tgreene
Executive Editor

What businesses want from NAC

Opinion
Dec 11, 20072 mins

* NAC survey lists the top requirements that respondents have for NAC

In a recent NAC survey of businesses, the Aberdeen Group listed the top requirements that the respondents had for NAC. The top technology requirements were: preventing unauthorized users and machines from accessing the network; logging all access events and recording them centrally; enforcing policies on remote users; and quarantining unhealthy machines.

In a recent NAC survey of businesses, the Aberdeen Group listed the top requirements that the respondents had for NAC.

The top technology requirements were: preventing unauthorized users and machines from accessing the network; logging all access events and recording them centrally; enforcing policies on remote users; and quarantining unhealthy machines.

That was according to the group of respondents that Aberdeen ranked as best-in-class by virtue of historical successes protecting their networks. At least 75% of the best-in-class respondents ranked those requirements as either high or very high importance.

Fewer of the elite respondents ranked as high the monitoring of user behavior (66%) and the monitoring of device behavior (64%) after being admitted. The report doesn’t go into why these post-admission concerns rank lower, but the author of the report, Carol Baroudi, says she thinks that it has to do with a general lack of education about NAC.

She says she would have expected all the best-in-class users to rank the top technology requirements as high or very high importance. “The fact that it’s not there now is very disconcerting,” she says.

Rather than define NAC for the 400 chosen from among those solicited for the online survey, the group asked what they thought NAC should include.

Some of the top requirements were less about NAC functionality than about administrative concerns such as being installed without affecting network performance and being transparent to end users.

The top driver pushing businesses toward NAC is protecting networks from external attacks, not concerns about employees whose devices become infected, which ranks sixth in the survey. Even so, mitigating internal threats with NAC is still tagged as a driver by 69% of survey respondents. Protecting from external attacks was cited by 86%.