Solution Architecture
Tenable One OT Exposure Platform Components
The Tenable One OT Exposure solution is composed of these components:
-
ICP (Tenable One OT Exposure Appliance)— This component collects and analyzes the network traffic directly from the network (via a span port or network tap) and/or using a data feed from the Tenable One OT Exposure Sensor (OT Exposure Sensor). The ICP appliance executes both the Network Detection and Active Query functions.
-
Tenable One OT Exposure Sensors — These are small devices deployed on network segments that are of interest, up to one sensor per managed switch.Tenable One OT Exposure sensors provide full visibility into these network segments by capturing all the traffic, compressing the data and then communicating the information to the Tenable One OT Exposure appliance. You can configure Sensors version 3.14 and later to send out active queries to the network segments on which they are deployed.
Network Components
Tenable One OT Exposure supports interaction with the following network components:
-
Tenable One OT Exposure user (management) — You can create user accounts to control access to the Tenable One OT Exposure Management Console. You can access the Management Console through a browser (Google Chrome) via a secure socket-layer authentication (HTTPS).
Note: You can only access Tenable One OT Exposure user interface from the latest version of Chrome.
-
Active Directory Server — User credentials can optionally be assigned using an LDAP server, such as Active Directory. In this case, user privileges are managed on the Active Directory.
-
SIEM— Send Tenable One OT Exposure Event logs to a SIEM using Syslog protocol.
-
SMTP Server —Tenable One OT Exposure sends event notifications by email to specific groups of employees via an SMTP server.
-
DNS Server — Integrate DNS servers into Tenable One OT Exposure to help in resolving asset names.
-
Third-party applications — External applications can interact with Tenable One OT Exposure using its REST API or access data using other specific integrations1.
