Skip to main content

Cisco Cyber Vision

Visualize your Cisco Cyber Vision OT environment in JupiterOne — the Cyber Vision Center, the industrial assets it discovers (PLCs, controllers, switches, and other devices, with their IP and MAC addresses, VLANs, and networks), and the CVE-backed vulnerabilities detected on them with their CVSS and Cisco Security Risk Scores — map each device to the vulnerabilities that affect it, and monitor OT exposure through queries and alerts.

Installation​

This integration connects to your on-premises Cisco Cyber Vision Center using the Cisco Cyber Vision New UI API (https://<center>/cvapi/v1/, Cyber Vision 5.4 and later) and ingests OT assets and the vulnerabilities detected on them. The Center is usually on your own network, so the integration normally runs on a JupiterOne Collector that can reach the Center over HTTPS (port 443 unless you include a different port in the hostname).

Configuration in Cisco Cyber Vision​

Before you configure the integration in JupiterOne, prepare the following in your Cisco Cyber Vision Center:

  • The hostname or IP address of the Center, for example 192.168.1.100. The JupiterOne Collector must be able to reach it over HTTPS.

  • An API token. In the Center, go to Admin > API > Token, click New Token (or Create your first token), enter a name such as JupiterOne, leave the Status toggle enabled, optionally set an expiration date, and save. Click Show to see and copy the token. Cisco recommends one token per application so you can expire or remove access separately. The menu location can differ between Center releases; see Cisco's authentication guide.

    The integration only sends GET requests to two endpoints, /cvapi/v1/assets and /cvapi/v1/assets/vulnerabilities, and never modifies data on the Center.

  • If the Center presents a self-signed or internal-CA TLS certificate, get the CA certificate in PEM format so the collector can verify the connection.

Once you have obtained the information above, proceed to JupiterOne to finalize the integration.

Configuration in JupiterOne​

To install the Cisco Cyber Vision integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Cisco Cyber Vision. Click New Instance to begin configuring your integration.

Creating an instance requires the following:

  • The Account Name used to identify the Cisco Cyber Vision account in JupiterOne. Ingested entities will have this value stored in tag.AccountName when the AccountName toggle is enabled.

  • Description to assist in identifying the integration instance, if desired.

  • Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as DISABLED and manually execute the integration.

  • The Center Hostname or IP of your Cyber Vision Center, for example 192.168.1.100. You can also enter host:port or a full https:// URL; the integration builds the https://<host>/cvapi/v1/ base URL from it.

  • The API Token created above. It is sent in the x-token-id request header.

  • Optionally, a CA Certificate to trust a self-signed or internal-CA certificate, or enable Disable TLS Verification to skip certificate validation (not recommended).

  • Optionally, set Minimum CVSS Score to limit the vulnerabilities that are ingested. Options: All vulnerabilities (default, no filter), 4.0 (medium and above), 7.0 (high and above), 9.0 (critical only). The value is sent to the Center as the cvss filter on /assets/vulnerabilities.

  • Optionally, set Minimum Cisco Security Risk Score to limit the vulnerabilities that are ingested. Options: All vulnerabilities (default, no filter), 25 and above, 50 and above, 75 and above. The value is sent to the Center as the csrs filter on /assets/vulnerabilities.

  • Optionally, set Last Active Within to ingest only assets that were last active within the selected window. Options: All assets (default, no filter), 7 days, 30 days, 90 days, 180 days, 365 days.

Raising either score threshold or narrowing Last Active Within removes the vulnerabilities or devices that fall outside the new filter from JupiterOne on the next run.

Data Sources​

Each data source can be enabled or disabled on its own. All data sources are disabled by default, so enable the ones you want to ingest. The Center account (cisco_cyber_vision_account) and the Cyber Vision service (cisco_cyber_vision_service) entities are always created.

Data SourceDescriptionEntities Created
DevicesOT assets (PLCs, controllers, switches, etc.) discovered by Cisco Cyber Vision, with asset type, vendor, IP and MAC addresses, VLANs, network names, vulnerability and active alert counts, and first and last active timescisco_cyber_vision_device
VulnerabilitiesCVE-backed vulnerabilities detected on Cisco Cyber Vision OT assets, with title, CVSS score, and Cisco Security Risk Scorecisco_cyber_vision_vulnerability

One vulnerability entity is created per CVE and shared by every device it affects. Its severity is derived from the CVSS score.

The relationships are built as follows:

  • Account to device (HAS) requires Devices.
  • Service to vulnerability (IDENTIFIED) requires Vulnerabilities.
  • Device to vulnerability (HAS) requires both Devices and Vulnerabilities.

The integration collects only assets and their vulnerabilities. Other Cyber Vision data, such as activities, flows, events, components, and baselines, is not retrieved.

Click Create once all values are provided to finalize the integration.

Next steps​

Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.

Additional resources​