Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Tutorial: Network Access Control (NAC): Page 6 of 11

Fortunately, NAC policy engines aid in policy creation. Finding an engine that fits your needs in terms of ease of use and granularity is especially vital as NAC vendors add more features to their products, and policy interfaces reflect this growing number of options. Like any management UI for a complex system, features like grouping, the ability to build custom objects and easily readable rule sets are important.

NAC Immersion Center

How external systems are integrated is equally crucial. For example, if your NAC system uses Active Directory for user authentication, the management system should be able to synchronize objects like users and groups from within AD, rather than having to recreate them. In a similar fashion, antivirus products, managed firewalls and patch management systems should also feed the management UI seamlessly.

A word on politics: It's dicey business for IT to make policy decisions dealing with upper management. But resist the temptation to treat executives differently. The CFO's laptop is no less vulnerable to attack than that of a field representative. Educating about sound practices and, where applicable, pointing to regulatory compliance implications can help here.

Enforcement