jheary
Distinguished Systems Engineer

Tips on creating a solid NAC Host Security Policy

Analysis
Aug 23, 20073 mins

I know, I hate creating host security policies too. They are a huge pain and a lot of work. But, the success of any NAC deployment relies heavily on the quality, and existence, of a solid host security policy (HSP). This host security policy should be specific to NAC so if you already have a generic one just rework it for NAC. Either way, your host security policy will serve as a guide for how you configure your NAC policies, where you place NAC in the network, and how you approach NAC’s ongoing maintenance. To be most effective a NAC host security policy should be created before NAC is deployed. To give you a start on the creation of your company’s unique host security policy here are some things that should be completed:

  • Obtain buy in from senior management and all stake holders affected by a NAC deployment. This step is critical to the success of the completed host policy and ultimately to the NAC deployment in general. Find an executive level project sponsor that will support you through the creation of, and subsequent enforce of, the host security policy.
  • Document the 10,000ft goal(s) that your HSP should focus on or accomplish. Be sure to include a representative from all relevant departments to help with goals creation. An example high level goal could be, “All company owned PC’s must be running an up-to-date version of the corporate Anti-virus software.” Or “User authentication must be enabled on all active switch ports in the university dorm buildings.”
  • This brings me to another point, it works best if you break up your company into separate NAC security domains. A NAC security domain can best be described as a group of network areas, host types, and/or locations that fall under a common host security policy. An example domain might be “guest access” or “VPN users”.
  • Establish an acceptable use policy for hosts in your network. Decide what security domains will be required to accept the AUP upon network login.
  • If your NAC solution is user role or group based, like Cisco NAC Appliance, then you need to determine what role types are needed. An example role might be, “guests” or “employees”.
  • Determine what access rights each individual user role or group has on the network. Additionally, consider if these rights need to change based on the clients location.
  • Define what host security posture checks and subsequent remediation options should be applied to each user role or group.
  • Finally, make sure you document and have agreement on how the HSP document itself will be kept current. A stale, never looked at again, HSP is of little value. It is critical that you ensure that your HSP is as living a document as is practical. For some this might me an annual review. For others it might mean updating it each time a new security check is added to a NAC policy.

This list will hopefully help you on your journey to creating your own unique host security policy for NAC. In my book, Cisco NAC Appliance, I devote a whole section to creating a NAC host security policy. So if you want more details you can get it there. So did I miss any major points? Do you have some HSP creation tips of your own you’d like to share? Blog Away!!

jheary

Jamey Heary, CCIE #7680, is a Distinguished Systems Engineer at Cisco Systems. Jamey sits on the PCI Security Standards Council- Board of Advisors where he provides strategic and technical guidance for future PCI standards. Jamey has authored several security books, his latest is Cisco ISE for BYOD and Secure Unified Access. He also has a patent on a new DDoS mitigation and firewall IP reputation technique. Jamey leads numerous security advisory boards for Cisco Systems and is a founding member of the Colorado Healthcare InfoSec Users Group. He is also recognized as a Distinguished Speaker at Cisco Live. He has been working in the IT field for 19 years and in IT security for 15 years.

More from this author