Read More Cisco Blogs 

By |2023-08-15T20:49:55+00:00August 15, 2023|Cisco: Learning|0 Comments

One Company, Many Careers: My Experiment in Career Growth Nikita Ravi Yajurvedi on August 15, 2023 at 12:00 pm

Choosing your career is probably one of the most difficult decisions you will make in life.

For me, to be very honest, it happened by chance.

To put it bluntly, I was always an all-rounder who… Read more on Cisco Blogs

Choosing your career is probably one of the most difficult decisions you will make in life.

For me, to be very honest, it happened by chance.

To put it bluntly, I was always an all-rounder who enjoyed studying and was good at most subjects, but unfortunately, I had no clue about what to pursue after graduation. Most of my relatives and friends were astonished at my confusion. So, before then, I tried my hand at almost everything:

I joined several clubs and societies
I worked for a few NGOs and social workers
I interned with a few multinational companies
I completed a full six-month internship with a medical organisation
I did a research project with my mentor

Then, in July 2018, I took the risk of applying for a job outside of the placement offers that came to our college. Fortunately for me, the risk paid off — This July, I celebrated five years at Cisco!

I started off my corporate work experience at Cisco as a Business Analyst in a finance cum operations role, where I learned the way of the ecosystem, different teams, organizations, and so much more. I always had a deep fervour for sales — growing up, I watched my dad in sales roles — and started working towards it, learning about current tech, staying relevant with the market trends, and soon moving to my first sales role in India, paving my path forward at Cisco.

That sales role changed my life. I spoke with so many people and learned how to connect with them, pivot, and confidently talk about the value I and my product could offer in even the smallest amount of time. It brought all my positive qualities to the surface and taught me more about the world and people than any MBA ever could.

Looking back, this ‘trial and error’ experiment of exploring all these fields and different roles gave me the opposite of confusion; it gave me a sense of clarity. I could get an insider’s view and understand the pros and cons of each career option. And this has been the biggest learning for me so far.

Making a decision, especially something as big as a career choice, will always be difficult. But today, careers are extremely dynamic. If you develop a mentality of having one ‘set’ career, and stop taking risks, you would miss out on a lot of opportunities! The best thing to do is experiment and challenge yourself because stepping outside your comfort zone is the only way to grow.  

Cisco has always been an incredible promoter of internal people movement, and there are several reasons why you find so many folks with more than ten years of experience still in the ecosystem: experimenting internally, the culture, the people, and the list goes on. “One company, many careers” isn’t just a saying. It’s a reality for so many.

In the last 5 years at Cisco, I have been very fortunate to have some of the best mentors, managers, and colleagues who have enriched my professional journey. My amazing managers have thrown me challenges, and I am certain to take the lessons learned forward and share them. Being a Gen Zer, I bring a different perspective, but the culture at Cisco is incredibly receptive, where everyone has a seat at the table, making you feel as though your voice is heard and you are truly valued.

I am gaining so many experiences here at Cisco, and the learning is exponential. This company has played a pivotal role in helping me explore my passion, unearth my skills, and constantly stay relevant. Not only have I experimented with my roles, but recently I moved cities and countries because of the people and the platform Cisco has provided. I am now currently the Territory Manager at Cisco Meraki in Sydney — my new springboard for experience, learning, and seeing where my next years at Cisco will take me!

Ready to grow with us? Find an opportunity now.

Subscribe to the We Are Cisco Blog.

Share

  Meraki Product Sales Specialist Nikita Y.'s career got its start through experimentation. See how that approach has spurred her growth at Cisco over the past five years!  Read More Cisco Blogs 

By |2023-08-15T20:49:55+00:00August 15, 2023|Cisco: Learning|0 Comments

Utilities Leadership Summit: Three trends, and two surprises Marcus Smith on August 15, 2023 at 4:00 pm

As part of Cisco Live Las Vegas 2023 we organized a Utilities Leadership Summit for top leaders in the industry. Our goal was to gain deeper insight into our customers’ challenges, discuss i… Read more on Cisco Blogs

As part of Cisco Live Las Vegas 2023 we organized a Utilities Leadership Summit for top leaders in the industry. Our goal was to gain deeper insight into our customers’ challenges, discuss innovations, and build strategic relationships. We explored high-level questions such as:

What are the top challenges and opportunities on the minds of utilities leaders in the US?
Which technologies have them hitting the accelerator?
And what do they value when building strategies and architectures for modernizing the grid?

We anchored the summit on three key topics: substation automation, distribution automation and utility wide-area networks. During Cisco Live US, clients, partners, and Cisco colleagues discussed these topics.

Since then, I’ve been reflecting on both formal discussions and casual conversations at Cisco Live US and considering the implications for other utilities. I’ve distilled my thinking into five takeaways.

Takeaway #1: Utilities want fewer devices with more functionality

When we surveyed utilities leaders about their top challenges, they were clear that resources are constrained. Given the lack of time and money, they value hardware that can perform multiple functions.

The Cisco Catalyst IR8340 Rugged Series Router is a great example. In a single piece of hardware, it offers a switch and router plus security (Cisco Cyber Vision sensor, Zone-based firewall and IDS/IPS capability) and a timing module for substation synchronization. It helps utilities save on power and heat while helping optimize rack space in the substation. The summit reaffirmed why the IR8340 has been very well received as a key platform for substation automation.

In the quest for efficiency and value, utilities leaders also told us they want end-to-end solutions proven to work. We’re able to provide that assurance to utilities with Cisco Validated Designs – for example, our designs for Substation Automation and SD-WAN for Distribution Automation are specifically developed for utilities.

Takeaway #2: Utilities are moving rapidly on SD-WAN

Summit attendees shared that they’re acting quickly to adopt SD-WAN for substation automation. There seemed to be consensus that SD-WAN will be a good fit for distribution automation, too. From my perspective, SD-WAN has gained significant momentum over the past six months. I attribute that to greater collaboration between IT and operational technology (OT) teams. While OT still owns final decisions, IT is showing OT the power of enterprise networking tools. These enterprise tools are very familiar to IT leaders, who can show OT leaders the potential ease of use, security, and automation they bring.

Takeaway #3: Virtualization in the substation is coming faster than you might think

It was mildly surprising to hear about rapidly increasing adoption of SD-WAN; it was almost shocking to discover how quickly some utilities are moving ahead on virtualization in the substation. There appears to be general acceptance that traditional applications will eventually be virtualized. After all, virtualization makes it possible to automate and centralize all the devices and systems within a substation. It enables greater security, visibility, and operational efficiency. It also unleashes new levels of intelligence. Although utilities are still early in this journey, they seem committed to making it happen.

Takeaway #4: First surprise: Utilities see the benefits of efficiently accessing and securing non-critical assets with the cloud.

Cisco’s Secure Equipment Access service enables an organization’s staff and contractors to access connected devices in a highly controlled and efficient manner. Because Secure Equipment Access is cloud based, I assumed utilities would be unable to use it to support certain substation assets. Conversations during Cisco Live US revealed that I was wrong. Utilities leaders I spoke with see great potential in using Secure Equipment Access to support ancillary non-critical equipment – for example door access control and fire detection systems – inside their substations. Streamlining the processes needed to keep these systems updated, secure and running smoothly is a powerful advantage.

Takeaway #5: Industry-specific partnerships matter

Cisco maintains strategic relationships with several industry-relevant partners, including Schweitzer Engineering Laboratories (SEL). Utilities customers at the summit were vocal about the value of such Cisco partnerships.

As utilities continue investigating cellular connectivity for substations and distribution network assets, there is growing interest in private LTE and 5G. Cisco solutions already support both, and we continue to invest in testing and proof-of-concepts. In fact, we shared our ongoing collaboration with Verizon to bring a joint solution for connecting substations and distribution assets—news that was well received during the event.

Ultimately, the summit demonstrated that utilities are no longer technology laggards; (surprise no. 2) some of the most innovative are emerging as technology leaders. To learn more about how Cisco is collaborating with utilities, listen to the replay of my session from Cisco Live US, The New Digital Substation.

Learn more

Cisco Catalyst IR8340 Rugged Series Router
Cisco Catalyst IE9300 Rugged Series Switches
Cisco Cyber Vision
Cisco Catalyst SD-WAN
Cisco Secure Equipment Access

Share

  5 takeaways from top industry leaders on key trends, thought leadership, and innovation in utilities  Read More Cisco Blogs 

By |2023-08-15T20:49:54+00:00August 15, 2023|Cisco: Learning|0 Comments

Making Your First Terraform File Doesn’t Have to Be Scary Quinn Snyder on August 15, 2023 at 7:00 pm

For the past several years, I’ve tried to give at least one Terraform-centric session at Cisco Live. That’s because they’re fun and make for awesome demos. What’s a technical talk without a demo? But … Read more on Cisco Blogs

For the past several years, I’ve tried to give at least one Terraform-centric session at Cisco Live. That’s because they’re fun and make for awesome demos. What’s a technical talk without a demo? But I also see huge crowds every time I talk about Terraform. While I wasn’t an economics major, I do know if demand is this large, we need a larger supply!

That’s why I decided to step back and focus to the basics of Terraform and its operation. The configuration applied won’t be anything complex, but it should explain some basic structures and requirements for Terraform to do its thing against a single piece of infrastructure, Cisco ACI. Don’t worry if you’re not an ACI expert; deep ACI knowledge isn’t required for what we’ll be configuring.

The HCL File: What Terraform will configure

A basic Terraform configuration file is written in Hashicorp Configuration Language (HCL). This domain-specific language (DSL) is similar in structure to JSON, but it adds components for things like control structures, large configuration blocks, and intuitive variable assignments (rather than simple key-value pairs).

At the top of every Terraform HCL file, we must declare the providers we’ll need to gather from the Terraform registry. A provider supplies the linkage between the Terraform binary and the endpoint to be configured by defining what can be configured and what the API endpoints and the data payloads should look like. In our example, we’ll only need to gather the ACI provider, which is defined like this:

terraform
  required_providers
    aci =
      source = “CiscoDevNet/aci”
   
 

Once you declare the required providers, you have to tell Terraform how to connect to the ACI fabric, which we do through the provider-specific configuration block:

provider "aci"
username = "admin"
password = "C1sco12345"
url      = "https://10.10.20.14"
insecure = true

Notice the name we gave the ACI provider (aci) in the terraform configuration block matches the declaration for the provider configuration. We’re telling Terraform the provider we named aci should use the following configuration to connect to the controller. Also, note the username, password, url, and insecure configuration options are nested within curly braces . This indicates to Terraform that all this configuration should all be grouped together, regardless of whitespaces, indentation, or the use of tabs vs. spaces.

Now that we have a connection method to the ACI controller, we can define the configuration we want to apply to our datacenter fabric. We do this using a resource configuration block. Within Terraform, we call something a resource when we want to change its configuration; it’s a data source when we only want to read in the configuration that already exists. The configuration block contains two arguments, the name of the tenant we’ll be creating and a description for that tenant.

resource "aci_tenant" "demo_tenant"
name        = "TheU_Tenant"
description = "Demo tenant for the U"

Once we write that configuration to a file, we can save it and begin the process to apply this configuration to our fabric using Terraform.

The Terraform workflow: How Terraform applies configuration

Terraform’s workflow to apply configuration is straightforward and stepwise. Once we’ve written the configuration, we can perform a terraform init, which will gather the providers from the Terraform registry who have been declared in the HCL file, install them into the project folder, and ensure they are signed with the same PGP key that HashiCorp has on file (to ensure end-to-end security). The output of this will look similar to this:

[I] theu-terraform » terraform init
Initializing the backend...
Initializing provider plugins...
- Finding latest version of ciscodevnet/aci...
- Installing ciscodevnet/aci v2.9.0...
- Installed ciscodevnet/aci v2.9.0 (signed by a HashiCorp partner, key ID 433649E2C56309DE)
Partner and community providers are signed by their developers.
If you'd like to know more about provider signing, you can read about it here:
https://www.terraform.io/docs/cli/plugins/signing.html
Terraform has created a lock file .terraform.lock.hcl to record the provider
selections it made above. Include this file in your version control repository
so that Terraform can guarantee to make the same selections by default when
you run "terraform init" in the future.
Terraform has been successfully initialized!

You may now begin working with Terraform. Try running “terraform plan” to see any changes required for your infrastructure. All Terraform commands should now work.

If you ever set or change modules or backend configuration for Terraform, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary.

Once the provider has been gathered, we can invoke terraform plan to see what changes will occur in the infrastructure prior to applying the config. I’m using the reservable ACI sandbox from Cisco DevNet  for the backend infrastructure but you can use the Always-On sandbox or any other ACI simulator or hardware instance. Just be sure to change the target username, password, and url in the HCL configuration file.

Performing the plan action will output the changes that need to be made to the infrastructure, based on what Terraform currently knows about the infrastructure (which in this case is nothing, as Terraform has not applied any configuration yet). For our configuration, the following output will appear:

[I] theu-terraform » terraform plan
Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols:
+ create
Terraform will perform the following actions:
# aci_tenant.demo_tenant will be created
+ resource "aci_tenant" "demo_tenant"
+ annotation                    = "orchestrator:terraform"
+ description                   = "Demo tenant for the U"
+ id                            = (known after apply)
+ name                          = "TheU_Tenant"
+ name_alias                    = (known after apply)
+ relation_fv_rs_tenant_mon_pol = (known after apply)

Plan: 1 to add, 0 to change, 0 to destroy.
───────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
Note: You didn't use the -out option to save this plan, so Terraform can't guarantee to take exactly these actions if
you run "terraform apply" now.

We can see that the items with a plus symbol (+) next to them are to be created, and they align with what we had in the configuration originally. Great!  Now we can apply this configuration. We perform this by using the terraform apply command. After invoking the command, we’ll be prompted if we want to create this change, and we’ll respond with “yes.”

[I] theu-terraform » terraform apply                                                      
Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the
following symbols:
  + create
Terraform will perform the following actions:
  # aci_tenant.demo_tenant will be created
  + resource "aci_tenant" "demo_tenant"
      + annotation                    = "orchestrator:terraform"
      + description                   = "Demo tenant for the U"
      + id                            = (known after apply)
      + name                          = "TheU_Tenant"
      + name_alias                    = (known after apply)
      + relation_fv_rs_tenant_mon_pol = (known after apply)
   
Plan: 1 to add, 0 to change, 0 to destroy.
Do you want to perform these actions?
  Terraform will perform the actions described above.
Only 'yes' will be accepted to approve.
  Enter a value: yes
aci_tenant.demo_tenant: Creating...
aci_tenant.demo_tenant: Creation complete after 3s [id=uni/tn-TheU_Tenant]
Apply complete! Resources: 1 added, 0 changed, 0 destroyed.

The configuration has now been applied to the fabric!  If you’d like to verify, log in to the fabric and click on the Tenants tab. You should see the newly created tenant.

Finally – if you’d like to delete the tenant the same way you created it, you don’t have to create any complex rollback configuration. Simply invoke terraform destroy from the command line. Terraform will verify the state that exists locally within your project aligns with what exists on the fabric; then it will indicate what will be removed. After a quick confirmation, you’ll see that the tenant is removed, and you can verify in the Tenants tab of the fabric.

[I] theu-terraform » terraform destroy                                                    
aci_tenant.demo_tenant: Refreshing state... [id=uni/tn-TheU_Tenant]
Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the
following symbols:
  - destroy
Terraform will perform the following actions:
  # aci_tenant.demo_tenant will be destroyed
  - resource "aci_tenant" "demo_tenant"
      - annotation  = "orchestrator:terraform" -> null
      - description = "Demo tenant for the U" -> null
      - id          = "uni/tn-TheU_Tenant" -> null
      - name        = "TheU_Tenant" -> null
   
Plan: 0 to add, 0 to change, 1 to destroy.
Do you really want to destroy all resources?
  Terraform will destroy all your managed infrastructure, as shown above.
  There is no undo. Only 'yes' will be accepted to confirm.
  Enter a value: yes
aci_tenant.demo_tenant: Destroying... [id=uni/tn-TheU_Tenant]
aci_tenant.demo_tenant: Destruction complete after 1s
Destroy complete! Resources: 1 destroyed.

Complete Infrastructure as Code lifecycle management with a single tool is pretty amazing, huh?

A bonus tip

Another tip regarding Terraform and HCL relates to the workflow section above. I described the use of curly braces to avoid the need to ensure whitespace is correct or tab width is uniform within the configuration file. This is generally a good thing, as we can focus on what we want to deploy rather than minutiae of the config. However, sometimes it helps when you format the configuration in a way that’s aligned and easier to read, even if it doesn’t affect the outcome of what is deployed.

In these instances, you can invoke terraform fmt within your project folder, and it will automatically format all Terraform HCL files into aligned and readable text. You can try this yourself by adding a tab or multiple spaces before an argument or maybe between the = sign within some of the HCL. Save the file, run the formatter, and then reopen the file to see the changes. Pretty neat, huh?

Want to know more?

For a deeper dive beyond this introductory video, I have several Terraform videos on our YouTube channel that dive into more complex configurations as well as other options that exist within Terraform. You can also watch the video below, which offers sample code links to get your hands dirty with Terraform.

As always, if you have any questions, drop them in the comments below or find me on Twitter @qsnyder.

Join the Cisco Learning Network today for free.

Follow Cisco Learning & Certifications

Twitter

By |2023-08-15T20:49:53+00:00August 15, 2023|Cisco: Learning|0 Comments

Comply to Connect: The Bridge to Zero Trust Will Ash on August 14, 2023 at 1:00 pm

This special guest post is by Chris Crider, Security Systems Engineering Leader for Cisco US Public Sector

Chris Crider

When it comes to Zero Trust frameworks and principles, few organizations are as … Read more on Cisco Blogs

This special guest post is by Chris Crider, Security Systems Engineering Leader for Cisco US Public Sector

Chris Crider

When it comes to Zero Trust frameworks and principles, few organizations are as comprehensive as the US Department of Defense (DoD). In 2022, the DoD released their seven-pillar strategy to articulate their critical cyber capabilities and activities associated with Zero Trust principles (Figure 1), while also aligning the functional rollout of those capabilities with a targeted timeline of execution of the basics through 2027.

Figure 1: DoD seven pillars of Zero Trust

What is Comply to Connect?

One of the capabilities in the Devices pillar of the DoD Zero Trust Strategy is Comply to Connect (C2C), an NDAA mandate and a Defense Information Systems Agency (DISA) program setup to monitor and manage government endpoints and their health, plus to affect their authorization into the environment based on an ongoing set of endpoint criteria. The scope of the C2C program is a tremendous undertaking by itself. However, the program’s extent does not account for user and device attribution to sessions or behavior within each session, which can also be made through a common set of tools in the journey to Zero Trust maturity.

The Comply to Connect program is a bridge to Zero Trust access. So, device authentication and authorization need to account for not only user devices but also non-user devices. This is especially true since the vast worlds of the Internet of Things (IoT) and Industrial Internet of Things (IIoT) have entered the spotlight due to cyber-attacks and a lack of emphasis on non-user devices like SCADA systems, traffic sensors, and security cameras.

Comply to Connect and device behavior

Since the IoT and IIoT have now become key gateways for intrusion, device health and least-privilege authorization must now be complemented with an understanding of device behavior and activity. For example:

Can an organization identify a device (like a camera)?
Does a device exhibit unusual activity for its role (like trying to connect to an adversarial network)?
Or even more simply, from an operational perspective, is an authorized endpoint on one network attempting to connect to a different network classification?

Applying Zero Trust principles like these to government networks helps agencies properly identify and authorize (or deny) any user and device trying to access their network. Just as importantly, it enables your agency to continuously monitor and attribute the behavior of an entity on your network. This lets you quickly and accurately take appropriate actions to stay secure.

Cisco’s security portfolio helps government organizations increase their Zero Trust maturity by facilitating secure communications from endpoint to application. This includes authenticating and authorizing a user and device per session. Plus, our comprehensive security portfolio also evaluates endpoint health, facilitates remediation, and attributes all data accessed and exchanged throughout the session with the originating entity.

Comply to Connect and Cisco ISE

For most government organizations, complexity often surfaces from deploying a large patchwork of tools to mitigate various threats. The result is a security environment with too many tools and not enough experts on staff. This means your missions and programs face an uphill battle to effectively combat threats from numerous attack vectors simultaneously.

That’s where Cisco Identity Services Engine (ISE) can add tremendous value for government networks. Cisco ISE is our Zero Trust policy engine and policy decision point (PDP). It’s a foundational component of Zero Trust and an exceptionally versatile component of a comprehensive strategy when paired with other tools, making contextual access decisions and enforcing policy continuously throughout each session.

Cisco ISE integrates with leading third-party identity platforms, endpoint solutions, and other various data sources to provide contextual and risk-based access to operational environments for both users and devices. It can also make decisions whether the session originates over traditional wired and wireless networks, P5G, VPN, or ZTNA use cases.

In a world where most organizations are understaffed, it’s critical that programs simplify their toolset to create maximum effectiveness. Automation and orchestration can also create their own operational challenges if there are too many moving parts among vendors. That’s why we’ve also equipped Cisco ISE is with rich APIs to help automate dynamic policy and facilitate simplified policy enforcement across security solutions and network environments.

An integrated toolset for Comply to Connect

When not using phishing mechanisms, today’s attackers rely on misconfigurations and user error for entry points. To achieve the desired outcomes and the promises of Zero Trust principles, the government must work to streamline their toolsets to ones that integrate effectively. This will help them achieve visibility and enforcement consistently end-to-end. Security architectures must also be able to assert both least-privilege access at the onset of the connection and risk-based updates to the session in the event of abnormal activity.

That’s the great thing about the Cisco Security portfolio. As a critical part of an integrated toolset, it creates a system to identify users and assets before it authorizes them for access into your network environment. The same capabilities can also monitor user and device behavior for abnormalities as they access data (in conjunction with other tools), across any connection medium, and ultimately update controls if risk-based updates must be applied to the session (Figure 2). This includes:

Cisco Identity Services Engine (ISE), Secure Firewall, Secure Network Analytics, and Secure Client combining to provide visibility and enforcement for any connection attempt. This creates a unified and secure platform, especially when paired with Cisco’s industry-leading network and threat intelligence capabilities.
Cisco ISE acting as a Zero Trust policy decision point (PDP) and integration point via APIs, to incorporate third-party capabilities in a multi-vendor Zero Trust ecosystem.
Cisco Secure Access integrating with our Secure Client to provide end-to-end encryption or protect endpoints from the cloud when they are not connected to the enterprise.
Figure 2: Cisco Security portfolio architecture

Getting the right tools for C2C

As always, it’s important to select the right tool for the job. This is especially true when it comes to cybersecurity. Deploying the proper mission-aligned tools helps your organization achieve the desired return on investment (ROI) while increasing your security operation center (SOC) efficiency. This is a great benefit of adopting Zero Trust principles.

The capabilities of Cisco’s security portfolio (through our technical alliance partners) also integrate with several leading industry vendors who provide deep endpoint inspection, identity lifecycle, hybrid workload and container environments, event correlation, and more. This provides your agency with maximum effectiveness.

Remember, when it comes to Zero Trust it’s important to look at where to begin each organization’s journey to maturity. For the DoD, building on a long-standing history of RMF, Defense in depth, and NIST 800-53, Zero Trust maturity can help facilitate collaboration between siloed organizations. The good news is that the Comply to Connect program can be used as a starting catalyst, with the basics of inventory and endpoint health creating an opportunity to enforce policy and attribute behavior to users and devices consistently.

Moving forward, using tools that effectively perform these functions for the scope of Comply to Connect, and inform other programs, is key to turning the tide against the growing pressures of defensive cyber operations (DCO). Cisco’s Security portfolio, in conjunction with a consolidated set of vendors, can help the government do so and streamline your efforts toward a more secure operational environment.

More resources

Cisco Solutions for Federal Government
Cisco FedRAMP Solutions
Breaking Through for Mission Advantage

Share

  The Comply to Connect (C2C) program is a bridge to Zero Trust access, and with the growth of Iot and IIoT devices it's now critical for DoD security. Learn all about C2C and selecting the right tools to get it done.  Read More Cisco Blogs 

By |2023-08-15T08:17:28+00:00August 15, 2023|Cisco: Learning|0 Comments

Why are CEOs Cyber Resilient? Richard Archdeacon on August 14, 2023 at 12:00 pm

I recently attended a session run by the Said Business School at Oxford along with an organisation called Istari. The discussion was based upon their research into at the view CEOs had of cyber… Read more on Cisco Blogs

I recently attended a session run by the Said Business School at Oxford along with an organisation called Istari. The discussion was based upon their research into at the view CEOs had of cyber resilience.

There were two immediate points which struck me. The first is that major cyber incidents are hugely traumatic for CEOs. It is an experience they are ill equipped to deal with when compared to other business challenges. This is not surprising considering the speed at which an incident can stop a business from operating and its relative recent appearance when compared to other risks. The second was that cyber security is not a topic to interest a CEO but cyber resilience certainly is. So, a lesson for security professionals is to “watch your language” and use more recognised terminology.

So, what practical steps can a CEO take to address Cyber Resilience rather than just heaving it on to the shoulders of the CISO.

One of the issues could be a possible difference between views on Cyber Resilience between Business Leaders and CISOs. A recent report by the World Economic Forum showed a comparative difference between these two groups in their organisations cyber resilience capability. Whereas CISOs saw a definite improvement Business Leaders were not so sure.

One action could be is to define and agree what resilience means to the organisation. It can be very different according to the nature, risk and priorities of the organisation. In a key, regulated member of the CNI there will be a different idea of resilience when compared to a born in the cloud start up chasing market share. The former will be focused on ensuring stability and compliance, the latter on availability and speed of change. So different views of what it means to keep the business operating, adapting and innovating.

The CEO should be agreeing on a Risk based approach and clearly expressing the importance of this is at the start. One principle I was told to follow many years ago as a young consultant is that CEOs always make decision with a Risk vs Opportunity mind set. If we do this, what will we gain, what could we lose and how do we minimise the downside? So, security teams can always present an issue on those terms. What the priorities are, how should they be addressed and the identifiable benefits.

From the CISO perspective this can be a great help in practical terms. For example, during a discussion with a couple of CISOs, it became apparent that they had different levels of budgetary support from their CEO. One had aligned all expenditure with the Risk Register and was well funded. The other had a funding surge after an incident but interest had waned and now funding was harder to justify. The former had the support of the CEO for the security function whilst the latter was seen in the light of a specific incident which became less valid as memories faded.

This observation led me to another topic. A lot is talked about Culture, the soft art of improving security and resilience. This is increasingly referred to by CISOs but shouldn’t the CEO be leading this change? To draw a comparison. Over the years the concept of Health and Safety has increased in profile as CEOs committed to the principles especially in industries such as Oil and Gas. This developed into a clear set of ordered  priorities, employees, customers, shareholders. Now the principles of Sustainability are also becoming fundamental to how an organisation operates. Cyber Resilience can likewise be developed into the fabric and values. Become part of the culture.

The best place to start is at the most senior level. Some years go the World Economic Forum produced a set of Board Principles to support CEOs and which are valid today. They encompass the basic needs which a Board to address from Accountability to Collaboration. Adopting an internationally recognised framework has been successful in the past and I am aware of a CISO who used these Principles to gain greater traction internally. Driven by the CEO this will create a sense of Cyber Resilience as part of the fundamental management of the business.

All preparation is improved by constant repetition and developing the ability to act when needed. Tabletop exercises are commonly carried out. But for the CEO to lead on these and ensure full cooperation is a further way to change the culture and thinking.  Being trained in a situation will intuitively increase awareness of the importance of cyber resilience as well as building in response capabilities. Learning in the middle of an incident is not the best option.

When addressing culture at a more tactical, day to day, basis the CEO should ensure that the ELT have Security Champions working in all areas of the business. People who understand how colleagues work to and align security with them. Understanding the User Experience. The benefit of this will be to feed back to the security teams the needs of the business from a resilience perspective. Whether following set procedures is more important than being able to adapt quickly and securely for example.  In addition, it makes security a cooperative rather than an antagonistic exercise where the security team impose controls.

As a final thought. The CEO could support the CISO in getting the right communications around the risk and benefits to the business by not holding the CISO responsible for communicating the ideas and principles. In other words, make it the responsibility for the business leaders to communicate what resilience means to them and their areas of responsibility.

One CISO was supported by the adoption of  this approach and got the support from within the organisation they secured.  The brand was of paramount importance to the business. Built up over years. A major corporate asset. The CISO asked the marketing team to define the impact and cost, tangible and intangible, of an incident on the brand and how resilience could be worked into the brand values as a positive element for customers. Whilst it may be a long trek for the CISO to achieve this support, for the CEO it could be a simple first step to inculcate cyber resilience into the culture and thinking of the organisation by asking the functional leads to take the initiative.

For the CEO an incident could be traumatic. But there are a range of proactive steps that could be taken at the most senior level through to daily operations.

There is an adage that the most expensive security is the security that is applied after the event. If the CEO leads Cyber Resilience journey, not only will security make the organisation more resilience, it could also save money. It will weigh the Risk vs Opportunity decision in favour of the opportunity by understanding and mitigating the risk. And by being part of the solution the CEO will find the traumatic impact of an incident is reduced.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Secure on social!

Cisco Secure Social Channels

InstagramFacebookTwitterLinkedIn

Share

  What practical steps can a CEO take to address Cyber Resilience rather than just heaving it on to the shoulders of the CISO?  Read More Cisco Blogs 

By |2023-08-15T08:17:28+00:00August 15, 2023|Cisco: Learning|0 Comments

Cisco “Black Belt for a Reason” shows how small contributions make a big impact Gaurav Sharma on August 11, 2023 at 3:00 pm

From donating 300 PPE masks to hospitals to A bridge of help connecting 170 smiling faces these successful Black Belt campaigns have inspired our Partner & Distributor communities across the… Read more on Cisco Blogs

From donating 300 PPE masks to hospitals to A bridge of help connecting 170 smiling faces these successful Black Belt campaigns have inspired our Partner & Distributor communities across the globe.

Continuing the momentum, here we are with yet another philanthropic initiative—”Black Belt Certification for a Reason”—a one-of-a-kind campaign that addresses not only Cisco Vietnam’s business goals but also caters to the essence of giving back to society.

In April 2023, the Cisco Vietnam DPSE team collaborated with distributors M.Tech, Synnex, and TechData, along with Cisco Black Belt to launch the “Black Belt Certification for a Reason” campaign. Eleven instructor-led sessions were conducted by DPSEs across three different locations within Vietnam, with the goal of training Partner engineers across Cisco technologies by leveraging the Cisco Black Belt learning plans. To conclude the campaign with a giving back activity, an innovative crowd funding model was experimented with to help the remote Aur Lang village.

Thanks to the 65 participants and charitable contributions of our participating distributors, “Black Belt Certification for a Reason” not only resulted in 202 new Black Belt certifications, but 22 million VND ($950 USD) being raised. The team’s target goal for new certifications was 120 and funds raised was $600 USD, making the campaign a success from a business perspective. But what made the campaign truly successful was what the team was able to do with the funds that were raised.

The DPSE Vietnam team chose to focus their give-back efforts on the Aur Lang village. The village has 23 families with a total population of about 100 people, including around 45 school-age children. Located deep in the jungle of the Tay Giang Mountains, from National Highway 14 it takes about 6 hours to walk to the village, going through 14km of trails with 8 hills and more than 10 streams and can only be accessed by foot. Due to geographical distance, the people of Aur Lang village mainly live on self-sufficiency, grow upland rice, fish in streams, and raise a few wild boars. Sometimes they get wild honey and Ganoderma mushrooms and bring them down to the town Prao, which is about 25km from the village, to exchange for money or necessary food. People here are lacking in electricity, health care, education (the school is too far away from the village, so the children must stay away from their parents, going to the town to stay and coming back to their home during the summer) and even communication (no cellphone signal).

The DPSE Vietnam team used the funds donated by the participating distributors to buy vegetable seeds; foot fungus medicine for people working in the fields; deworming medicine for children; comic books; some sweets; clothes; and some sport equipment such as footballs, volleyballs, and badminton rackets for the children to have fun in the summer. Each household was also supported with cash (500k VND/household) so that they can actively buy some breeding stock to grow them up, or spend on necessary expenses for their family. In addition to the above gifts, the team also gave the village a small festival with grilled pork and a pot of pork porridge stewed with pumpkin.

“The villagers are very happy and excited when they got the support from Cisco. Vegetable seeds, medicine are things that the villagers desperately need. The representative of the village will support the people to buy breeding stock to improve their lives. The villagers would like to sincerely thank the company, the implementation team, and wish the company more success, to help more communities like our village.”– Mr. A Ting Del, head of the village, represented the villagers to express his emotion and gratitude to the team and Cisco Vietnam

The three-day weekend in the Aur Lang village was a memorable experience for the team. Staying away from computers, phones, social networks, playing with the children, cooking with the villagers, bringing joy to the people—we felt energized to return to our busy lives in the city.

There is nothing better for us as an organization to help our ecosystem Partners in their business while giving back to society which makes the Black Belt for a Reason/Cause initiative a true Win-Win!

Learn more about how you can partner for a purpose

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook    @CiscoPartners Twitter  

By |2023-08-14T19:23:31+00:00August 14, 2023|Cisco: Learning|0 Comments
Go to Top