- 12 myths about how the Internet works
- Smartphone smackdown: Storm vs. iPhone
- IETF: Should we ignore the Kaminsky bug?
- Top 10 wicked cool algorithms
- How to recession-proof yourself
Senior Editor Tim Greene clarifies issues surrounding the evolving NAC security architecture.
A panel of NAC experts at Interop gave a broad overview of the status of the technology, which it declared mature, meaning that most vendors have a way to deal with devices that can't support a NAC client or per-session agent and support 802.1x enforcement.
The panel also said the next generation of NAC will pull in other security systems such as IDS (Compare IDS products), VPN, antivirus (Compare antivirus products) and firewalls (Compare Enterprise Firewall products) to share data they collect and use that to make policy-enforcement decisions. In addition, a unified management of NAC and these other systems will be developed over time to enable a single administrator to draw on all the platforms at once to isolate incidents.
Since its inception, the expectations about what NAC can do has expanded from checking the security posture of a device to providing broad visibility into what each device is doing on the network and whether that complies with policies.
This capability is being developed to assign least privileges to end users, that is granting them access to just those resources they need to do their jobs and nothing else, members of the panel said.
Coming down the pike are industry-specific applications of NAC that, they say, tie in with existing infrastructure in manufacturing or financial industries to meet their unique access control needs.
The panel seemed to agree that NAC standards from the IETF will be readily incorporated into today’s NAC products that comply with the standards put out by Trusted Computing Group (TCG). The IETF is working on a set of standards that will be more broadly accepted - which pretty much means that Cisco will comply with them - and should be ready sometime next year.
The IETF standards amount to TCG standards that have undergone tweaking, so bringing TCG compliant standards into compliance with IETF standards should be relatively painless, the panel said.
Tim Greene is senior editor at Network World.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comments (1)
NACBy realvillain on September 23, 2008, 4:05 pmROFL So this panel of 'NAC experts' are saying its mature yet admit that primary features such as;- least privledge provisioning, unified management. So not only...
Reply | Read entire comment
View all comments