On NAC.
NAC is a buzzword these days: in a nutshell: Network Access Protocol tries to govern what you are allowed to do on the network based on who you are. So, there's a policy that is defined according to three parameters:
- Who you really are (authentication)
- Your end-point security (are you from a fixed and uptodate security-wise desktop running a secure operating system or are you connecting from a Windows desktop that hasn't been upgraded in the last three month)
- Network environmental information: are you connecting through a wireless access point or through a VPN. Are you in the main building or a remote office.
- What's NAC's ROI?
- NAC is reactionary, it's worrying about last week threats
- It's complicated, there are tons of solutions (M$, Juniper, Cisco) and its granularity (down to individual FW policies, for instance) can make it difficult to deploy it adequately.
Update: there has been a lot of articles published on NAC recently, as the topic is picking up more steam than ever before. The company StillSecure.com for instance, publishes a bunch of interesting papers on the topic.
Labels: security
0 Comments:
Post a Comment
<< Home