tgreene
Executive Editor

How businesses should look at NAC

Opinion
Feb 26, 20082 mins

* NAC shouldn't be seen as a separate security system

Businesses shouldn’t look at NAC as a separate security system, but rather as a set of tasks that must be performed in an overall network architecture regardless of the actual gear carrying them out, according to a recent report by the Yankee Group.

The goal should be logon-to-shutdown security that incorporates NAC in its broadest definition, but that doesn’t necessarily have to be delivered in the form that NAC vendors present it.

That definition embraces pre-connect posture checks on endpoints as well as subsequent re-checks, monitoring of behavior for suspicious activity and acting to alert about or block traffic that violates policies.

The study suggests considering existing network infrastructure and products from more than one vendor to piece together the desired protection. If that coincides with a vendor’s NAC offerings, fine, but customers shouldn’t feel they must be locked in to buying wholesale into a single vendor’s vision of NAC.

Protection from infected endpoints, enforcing access rights and blocking network-use violations should be what businesses seek to do, says the report written by analyst Phil Hochmuth. “To accomplish this, the underlying network must be utilized as a security platform, with actionable tie-ins to multiple detection and monitoring points,” he writes.

Choosing what security functions need to be performed and how best to perform them in concert with each other may include NAC, but doesn’t mean you need to be a slave to NAC vendors’ visions of how that must be done – not necessarily good news for NAC vendors.If customers regard NAC capabilities as a cog in network security as opposed to a potentially expanding system, then NAC vendors are left with a line of gear destined to be absorbed into other devices and tools.