tgreene
Executive Editor

How do you measure the volume and cost of things that didn’t happen?

Opinion
May 29, 20082 mins

* NAC is for solving problems not for making profit

It’s hard to prove that NAC can produce an ROI. It’s not alone among security technologies that have trouble quantifying their worth because they stop bad things from happening. How do you measure the volume and cost of things that didn’t happen?

The answer is you can’t, but there are a host of soft costs that may persuade the corporate bean counters to spring for NAC if it is otherwise warranted.

NAC can reduce downtime because fewer infected machines wreak havoc on the network, and the ability to contain outbreaks reduces the cleanup time for those attacks that manage to get through.

NAC can claim a variety of administrative savings. With NAC in place, guests can log themselves in to limited areas of the network without an administrator having to set up individual accounts. Administrative time is freed up by automating endpoint checks to see that the machines have acceptable security configurations.

With some NAC products, machines found lacking can be remediated automatically, again reducing the amount of assistance that administrators and help desk workers have to deliver.

Some NAC vendors whose products can be deployed as an overlay to existing network gear claim cost-avoidance. If NAC can embrace some existing network equipment as part of the NAC deployment, then the customer is getting added utility out of an existing investment as well as avoiding the cost of adding that NAC element.

From an accounting standpoint, all these merits are pretty squishy. The bottom line: stick to the argument that you need NAC to solve specific problems, not that NAC can be a profit center.