Network Access Control (NAC) Devices
5 slides · 4 min read · Domain 4
Network Access Control Devices
Network access control devices manage and enforce security policies by controlling which users or devices can access a network, based on authentication, compliance, and authorization rules.
An organization's network is perhaps one of its most critical
assets.
As such, it is vital that we both know and control access to it, both from insiders (e.g., employees, contractors) and outsiders (e.g., customers, corporate partners, vendors). We must be able to see who and what is attempting to make a network connection.
At one time, network access was limited to internal devices. Gradually, that was extended to remote connections, although initially those were the exceptions rather than the norm. This started to change around 2009 and 2010 when growth began to increase with the concepts of Bring Your Own Device (BYOD) and Internet of Things (loT). Currently, many organizations support both concepts, and the growth of both is increasing year after year. There are an estimated tens of billions loT devices in global use. Add to that mix the rapid increase in remote working necessitated by the COVID-19 pandemic. It is perhaps safe to say network access control (NAC) is becoming ever more important.
Having identified the need for a NAC solution, the capabilities sought should be identified. As we know, everything begins with a policy, the organization's access control policies and associated security policies should be enforced via NAC devices. Remember, of course, that an access control device only enforces policies and does not create them.
The NAC device will provide the network visibility needed for access security and may later be used for incident response. Aside from identifying connections, it should also be able to provide isolation for noncompliant devices within a quarantined network. When linked to a health remediation service, it should provide a mechanism to fix the noncompliant elements such as turning on endpoint protection, setting firewall rules, and installing missing patches before allowing the device to fully join the network.
In short, the NAC should ensure that all devices wishing to join the network do so only when they comply with the requirements laid out in the policies.
Considering just loT for a moment, it is important to understand the range of devices that might be found within an organization. loT includes heating, ventilation, and air conditioning (HVAC) systems that monitor the ambient temperature and adjust the heating or cooling levels automatically, air-monitoring systems, security systems, sensors, and closed-circuit television (CCTV), right down to vending and coffee machines.
This visibility will group users together with temporary users such as guests or contractors, and any devices they may bring with them into the organization. Finally, NAC devices should provide bidirectional integration, allowing full integration with all security and network solutions that are, or will be, deployed within the corporate network.
Let's consider some possible use cases for NAC deployment:
- Medical devices,
- loT devices,
- Incident response,
- BYOD,
- Guest users and contractors,
- Cloud,
- Compliance, and
- Mobile devices (e.g., laptops, tablets, smartphones).
We'll focus on just a few, starting with the two use cases previously identified: BYOD and loT. Cisco's Identity Services Engine (ISE) is an industry standard solution that provides the visibility that all NAC devices must provide. Identifying applications, users, and devices, ISE identifies and simplifies network management control.
As established, it is critically important that all mobile devices, regardless of their owners, go through an onboarding process, ideally each time a network connection is made, and that the device is identified and interrogated to ensure the organization's policies are being met.
loT devices typically are not capable of defending themselves from attack, and many require wider network accessconsider Amazon's Alexa. With some devices, the security credentials are even hard-encoded and cannot be changed, such as in pacemakers.
If the device cannot defend itself, then NAC can provide threat defense by establishing secure, isolated loT network segments and by monitoring traffic in and out of those segments, looking for cyberattacks or compromised hosts, and blocking such attacks and connections.
NAC devices should also be capable of corelating information from threat sensors such as advanced malware protection, data loss prevention (DLP), and next-generation, intrusion-prevention systems (NGIPS), effectively automating the triggering of a response and blocking or quarantining affected devices on the network.
