Saturday, June 10, 2006

On NAC.

NAC is a buzzword these days: in a nutshell: Network Access Protocol tries to govern what you are allowed to do on the network based on who you are. So, there's a policy that is defined according to three parameters:
  1. Who you really are (authentication)
  2. Your end-point security (are you from a fixed and uptodate security-wise desktop running a secure operating system or are you connecting from a Windows desktop that hasn't been upgraded in the last three month)
  3. Network environmental information: are you connecting through a wireless access point or through a VPN. Are you in the main building or a remote office.
Couple points:
  1. What's NAC's ROI?
  2. NAC is reactionary, it's worrying about last week threats
  3. It's complicated, there are tons of solutions (M$, Juniper, Cisco) and its granularity (down to individual FW policies, for instance) can make it difficult to deploy it adequately.
Lots of links are available on the topic. Here's one that's a good starting point.

Update: there has been a lot of articles published on NAC recently, as the topic is picking up more steam than ever before. The company StillSecure.com for instance, publishes a bunch of interesting papers on the topic.

Labels:

0 Comments:

Post a Comment

<< Home