* Automating policy enforcement on enterprise networks with NAC
If grade schools had technology that could stop students from coming to class unless their homework was complete, would they turn students away at the door if they hadn’t finished their assignments? Or give them a warning but let them come to class? And
If grade schools had technology that could stop students from coming to class unless their homework was complete, would they turn students away at the door if they hadn’t finished their assignments? Or give them a warning but let them come to class? And would the policy become stricter based on the type of homework?
It’s an interesting analogy to automating security policy enforcement on enterprise networks.
Historically, enterprise security policies have been distributed via books or e-mail and users are expected to comply, but compliance is hard to enforce. With network access control (NAC), it’s possible to automate enforcement. But as with the school scenario, we need to think through what enforcement means in practice.
Surprisingly, with all the hype around NAC, this topic has received little attention, yet it may be one of the most significant determinants of a deployment’s success.
The goal of NAC is not to keep devices off the network; it’s to make sure the network isn’t compromised by problem devices or unauthorized access.
For more on this story, please click here.




