home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Network Computing Blog
Lead NAC Analyst:
Mike Fratto
Mike Fratto


:: More analysis, strategies and news at our
NAC Immersion Center


:: Subcribe to This Blog's
RSS Feed
SPECIAL EVENT BLOGS:
BrainShare 2008

IMMERSION CENTER BLOGS:
Network Access Control
Virtualization
Application Performance Optimization
Data Center
Data Privacy
802.11n
SOA/Web Services

MORE TOPCS:
Security
Wireless
Application Infrastructure
Collaboration
Network and Systems Management
Network Infrastructure
Storage and Servers
Enterprise Applications
Business Strategy
Personal Technology
Podcasts
NWC Inc
NWC Labs
Techno-Oddities

MORE GREAT BLOGS
Ars Technica
bMighty
Boing Boing
Geek.com
InformationWeek
IT Toolbox
TechCrunch



NAC Immersion Center Blog

February 20, 2008
Standards = Survival
By Mike Fratto

This week, Steve Hanna sent the TCG/TNC specifications to the NEA working group for consideration as working group documents. These are basically submissions of existing TCG/TNC specifications along with an explanation of how the specifications meet requirements already agreed to by the NEA working group. Apparently, these are the only specifications submitted to the working group.

Great news? Not if you listen to Mike Rothman, who thinks companies don't care about standards. He thinks companies raise the standards barrier when they want to spare a salesperson's feelings. Having sat on both sides of the sales table, I don't think that's really the answer, but I also don't think Rothman's basic assessment that companies don't care about standards is off the mark.

For the last couple of years that I have polled IT professionals about NAC, I have asked how critical standards are. The responses are lukewarm for any particular standard or framework, but it's clear that IT professionals want a standard. There's good reason for that desire. If a standard emerges, that opens the door to competition among not only all the products that a NAC can leverage, but opens competition to the NAC system itself. You aren't locked into a product purchase because your NAC system depends on some other applications.

The question to ask isn't really how important standards are. The question to ask is whether organizations wait for standards. It's not as though NAC is a critical feature like IP or DNS. Organizations can live without NAC; they can still control access to applications using other technology; they can still manage guest access through process and technology; and they can still stop malicious activity like worm outbreaks. NAC just makes some of that control simpler and, depending on the product, more surgical. Would you rather stop a problem close to the source, like at the host or network port, or would you rather stop a problem that gets deeper into your network? NAC standards foster integration with everything else you've purchased.

The desire for standards hasn't reached a critical stage and probably won't for a long, long time. Today, nothing critical will be broken if NAC standards aren't adopted because few or no business processes depend on NAC. I recall troubleshooting interoperability problems between PPP stacks and remote access servers back in the '90s. Microsoft used CHAP as the remote access authentication scheme in PPP, but rather than using MD5 hashing specified in RFC 1994, Microsoft used MD4, which is what NT LANManager used. That wreaked havoc with companies using Microsoft's RAS dialer and their existing RAS equipment because users couldn't login using their domain credentials. Standards mattered in that case because of the existing RAS equipment that already had been deployed. I bet there were organizations that used Windows NT as their RAS server and had no problems at all.

Rothman's right in thinking that companies that really want NAC will move forward whether or not standards exist. They already are moving forward. Someone is buying this gear. But standards aren't just for customers. Standards are about easing integration among multiple vendors so that the salespeople don't have to jump over barriers in the field. I will even go so far as to say that no matter what form NAC takes in the future, if it's going to thrive, standards that cover every aspect from host assessment to transmitting enforcement will have to be in place and adopted by everyone.

-- Posted at 04:47 PM in NAC Immersion Center





This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights