nac -a bandaid for your network v07.21.11.txt
This is just a blog storming session about why I feel NAC is over-rated.. It may be the best marketing invention in a while to give vendors the opportunity to sell you a security solution, but it clearly isn't the best use of technical minds to come up with an effective way of securely managing diverse networks. NAC - Posture Assessment If you are responsible for keeping the corporate workstations up to date, then you are just proving to yourself that your method is ineffective if you perform posture assessment and fail the workstation. Why not concentrate on way to deliver updates and patches to a workstation while it is not directly connected to your corporate network? - Windows Update can be configured to access an internet site accessible: (ie: windowsupdate.corporate.com) that works internally and externally. - SMS and GPO updates can't easily be applied unless you have a VPN connection back to the corporate network.. seems like a good place for MS to work on ISA