Contributor

Once and future technology? Network based entitlement is back.

Opinion
Jun 13, 20082 mins

Like the legendary period in English history there once was a company, whose product, Hark! , promised a new way to enforce the rule of law. But instead of chivalry it was access control policies that Camelot the company promised.  

For all the lovely talk about access control emanating from so-called NAC vendors who must have invoked Merlin to magically transform the unworkable Network Admission Control into Network Access Control, there is still one huge problem with access controls. Most enterprises really have no idea who should have access to what resources.  The granularity of access control needed to secure the enterprise is beyond the ken of most IT guys.  Let’s face it, knowing what applications, networks, and data sets any one of say 10,000 people should have access to is not a simple problem.

Camelot attempted to address the failings of most identity and access management (IAM) systems by building in a learning component.  What happened to Camelot?  I wish I knew.  For some reason the IT press is great at recording the history of startups as long as they have an active PR program.  As soon as vendors start to die the historical record seems to get wiped clean.  I would guess that part of the problem was that they were too far ahead of their time. Another issue was they relied on host agents to do the learning and enforcement, a company killer if there ever was one.

Now, in what appears to me to be the second coming, a new vendor is born from the knights of Cisco. Five top networking guys have apparently recognized that the marketing department at Cisco is not really that good at inventing security solutions (admission control) but that there truly is a need for automated tools to discover and enforce access control policies in the enterprise.  The company, Rohati, came out of stealth mode in time for the Gartner IT Security Summit last week in DC.  They are calling their technology Network-Based Entitlement Control or NBEC.   No agents, automated discovery, policy management. I love it.  This could work. 

I hope the ever flexible NAC vendors get out of the end point health check business.  Then we could have an industry that is all pulling in the same direction: towards better policy management, more granular authorization, and ultimately, better security.

 ———

Follow Stiennon on Twitter

Join the Security Leaders Group on LinkedIn 

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author