<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>McAfee Security Insights Blog &#187; NAC</title>
	<atom:link href="http://siblog.mcafee.com/?cat=86&#038;feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://siblog.mcafee.com</link>
	<description></description>
	<lastBuildDate>Sat, 21 Nov 2009 00:50:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Network Risk Control</title>
		<link>http://siblog.mcafee.com/?p=323</link>
		<comments>http://siblog.mcafee.com/?p=323#comments</comments>
		<pubDate>Fri, 07 Nov 2008 01:24:39 +0000</pubDate>
		<dc:creator>Dan Wolff</dc:creator>
				<category><![CDATA[NAC]]></category>

		<guid isPermaLink="false">http://siblog.mcafee.com/?p=323</guid>
		<description><![CDATA[Tim Greene at Network World just issued a nice story in support of the notion that NAC can be a sort of &#8216;backstop&#8217; to security tools.
NAC is supposed to do a lot of things and once it’s installed, customers are finding that NAC often does even more than they bargained for.
For instance, NAC can act [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.networkworld.com/newsletters/vpn/2008/110308nac2.html?hpg1=bn">Tim Greene at Network World</a> just issued a nice story in support of the notion that NAC can be a sort of &#8216;backstop&#8217; to security tools.</p>
<p>NAC is supposed to do a lot of things and once it’s installed, customers are finding that NAC often does even more than they bargained for.</p>
<p>For instance, NAC can act as a backstop to other applications such as patch management that are supposed to maintain the proper corporate desktop image. Many customers say that when their NAC gear tests the health of endpoints, it often discovers that machines that should have been patched have not been, or that updates that should have been installed haven&#8217;t.</p>
<p>One customer had statistics on the improvements. With patch-management software alone, 70% of endpoints were actually patched within 30 days of when the distribution started. With NAC in place, checking for unpatched machines as part if its tests, compliance jumped to 99% within 7 days.</p>
<p>Similarly, the same customer found that vulnerabilities on its endpoints dropped significantly after NAC was installed. On its 50,000-endpoint network, the average number of vulnerabilities was 4.3 per machine. After NAC was in place and testing for some of the items that accounted for vulnerabilities, that number dropped to 1.3 per machine.</p>
<p>While some may debate whether NAC is an effective security platform &#8211; and some well-informed security experts say it is not &#8211; it is undeniably a risk-mitigation tool. Having patched operating systems, updated antivirus and personal firewalls that are properly configured and turned on all contribute to lower risk. As these numbers from an actual user demonstrate, the benefits can be dramatic.</p>
<p>I am interested in your own stories about success with NAC, so please leave a comment below. Thanks!</p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=McAfee%20Security%20Insights%20Blog&amp;siteurl=http%3A%2F%2Fsiblog.mcafee.com%2F&amp;linkname=Network%20Risk%20Control&amp;linkurl=http%3A%2F%2Fsiblog.mcafee.com%2F%3Fp%3D323" target="_blank"><img src="http://siblog.mcafee.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://siblog.mcafee.com/?feed=rss2&amp;p=323</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Introducing the Third Generation of NAC</title>
		<link>http://siblog.mcafee.com/?p=319</link>
		<comments>http://siblog.mcafee.com/?p=319#comments</comments>
		<pubDate>Wed, 05 Nov 2008 00:47:35 +0000</pubDate>
		<dc:creator>Dan Wolff</dc:creator>
				<category><![CDATA[NAC]]></category>

		<guid isPermaLink="false">http://siblog.mcafee.com/?p=319</guid>
		<description><![CDATA[ 
OK, you have spent a lot to secure your endpoints, but is your investment going to waste?
IT organizations large and small have invested heavily in endpoint security to address the rapidly evolving security challenge. AntiVirus, AntiSpam, Firewall, Host Intrusion Prevention, Compliance Auditing and more have been deployed to protect and assess endpoints. Much has [...]]]></description>
			<content:encoded><![CDATA[<p><!--[if gte mso 9]><xml> Normal   0                                 false   false   false      EN-US   X-NONE   X-NONE                                                     MicrosoftInternetExplorer4 </xml><![endif]--><!--[if gte mso 9]><xml> </xml><![endif]--> <!--[if gte mso 10]></p>
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Calibri","sans-serif";
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
</style>
<p><![endif]--></p>
<p>OK, you have spent a lot to secure your endpoints, but is your investment going to waste?</p>
<p>IT organizations large and small have invested heavily in endpoint security to address the rapidly evolving security challenge. AntiVirus, AntiSpam, Firewall, Host Intrusion Prevention, Compliance Auditing and more have been deployed to protect and assess endpoints. Much has been made of the &#8220;dissolving perimeter problem&#8221;, and rightly so. But in today&#8217;s economy companies are increasingly looking to also &#8216;dissolve the controls&#8221; in an effort to reduce operational and hardware cost by allowing end users to acquire and manage their own hardware. When many users are allowed to self administer their own computers, it becomes relatively easy for them to install all manner of questionable applications (e.g. peer to peer) and even tamper or disable Antivirus or endpoint firewall policies. This introduces a great challenges to network security staff, as this self imposed &#8216;back door&#8217; creates a vulnerability and risk that needs a solution.</p>
<p>Enter NAC</p>
<p>NAC (Network Access Control), continues to generate a lot of enthusiasm, and correspondingly, a large number of corporate initiatives to ensure the security and &#8216;health&#8217; of endpoints connecting to the corporate network. An August survey of McAfee&#8217;s customers shows that 68% of companies are evaluating or have already deployed a NAC (Network Access Control) solution. A great potential for a NAC solution is to ensure that machines that are outside of some compliance standards cannot access corporate resources unless they meet a minimal standard of health, such as</p>
<ul>
<li>Security tools are up to date: is AV and Anti-Spyware on are signatures within a certain age limit? Are DLP solution installed and working properly?</li>
</ul>
<ul>
<li>Are only acceptable applications present. e.g. no Peer to Peer applications.</li>
</ul>
<ul>
<li>Once a machine is on the network, is it &#8216;clean&#8217;? For example, is it infected with a bot or other malware that a NAC solution can detect.</li>
</ul>
<p>On October 20<sup>th</sup>, McAfee announced Unified Secure Access, our answer to the NAC. Unified Secure Access uniquely enables enterprises to manage access to networks and systems based on in-depth knowledge of system health, compliance and user identity and enforce compliance both pre- and post-admission with a broad array of enforcement options, including end-point, in-line and infrastructure integration options.This along with McAfee&#8217;s well established policy management infrastructure enable, for the first time, simplified NAC implementations that reduce operational cost and resources while ensuring reliable access to approved systems and personnel.</p>
<p>NAC has the potential to ensure investments in security tools are maintained. More on this in an upcoming post.</p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=McAfee%20Security%20Insights%20Blog&amp;siteurl=http%3A%2F%2Fsiblog.mcafee.com%2F&amp;linkname=Introducing%20the%20Third%20Generation%20of%20NAC&amp;linkurl=http%3A%2F%2Fsiblog.mcafee.com%2F%3Fp%3D319" target="_blank"><img src="http://siblog.mcafee.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://siblog.mcafee.com/?feed=rss2&amp;p=319</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.338 seconds -->
<!-- Cached page served by WP-Cache -->
