* Welcome to the Network Access Control Newsletter
Editor’s Note : Welcome to the Network Access Control Newsletter. NAC is an emerging network security architecture that starts with securing endpoints before they connect to networks and extends to monitoring and controlling their activity after they have been admitted. There are working NAC products today, but most vendors committed to NAC are still fleshing out their products, which makes it an area that warrants a newsletter of its own. Along with the shift in focus comes a new, intuitive name: the Network Access Control Newsletter. We hope you find it useful. Network World and networkworld.com will continue to cover VPNs as part of our regular news coverage. Thanks for reading.
NAC is one of the most talked about security schemes to come along in quite some time and it makes sense for IT decision-makers to pay attention to it. Different groups define NAC differently, and if it reaches its potential, it will become an important element in network security. There will be no ignoring it.
The concept of NAC in all its forms is ambitious and potentially very useful. NAC seeks to assure as much as possible that devices attempting to join networks won’t infect them with malware. And it seeks to make sure that once devices are inspected and admitted to networks, they don’t then misbehave by spreading malware that evaded initial detection.
Some NAC proposals also attempt to link machines joining networks with the people using those machines as a way to better control access rights. This linking of users with machines can better protect not only the networks, but data on the networks. So, for instance, an authorized person might try to connect from an insecure machine. In response, NAC might allow access to just a limited subset of the assets that person is authorized to reach when connected via a secure machine. In this way, the user gets some access, and the greater network is protected from the threat represented by the insecure machine.
Similarly, some NAC proposals call for tracking what resources users attempt to reach once they are admitted to networks. NAC compares that behavior with what the user is authorized to do, and when NAC detects someone trying to get at unauthorized data, it can shut down access until the behavior can be investigated.
A more refined version calls for shutting down just suspicious behaviors of particular machines, but allowing other uses. In the case of a worm-infected PC that is pumping out hundreds of e-mails per minute, NAC might neutralize its e-mail capabilities but allow all other authorized behavior.
The definitions of NAC area broad, and so the scope of this newsletter will be broad as well to help you keep abreast of this technology as it defines itself. You will find it in your inbox every Tuesday and Thursday.
Please write with comments, questions and suggestions, and thanks for reading.




