Network Access Control (NAC) is an industry-standard term used to describe methods and tools that selectively allow only authorized users, devices and applications to gain access to resources on the network. NAC is considered an important first line of security as it can dynamically provision the network and the access provided based on a number of administrator controlled factors.
The
Access Control diagram highlights the components of an access control solution. First and foremost, resources and access should be provisioned for authenticated users to provide them the appropriate access to accomplish their work without extending access unnecessarily. The organization may also want to extend guest access that allows users to reach the internet and external resources without compromising security. Many organizations also want a check of endpoint health before allowing users to access the network and potentially spread malware. Should these trusted users have a problem, they can be routed to a remediation network to address the issue. Lastly, the solution should have a management, reporting and verification component to insure compliance and appropriate operation.