What you are evaluating
SaaS and on-premises offerings have different deployment boundaries. This profile covers OT/IoT security; Medical Device Security, vulnerability prioritization and remote-access offerings require their own entitlement checks.
A useful evaluation context
Organizations joining IT asset records with OT and IoT visibility across several facilities.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Traffic analysis and supported active queries collect complementary device context.
- Communication baselines and policy queries identify activity that warrants review.
- Integrations can hand off context or trigger actions through NAC, firewall, ticketing or orchestration tools.
Where it fits in the work
- Reconcile a discovered device with the CMDB and confirm its physical-process owner.
- Investigate an unusual connection using device behavior and site context.
- Create a contextual ticket and obtain approval before an external enforcement tool changes access.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A facilities controller appears in network discovery but not the CMDB. In a tabletop exercise, reconcile its identity and explain whether its outbound connection is expected.
Evidence to look for
Produce a corrected ownership record, the evidence for the device match and an approved escalation path. Do not treat an enrichment match as independently verified firmware inventory.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which fields come from direct observation, active queries or enrichment?
- Where does the selected SaaS or on-premises edition retain asset data?
- What permissions can each connector exercise against critical equipment?