Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the easy-accordion-free domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the zoho-flow domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the wordpress-seo domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php on line 6114

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893
{"id":1803,"date":"2023-11-30T00:54:30","date_gmt":"2023-11-30T00:54:30","guid":{"rendered":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/"},"modified":"2023-11-30T00:54:30","modified_gmt":"2023-11-30T00:54:30","slug":"gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm","status":"publish","type":"post","link":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/","title":{"rendered":"Gain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm"},"content":{"rendered":"

Zero Trust Network Access (ZTNA) is a secure remote access service. It verifies remote users and grants them access to the right resources at the right times based on identity and context policies.\u2026 Read more on Cisco Blogs<\/a><\/em><\/p>\n

\u200b<\/p>\n

Zero Trust Network Access (ZTNA) is a secure remote access service. It verifies remote users and grants them access to the right resources at the right times based on identity and context policies. <\/em>This is part 3 in our blog series about ZTNA for operational technology (OT). Check out <\/em>Part 1<\/em><\/a> for why ZTNA beats out always-on VPNs for OT remote access and <\/em>Part 2<\/em><\/a> for how ZTNA reduces the attack surface by restricting access methods and verifying remote users\u2019 security posture.<\/em><\/p>\n

Video cameras are everywhere, including in facilities with the strictest physical access controls. Even if you trust an individual to enter a sensitive area, you still need to monitor their activities once they\u2019re in the door. Seeing a suspicious activity, you can step in to stop it. And if problems crop up after the visit, reviewing a recording can help pinpoint what went wrong.<\/p>\n

Monitoring and recording activities are equally critical when it comes to remote users accessing your OT networks. It\u2019s not enough to verify the identity of remote employees, vendors, and contractors. Neither is it enough to know who is connected to what OT\/ICS assets. You also need to know what users are doing during remote access sessions. Most organizations lack that visibility today, a shortcoming for cybersecurity compliance, governance, the ability to stop and recover from breaches, and incident investigation.<\/p>\n

Conveniently, Cisco Secure Equipment Access (SEA)<\/a> gives you an all-in-one solution to grant remote access, enforce access controls, and monitor and record remote session activity. Here are three ways you can take advantage of Cisco SEA to actively control OT remote access.<\/p>\n

1 \u2013 Monitor, join, and terminate active sessions<\/h2>\n

See a list of all active sessions on the Cisco SEA console. By clicking on the session between \u2018User A\u2019 and \u2018Asset B\u2019 you can watch session activities as they happen, including commands sent to the asset. Watching a vendor configure an OT\/ICS asset can be helpful for training, for example. And if you see something suspicious, like an attempt to change the code or a variable in a programmable logic controller (PLC), you can terminate the session with a click and disconnect the remote user. Remote session termination is required by ISA\/IEC62443-3-3 FR2<\/a>.<\/p>\n

2 \u2013 Maintain a complete log of past sessions<\/h2>\n

Cybersecurity best practices require maintaining a detailed history of all past sessions, useful for security audits, forensic investigations, and regulatory compliance. The EU\u2019s NIS2 Directive<\/a>, for example, requires a full audit trail for every event that affects critical infrastructure and OT security standards such as ISA\/IEC62443-3-3<\/a> require records of all login attempts. Cisco SEA logs both system-generated and user-generated events. For example, review how remote users authenticate, including usernames, time, device posture, and session activities. Or see who added new users or new assets to the system.<\/p>\n

3 \u2013 Record sessions to see what happened<\/h2>\n

Optionally record sessions for selected assets, simply by selecting the asset on the console and checking a box. Recordings enrich your audit trail and can be particularly helpful for troubleshooting. If an asset like a robot arm, wind turbine, or highway sign stops working, for example, you might discover that a vendor recently upgraded the software or made a typo in a new configuration. Faster troubleshooting helps you put the asset back into production sooner.<\/p>\n

Keep it simple, with an all-in-one solution for secure equipment access<\/h2>\n

Summing up, Cisco SEA gives you a single interface to protect your ICS and OT assets with ZTNA. Require all remote users to authenticate through a single point. Control which assets they can access and at what times. And do what a video camera does by monitoring all remote session activities and recording data for security audits.<\/p>\n

Learn more about Cisco Secure Equipment Access here<\/a>.<\/strong><\/p>\n

\n\t\tShare\n
\n
<\/div>\n<\/div>\n
\n
\n\t\t<\/a>\n\t<\/div>\n<\/div>\n
\n
\n\t\t<\/a>\n\t<\/div>\n<\/div>\n
\n
\n\t <\/a>\n\t<\/div>\n<\/div>\n<\/div>\n
Share:<\/div>\n
\n
\n
<\/div>\n<\/div>\n
\n
\n\t\t<\/a>\n\t<\/div>\n<\/div>\n
\n
\n\t\t<\/a>\n\t<\/div>\n<\/div>\n
\n
\n\t <\/a>\n\t<\/div>\n<\/div>\n<\/div>\n

\u00a0\u00a0Learn how Cisco Secure Equipment Access gives you visibility into active and past remote access sessions, lets you terminate an active session if something doesn\u2019t look right, and record sessions for training or forensics.\u00a0\u00a0Read More<\/a>\u00a0Cisco Blogs\u00a0<\/p>","protected":false},"excerpt":{"rendered":"

<\/p>\n

Zero Trust Network Access (ZTNA) is a secure remote access service. It verifies remote users and grants them access to the right resources at the right times based on identity and context policies.\u2026 Read more on Cisco Blogs<\/a><\/em><\/p>\n

\u200b<\/p>\n

Zero Trust Network Access (ZTNA) is a secure remote access service. It verifies remote users and grants them access to the right resources at the right times based on identity and context policies. <\/em>This is part 3 in our blog series about ZTNA for operational technology (OT). Check out <\/em>Part 1<\/em><\/a> for why ZTNA beats out always-on VPNs for OT remote access and <\/em>Part 2<\/em><\/a> for how ZTNA reduces the attack surface by restricting access methods and verifying remote users\u2019 security posture.<\/em><\/p>\n

Video cameras are everywhere, including in facilities with the strictest physical access controls. Even if you trust an individual to enter a sensitive area, you still need to monitor their activities once they\u2019re in the door. Seeing a suspicious activity, you can step in to stop it. And if problems crop up after the visit, reviewing a recording can help pinpoint what went wrong.<\/p>\n

Monitoring and recording activities are equally critical when it comes to remote users accessing your OT networks. It\u2019s not enough to verify the identity of remote employees, vendors, and contractors. Neither is it enough to know who is connected to what OT\/ICS assets. You also need to know what users are doing during remote access sessions. Most organizations lack that visibility today, a shortcoming for cybersecurity compliance, governance, the ability to stop and recover from breaches, and incident investigation.<\/p>\n

Conveniently, Cisco Secure Equipment Access (SEA)<\/a> gives you an all-in-one solution to grant remote access, enforce access controls, and monitor and record remote session activity. Here are three ways you can take advantage of Cisco SEA to actively control OT remote access.<\/p>\n

1 \u2013 Monitor, join, and terminate active sessions<\/h2>\n

See a list of all active sessions on the Cisco SEA console. By clicking on the session between \u2018User A\u2019 and \u2018Asset B\u2019 you can watch session activities as they happen, including commands sent to the asset. Watching a vendor configure an OT\/ICS asset can be helpful for training, for example. And if you see something suspicious, like an attempt to change the code or a variable in a programmable logic controller (PLC), you can terminate the session with a click and disconnect the remote user. Remote session termination is required by ISA\/IEC62443-3-3 FR2<\/a>.<\/p>\n

2 \u2013 Maintain a complete log of past sessions<\/h2>\n

Cybersecurity best practices require maintaining a detailed history of all past sessions, useful for security audits, forensic investigations, and regulatory compliance. The EU\u2019s NIS2 Directive<\/a>, for example, requires a full audit trail for every event that affects critical infrastructure and OT security standards such as ISA\/IEC62443-3-3<\/a> require records of all login attempts. Cisco SEA logs both system-generated and user-generated events. For example, review how remote users authenticate, including usernames, time, device posture, and session activities. Or see who added new users or new assets to the system.<\/p>\n

3 \u2013 Record sessions to see what happened<\/h2>\n

Optionally record sessions for selected assets, simply by selecting the asset on the console and checking a box. Recordings enrich your audit trail and can be particularly helpful for troubleshooting. If an asset like a robot arm, wind turbine, or highway sign stops working, for example, you might discover that a vendor recently upgraded the software or made a typo in a new configuration. Faster troubleshooting helps you put the asset back into production sooner.<\/p>\n

Keep it simple, with an all-in-one solution for secure equipment access<\/h2>\n

Summing up, Cisco SEA gives you a single interface to protect your ICS and OT assets with ZTNA. Require all remote users to authenticate through a single point. Control which assets they can access and at what times. And do what a video camera does by monitoring all remote session activities and recording data for security audits.<\/p>\n

Learn more about Cisco Secure Equipment Access here<\/a>.<\/strong><\/p>\n

\n\t\tShare<\/p>\n
\n
<\/div>\n<\/div>\n
\n
\n\t\t<\/a>\n\t<\/div>\n<\/div>\n
\n
\n\t\t<\/a>\n\t<\/div>\n<\/div>\n
\n
\n\t <\/a>\n\t<\/div>\n<\/div>\n<\/div>\n
Share:<\/div>\n
\n
\n
<\/div>\n<\/div>\n
\n
\n\t\t<\/a>\n\t<\/div>\n<\/div>\n
\n
\n\t\t<\/a>\n\t<\/div>\n<\/div>\n
\n
\n\t <\/a>\n\t<\/div>\n<\/div>\n<\/div>\n

\u00a0\u00a0Learn how Cisco Secure Equipment Access gives you visibility into active and past remote access sessions, lets you terminate an active session if something doesn\u2019t look right, and record sessions for training or forensics.\u00a0\u00a0Read More<\/a>\u00a0Cisco Blogs\u00a0<\/p>\n

<\/p>\n","protected":false},"author":0,"featured_media":1804,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-1803","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cisco-learning"],"yoast_head":"\nGain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm - JHC<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Gain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm\" \/>\n<meta property=\"og:description\" content=\"Zero Trust Network Access (ZTNA) is a secure remote access service. It verifies remote users and grants them access to the right resources at the right times based on identity and context policies.\u2026 Read more on Cisco Blogs \u200b Zero Trust Network Access (ZTNA) is a secure remote access service. It verifies remote users and grants them access to the right resources at the right times based on identity and context policies. This is part 3 in our blog series about ZTNA for operational technology (OT). Check out Part 1 for why ZTNA beats out always-on VPNs for OT remote access and Part 2 for how ZTNA reduces the attack surface by restricting access methods and verifying remote users\u2019 security posture. Video cameras are everywhere, including in facilities with the strictest physical access controls. Even if you trust an individual to enter a sensitive area, you still need to monitor their activities once they\u2019re in the door. Seeing a suspicious activity, you can step in to stop it. And if problems crop up after the visit, reviewing a recording can help pinpoint what went wrong. Monitoring and recording activities are equally critical when it comes to remote users accessing your OT networks. It\u2019s not enough to verify the identity of remote employees, vendors, and contractors. Neither is it enough to know who is connected to what OT\/ICS assets. You also need to know what users are doing during remote access sessions. Most organizations lack that visibility today, a shortcoming for cybersecurity compliance, governance, the ability to stop and recover from breaches, and incident investigation. Conveniently, Cisco Secure Equipment Access (SEA) gives you an all-in-one solution to grant remote access, enforce access controls, and monitor and record remote session activity. Here are three ways you can take advantage of Cisco SEA to actively control OT remote access. 1 \u2013 Monitor, join, and terminate active sessions See a list of all active sessions on the Cisco SEA console. By clicking on the session between \u2018User A\u2019 and \u2018Asset B\u2019 you can watch session activities as they happen, including commands sent to the asset. Watching a vendor configure an OT\/ICS asset can be helpful for training, for example. And if you see something suspicious, like an attempt to change the code or a variable in a programmable logic controller (PLC), you can terminate the session with a click and disconnect the remote user. Remote session termination is required by ISA\/IEC62443-3-3 FR2. 2 \u2013 Maintain a complete log of past sessions Cybersecurity best practices require maintaining a detailed history of all past sessions, useful for security audits, forensic investigations, and regulatory compliance. The EU\u2019s NIS2 Directive, for example, requires a full audit trail for every event that affects critical infrastructure and OT security standards such as ISA\/IEC62443-3-3 require records of all login attempts. Cisco SEA logs both system-generated and user-generated events. For example, review how remote users authenticate, including usernames, time, device posture, and session activities. Or see who added new users or new assets to the system. 3 \u2013 Record sessions to see what happened Optionally record sessions for selected assets, simply by selecting the asset on the console and checking a box. Recordings enrich your audit trail and can be particularly helpful for troubleshooting. If an asset like a robot arm, wind turbine, or highway sign stops working, for example, you might discover that a vendor recently upgraded the software or made a typo in a new configuration. Faster troubleshooting helps you put the asset back into production sooner. Keep it simple, with an all-in-one solution for secure equipment access Summing up, Cisco SEA gives you a single interface to protect your ICS and OT assets with ZTNA. Require all remote users to authenticate through a single point. Control which assets they can access and at what times. And do what a video camera does by monitoring all remote session activities and recording data for security audits. Learn more about Cisco Secure Equipment Access here. Share Share: \u00a0\u00a0Learn how Cisco Secure Equipment Access gives you visibility into active and past remote access sessions, lets you terminate an active session if something doesn\u2019t look right, and record sessions for training or forensics.\u00a0\u00a0Read More\u00a0Cisco Blogs\u00a0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/\" \/>\n<meta property=\"og:site_name\" content=\"JHC\" \/>\n<meta property=\"article:published_time\" content=\"2023-11-30T00:54:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/11\/16475678-hY5pua.gif\" \/>\n\t<meta property=\"og:image:width\" content=\"1\" \/>\n\t<meta property=\"og:image:height\" content=\"1\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/gif\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/\"},\"author\":{\"name\":\"\",\"@id\":\"\"},\"headline\":\"Gain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm\",\"datePublished\":\"2023-11-30T00:54:30+00:00\",\"dateModified\":\"2023-11-30T00:54:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/\"},\"wordCount\":723,\"publisher\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/11\/16475678-hY5pua.gif\",\"articleSection\":[\"Cisco: Learning\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/\",\"url\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/\",\"name\":\"Gain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm - JHC\",\"isPartOf\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/11\/16475678-hY5pua.gif\",\"datePublished\":\"2023-11-30T00:54:30+00:00\",\"dateModified\":\"2023-11-30T00:54:30+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#primaryimage\",\"url\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/11\/16475678-hY5pua.gif\",\"contentUrl\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/11\/16475678-hY5pua.gif\",\"width\":1,\"height\":1},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/jacksonholdingcompany.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Gain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/#website\",\"url\":\"https:\/\/jacksonholdingcompany.com\/\",\"name\":\"JHC\",\"description\":\"Your Business Is Our Business\",\"publisher\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/jacksonholdingcompany.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/#organization\",\"name\":\"JHC\",\"url\":\"https:\/\/jacksonholdingcompany.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/07\/cropped-cropped-jHC-white-500-\u00d7-200-px-1-1.png\",\"contentUrl\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/07\/cropped-cropped-jHC-white-500-\u00d7-200-px-1-1.png\",\"width\":452,\"height\":149,\"caption\":\"JHC\"},\"image\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Gain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm - JHC","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/","og_locale":"en_US","og_type":"article","og_title":"Gain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm","og_description":"Zero Trust Network Access (ZTNA) is a secure remote access service. It verifies remote users and grants them access to the right resources at the right times based on identity and context policies.\u2026 Read more on Cisco Blogs \u200b Zero Trust Network Access (ZTNA) is a secure remote access service. It verifies remote users and grants them access to the right resources at the right times based on identity and context policies. This is part 3 in our blog series about ZTNA for operational technology (OT). Check out Part 1 for why ZTNA beats out always-on VPNs for OT remote access and Part 2 for how ZTNA reduces the attack surface by restricting access methods and verifying remote users\u2019 security posture. Video cameras are everywhere, including in facilities with the strictest physical access controls. Even if you trust an individual to enter a sensitive area, you still need to monitor their activities once they\u2019re in the door. Seeing a suspicious activity, you can step in to stop it. And if problems crop up after the visit, reviewing a recording can help pinpoint what went wrong. Monitoring and recording activities are equally critical when it comes to remote users accessing your OT networks. It\u2019s not enough to verify the identity of remote employees, vendors, and contractors. Neither is it enough to know who is connected to what OT\/ICS assets. You also need to know what users are doing during remote access sessions. Most organizations lack that visibility today, a shortcoming for cybersecurity compliance, governance, the ability to stop and recover from breaches, and incident investigation. Conveniently, Cisco Secure Equipment Access (SEA) gives you an all-in-one solution to grant remote access, enforce access controls, and monitor and record remote session activity. Here are three ways you can take advantage of Cisco SEA to actively control OT remote access. 1 \u2013 Monitor, join, and terminate active sessions See a list of all active sessions on the Cisco SEA console. By clicking on the session between \u2018User A\u2019 and \u2018Asset B\u2019 you can watch session activities as they happen, including commands sent to the asset. Watching a vendor configure an OT\/ICS asset can be helpful for training, for example. And if you see something suspicious, like an attempt to change the code or a variable in a programmable logic controller (PLC), you can terminate the session with a click and disconnect the remote user. Remote session termination is required by ISA\/IEC62443-3-3 FR2. 2 \u2013 Maintain a complete log of past sessions Cybersecurity best practices require maintaining a detailed history of all past sessions, useful for security audits, forensic investigations, and regulatory compliance. The EU\u2019s NIS2 Directive, for example, requires a full audit trail for every event that affects critical infrastructure and OT security standards such as ISA\/IEC62443-3-3 require records of all login attempts. Cisco SEA logs both system-generated and user-generated events. For example, review how remote users authenticate, including usernames, time, device posture, and session activities. Or see who added new users or new assets to the system. 3 \u2013 Record sessions to see what happened Optionally record sessions for selected assets, simply by selecting the asset on the console and checking a box. Recordings enrich your audit trail and can be particularly helpful for troubleshooting. If an asset like a robot arm, wind turbine, or highway sign stops working, for example, you might discover that a vendor recently upgraded the software or made a typo in a new configuration. Faster troubleshooting helps you put the asset back into production sooner. Keep it simple, with an all-in-one solution for secure equipment access Summing up, Cisco SEA gives you a single interface to protect your ICS and OT assets with ZTNA. Require all remote users to authenticate through a single point. Control which assets they can access and at what times. And do what a video camera does by monitoring all remote session activities and recording data for security audits. Learn more about Cisco Secure Equipment Access here. Share Share: \u00a0\u00a0Learn how Cisco Secure Equipment Access gives you visibility into active and past remote access sessions, lets you terminate an active session if something doesn\u2019t look right, and record sessions for training or forensics.\u00a0\u00a0Read More\u00a0Cisco Blogs\u00a0","og_url":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/","og_site_name":"JHC","article_published_time":"2023-11-30T00:54:30+00:00","og_image":[{"width":1,"height":1,"url":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/11\/16475678-hY5pua.gif","type":"image\/gif"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#article","isPartOf":{"@id":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/"},"author":{"name":"","@id":""},"headline":"Gain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm","datePublished":"2023-11-30T00:54:30+00:00","dateModified":"2023-11-30T00:54:30+00:00","mainEntityOfPage":{"@id":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/"},"wordCount":723,"publisher":{"@id":"https:\/\/jacksonholdingcompany.com\/#organization"},"image":{"@id":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#primaryimage"},"thumbnailUrl":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/11\/16475678-hY5pua.gif","articleSection":["Cisco: Learning"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/","url":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/","name":"Gain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm - JHC","isPartOf":{"@id":"https:\/\/jacksonholdingcompany.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#primaryimage"},"image":{"@id":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#primaryimage"},"thumbnailUrl":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/11\/16475678-hY5pua.gif","datePublished":"2023-11-30T00:54:30+00:00","dateModified":"2023-11-30T00:54:30+00:00","breadcrumb":{"@id":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#primaryimage","url":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/11\/16475678-hY5pua.gif","contentUrl":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/11\/16475678-hY5pua.gif","width":1,"height":1},{"@type":"BreadcrumbList","@id":"https:\/\/jacksonholdingcompany.com\/gain-control-over-ot-remote-access-with-session-monitoring-recording-and-termination-ruben-lobo-on-november-29-2023-at-501-pm\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/jacksonholdingcompany.com\/"},{"@type":"ListItem","position":2,"name":"Gain control over OT remote access with session monitoring, recording, and termination Ruben Lobo on November 29, 2023 at 5:01 pm"}]},{"@type":"WebSite","@id":"https:\/\/jacksonholdingcompany.com\/#website","url":"https:\/\/jacksonholdingcompany.com\/","name":"JHC","description":"Your Business Is Our Business","publisher":{"@id":"https:\/\/jacksonholdingcompany.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/jacksonholdingcompany.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/jacksonholdingcompany.com\/#organization","name":"JHC","url":"https:\/\/jacksonholdingcompany.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jacksonholdingcompany.com\/#\/schema\/logo\/image\/","url":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/07\/cropped-cropped-jHC-white-500-\u00d7-200-px-1-1.png","contentUrl":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/07\/cropped-cropped-jHC-white-500-\u00d7-200-px-1-1.png","width":452,"height":149,"caption":"JHC"},"image":{"@id":"https:\/\/jacksonholdingcompany.com\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/posts\/1803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/comments?post=1803"}],"version-history":[{"count":0,"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/posts\/1803\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/media\/1804"}],"wp:attachment":[{"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/media?parent=1803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/categories?post=1803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/tags?post=1803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}