Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Security

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

Crackin' the Kraken bot. Listen now!

Network World's Newsmaker of the Week

Wireless dangers at airports. Listen now!

Network World Panorama

Additional Resources

RSS

FEATURED WHITEPAPERS

Edison Group TCO White Paper HP

Edison analysts put the management software of an HP EVA system through a series of typical day-to-day storage management tasks. The same tasks were also evaluated on similar systems from NetApp and EMC. This study demonstrates how the superior user interface and virtualization offered by the HP EVA storage system can provide organizations with the benefits of higher administrative efficiency combined with the potential ability to utilize less expensive human resources.

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

Would you support government censorship of the Internet for less spam, viruses and other attacks? - Anonymous

Join the Discussion

Trusted Computing Group broadens its NAC scope

Moving beyond pre-admission NAC to post-connect NAC
Security: Network Access Control Alert By Tim Greene , Network World , 05/06/2008
Tim Greene
Sign up for this newsletter now!
  • Social Web 
  • Email 
  • Feedback 
  • Close

Trusted Computing Group is expanding its area of interest beyond pre-admission NAC to post-connect NAC.

The broadened scope comes in the form of a new protocol called IF-MAP, which stands for interface for meta-data access point. The protocol is intended to be spoken between security devices on networks and a meta-data access point (MAP) that receives and posts the data.

The idea is that security devices such as firewalls, intrusion detection and prevention systems, wireless controllers, configuration and change management platforms and the like, collect data that becomes more valuable if shared. A configuration change management platform could discover a shortcoming in an endpoint and post it to the MAP. An enterprise security management device might then determine that shortcoming violates security policy.

Notification of that violation posted to the MAP could trigger a firewall to block the device from the network.

If it is adopted, IF-MAP could enable gear from multiple vendors to participate in post-connect NAC. From the customer point of view such a development could mean a richer post-connect NAC scheme than a single vendor might offer. Perhaps as importantly, it could enable existing customer gear to participate in the scheme, potentially reducing the overall cost.

This protocol is brand new and no vendors have officially incorporated it in their products, but it’s an option that may materialize soon.

Comments (2)
Login
Forgot your account info?

Yes, it is true.By Anonymous on May 7, 2008, 8:04 amYes, it is true. Sophos' product already does that today and has been for some time. They are calling it "post-connect policy assessment". Machines that have deviated...

Reply | Read entire comment

Or you can do it today with SophosBy Anonymous on May 6, 2008, 9:45 amOr you can do it today with Sophos.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code