tgreene
Executive Editor

StillSecure on the fence about hosted NAC

Opinion
Feb 12, 20092 mins

* StillSecure is looking to get into the security services business but still on the fence about including hosted NAC

When StillSecure announced this week it will offer services as well as security gear, it was still on the fence about whether to include hosted NAC.

The problem is that NAC isn’t a clearly self-contained entity, says Alan Shimel, the chief strategy officer for the company.

And he has a point. Whereas you can put a firewall or intrusion detection system in a box and install it and monitor it, it’s not so simple with NAC. Part of the reason is the nature of how NAC fits into a network.

NAC can be packaged as a stand-alone appliance, but unless it sits inline with every access switch (or is the access switch) it must interact with other devices on the network. That means a potentially complicated configuration to fit in with switches, firewalls, VPN concentrators, what have you, that will act as enforcement points for NAC policies.

This may require upgrading other network infrastructure to support NAC – not the ideal scenario for a business trying to sell managed security services as a way to boost security economically.

NAC is also an interdepartmental challenge. Policies are set by a combination of business, network, desktop and security executives, something that companies have trouble sorting out themselves. Imagine being the service provider coming in trying to coordinate cooperation.

A better way of looking at NAC as a service is to consider it part of a larger identity-aware network security plan that includes other elements such as IDS/IPS, application firewalling and the like. Such a service may include elements of NAC, but, as Shimel says, “It may look different from NAC.”