« Guess who wrote this ... | Main | Congress wants to put an end to NSA wiretaps without warrants »

May 16, 2007

Richard Stiennon comments on Amrit's NAC post

I decided to do Rich the favor and list his comments into the center section for everyone to see.  I don't agree with Richard on this (that is no secret) but wanted to give his point of view its due.  So Amrit has his take, Richard his and I mine. Thats what makes the world go round!

Too bad one can't comment at Enterprise Systems. So I'll comment here instead!   You have to admit Amrit lays out his arguments pretty well even though they are tainted by a configuration management perspective. But, you know what? NAC is all about configuration management. The way it is being promulgated (Thank you FireFox for in-line spell checking!)NAC addresses the issue of out-of-policy devices and what to do with them. Security is a side issue although the vendors like to push that aspect. But NAC cannot address security issues beyond the prevention of the spread of a worm or virus- at the expense of loss of productivity.

To me the issue is: After investing all that money in NAC what have you done to counter the threat of a healthy machine being used to attack you?

Yes, configuration management, NAC, and security all overlap. But I would draw the diagram with NAC inside Config Management and both intersecting a small piece of security.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e4d369e200d83556e9f069e2

Listed below are links to weblogs that reference Richard Stiennon comments on Amrit's NAC post:

Comments

My Photo

Subscribe to my blog

Enter your email address:

Delivered by FeedBurner

Lijit Search

Blog Networks

Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 2.5 License.

Search

Lijit Search

Attend a Computer Forensics Boot Camp to better your skills and become a better worker
Blog powered by TypePad
Member since 10/2005