July 19, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Messaging Middleware Syndicate This
Print this article    Email this article    Talk Back!    Write to Editor
What You Need to Know About Access Control
03/17/2008
By Dan Clark, Vice President of Marketing, Lockdown Networks
Untitled Document

***Editor's Note: If you like this topic, make sure you sign-up for the ebizQ webinar, Threatscape 2008, that'll explore in-depth what threats to expect in 2008 and how to effectively combat them.

ADVERTISEMENT
Our Popular Webinars
BPM for Financial Services
Roundtable Discussion: Open Source Market Update
Event-Driven SOA: The Best Practice of Advanced Architecture Teams
Evolving Security Architectures and SOA for Better Business Collaboration
Getting Started with BPM
More Webinars

Network Access Control (NAC) is a hot topic in network security. Unfortunately, most NAC discussions focus on inline vs. out of band, or pre-connect vs. post-connect. This emphasis on architectures obscures the real issue: how best to realize an enterprise’s security objectives.

It All Starts with Policy

NAC is widely considered a solution to three distinct problems: (1) control of access based on identity; (2) enforcement of health/compliance policies; and (3) malware containment. Many enterprises initiate NAC projects in response to one of these driving issues. For instance, universities may worry more about student machines without adequate virus protection, while enterprises may be more concerned about avoiding access by malicious users.

A successful NAC deployment ultimately begins with an accurate assessment of security needs and policy objectives. Without laying this groundwork, an enterprise can easily find itself in a situation where policy is dictated by the choice of NAC architecture, resulting in failed or limited deployments. To optimize the value of a NAC deployment it’s essential to think about future requirements, not just near-term policy drivers.

Available NAC Architectures

In general, vendors have developed three architectural approaches to NAC: edge, inline and protocol. Edge solutions using VLANs offer the strongest enforcement approach, while protocol and inline enforcement offer faster rollouts.

Each approach aligns to one or two of the typical NAC objectives. While a few vendors claim to know everything about everyone on the network, there is no current NAC product that fully addresses all three objectives on its own. Doing so requires interoperability with existing security and network infrastructure.

Edge-based NAC utilizes VLAN enforcement on switches and WAPs to control access, as shown in Figure 1. VLAN enforcement is very secure, controlling access before users and devices join a network, making it more difficult for malicious users to circumvent. Some out-of-band NAC solutions offer strong device assessment. These attributes make edge enforcement best for user control and compliance-driven initiatives.

Page 1

More Top Stories
SQL Injection Rears Its Ugly Head Again Gold Club Protected
Data Warehouses and Disaster Recovery Gold Club Protected
Expect the Unexpected with Data Security Gold Club Protected
Is Big the New Small in Application Security? Gold Club Protected
Doing Risk Management Right Gold Club Protected
Defending Against the Cross-Site Scripting Attack Gold Club Protected
More Top Stories
Related News
Make Time for Runtime: AmberPoint Joins SAP Co-Innovation Lab
AdaptiveMobile Sees Sharp Rise in Mobile Network Virus Attacks
Little Data Leaks Can Sink the Corporate Ship
More News
Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
ebizQ Web 2.0 and the Enterprise
Your E-mail Address:
Getting Started with BPM
Date: Jul 29, 2008
Time: 12:00 PM ET
(16:00 GMT)

REGISTER TODAY!
Evolving Security Architectures and SOA for Better Business Collaboration
Date: Aug 06, 2008
Time: 12:00 PM ET
(16:00 GMT)

REGISTER TODAY!
Archived Webinars | Upcoming Webinars
  BI for Consumer Packaged Goods

By: Don Tapscott WHILE HISTORICALLY consumer packaged goods (CPG) organizations have made significant investments in data collection and...Learn More

ebizQ also recommends
 Optimal Service-Parts Management: Part One
 The Geek Gap: Do Suits Care?
 Collaboration and Social Media <i>Taking Stock of Today's Experiences and Tomorrow's Opportunities</i>
 BPM Done Right
 Mitigate Risk with Security Assessments
More White Papers

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map

Live Chat