Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

When it's OK to use NAC endpoint checking sporadically

Benefits and caveats to sporadic NAC endpoint checking
Security: Network Access Control Alert By Tim Greene , Network World , 11/27/2007
Tim Greene
Sign up for this newsletter now!

Cloud Security|Cloud computing offers advantages over building and maintaining private data centers including flexibility, reduced maintenance and operations costs and the ability to employ lower powered, lower priced personal computers.

  • Share/Email
  • Tweet This
  • Comment
  • Print

A recurring theme among NAC customers is they use NAC endpoint checking sporadically. When a computer has been scanned and found compliant once, it is designated good to connect to the network for an extended period of time - a month is the timeframe that keeps coming up.

The reason customers give is preserving a speedy login for end users. Waiting to be scanned and waiting even longer to remediate problems found is too high a price to pay. The cost-benefit of time and complaints vs. the incremental security the endpoint check gives to the organization seems to favor keeping the scans to a minimum.

These customers aren’t cavalier. They aren’t abdicating their responsibilities to keep their networks safe, they’re just facing the business reality that end user frustration can be counter productive, both in IT costs and in user distraction from achieving business goals.

If the NAC endpoint checks are minimal, customers must use other means to protect their networks, either using post-admission NAC resources or other tools such as intrusion-prevention systems and strict asset-management enforcement.

This reduced frequency for endpoint scanning seems to work for students at universities and for wired desktops at corporations, according to NAC implementers. In practice both these populations prove stable enough that they don’t cause severe enough problems that would call for more stringent scrutiny.

But the relaxed posture is not extended to guests, contractors and vendors, who are a less known quantity and whose patience is required as a cost of doing business.

Tim Greene is senior editor at Network World.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comments (2)
Login
Forgot your account info?

Creating A False Sense of SecurityBy Dana Hendrickson on November 27, 2007, 3:56 pmTim, the extreme general position you are advocating - to heavily favor user productivity over network security in setting an organization's security policies for...

Reply | Read entire comment

compromise for poor designBy Alan Shimel on November 27, 2007, 5:52 pmDana - I have to wholeheartedly agree with you. I think this is just marketing spin by companies that do not have purpose built NAC health or posture checking and...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed