Mobile device proliferation means joining NAC with MDM-- you need to control the proliferation of smart devices. It's not going to be easy.
The number of break-ins to high profile networks is at an all time high. Media announcements of a seeming record number of ripped off user information, credit card links, and other sensitive information appears seemingly daily. Somehow, someone broke in. Admittance control doesn’t necessarily make the fortress bullet proof, but conceptually, it allows a lot of control over credentials of users running on internal network circuits. Admittance control surrounds two concepts: authentication, and policy control. Users desiring admittance to a network are vetted after authentication, through policies, to determine if their user environment is up to date. If it’s not, the idea is to remediate the user’s environment to accommodate patches, fixes, virus control packages, or other elements of their platform to a standard. Once held to this standard, network admittance is granted, subject to the user’s security rights individually, and through group membership. That’s the theory. In reality, there are other difficulties that now have a direct bearing on NAC. Part of the problem surrounds the large number of devices that can’t be used with NAC; these devices, like non-Windows based smartphones and tablets, often lack NAC agents that vet the device. Another difficulty lies with the sheer complexity of NAC infrastructure—sophisticated policies, third-party vendor liaison, and maintaining the layout. Users with WiFi tablet and smartphone devices need to be vetted separately, through the use of MDM applications. Linking MDM and NAC seems like a natural idea, but Mobile Device Management is only now being linked to NAC. Cisco and Enterasys have partial coverage, but some of the admittance control revolves around identifying devices, and new devices are entering the marketplace faster than vendors can keep up. Microsoft’s NAC implementation revolves around the use of third parties to control the vetting procedure associated with non-Windows devices. This means that the admittance control often vectors unknown, unvetted devices to DMZ or walled areas, prohibiting devices from peer-use of network resources. While seemingly painful—users unable to get direct access to many kinds of objects and resources—it’s a price that has to be paid. The reason is that malware-infested devices are difficult to detect, and in the case of iOS and Android, rooted (security compromised) devices are difficult to detect. There’s really no choice but to deny full access until a reasonable MDM solution for the device will be found for an unknown, yet user-desired device. Microsoft hopes to offer iOS and Android MDM control when System Center: Configuration gets its updates that allow it to replace Microsoft’s System Center: Mobile Device Manager/SC:MDM. It remains to be seen how fast Microsoft will be able to perform the updates needed to vet fresh and unknown devices into the protection schemes afforded by having a connected NAC and MDM application that covers more than Microsoft Windows Mobile Devices, which is the current limitation of the production software shipping with SC:MDM. Caught in the middle are other MDM makers, who must build connectors to System Center, or potentially get lost in the shuffle. Updates to devices, and the integrity of MDM control by third parties will become more difficult as tablet and smartphone devices proliferate. The demands to day for new device vetting are high, and this will only increase. Managing the synchronization between NAC controls, third party MDM applications, and the ongoing threats to the multitudinous number of smartphone operating systems and environments adds yet another dimension to the control issue. Rapid updates, ad hoc vetting analysis, persistent and dissolving smart device agent provisioning, these are all details yet to be worked out, for the large part. Although web site stability has become crucial to security, so has admittance control as mobility becomes mandatory. A strong MDM-NAC link will evolve, but the variety of devices that users will demand to be used will become one of the biggest challenges of the early part of this decade.




