* NAC best-practices survey findings
endif; ?>A recent NAC best-practices survey of 400 organizations by the Aberdeen Group found that many of them supplement NAC with other security technologies.
This makes sense since virtually all security experts recommend using layered security technologies as the best defense against threats.
One of the most surprising things about use of supplemental technologies is that they are not more widely used than the survey indicates. For instance, patch management software, which can go a long way toward ensuring that machines logging in to networks have the proper versions of software running, is used by only 69% of those surveyed that rank as best-in-class users.
Here are the Aberdeen results for the technologies they polled for:
* Identity and access management, 54% of best-in-class users
* Vulnerability scanners, 56% of best-in-class users
* Intrusion prevention, 73% of best-in-class users
* Unified threat management, 45% of best-in-class users
* Vulnerability management, 56% of best-in-class users
* Patch management, 78% of best-in-class users.
The survey indicates that of these security technologies, NAC itself is the least adopted, with only 37% of best-in-class users implementing NAC at endpoints. If expanded to any type of network access control, that percentage grows to 53% over all categories of users. The results say that enough best-in-class users have plans to implement NAC soon, so the percentage will rise to 70% next year.
Aberdeen defines best-in-class users as those that have recorded a decrease in successful network breaches over the past two years, that have had no instances of unauthorized network access and that have had no network downtime as a result of a network attack.
More from this survey next time.




