Skip Links

Network World

  • Social Web 
  • Email 
  • Close

How do you measure the volume and cost of things that didn't happen?

NAC is for solving problems not for making profit
Security: Network Access Control Alert By Tim Greene , Network World , 05/29/2008
Tim Greene
Sign up for this newsletter now!

Senior Editor Tim Greene clarifies issues surrounding the evolving NAC security architecture.

It's hard to prove that NAC can produce an ROI. It's not alone among security technologies that have trouble quantifying their worth because they stop bad things from happening. How do you measure the volume and cost of things that didn't happen?

The answer is you can’t, but there are a host of soft costs that may persuade the corporate bean counters to spring for NAC if it is otherwise warranted.

NAC can reduce downtime because fewer infected machines wreak havoc on the network, and the ability to contain outbreaks reduces the cleanup time for those attacks that manage to get through.

NAC can claim a variety of administrative savings. With NAC in place, guests can log themselves in to limited areas of the network without an administrator having to set up individual accounts. Administrative time is freed up by automating endpoint checks to see that the machines have acceptable security configurations.

With some NAC products, machines found lacking can be remediated automatically, again reducing the amount of assistance that administrators and help desk workers have to deliver.

Some NAC vendors whose products can be deployed as an overlay to existing network gear claim cost-avoidance. If NAC can embrace some existing network equipment as part of the NAC deployment, then the customer is getting added utility out of an existing investment as well as avoiding the cost of adding that NAC element.

From an accounting standpoint, all these merits are pretty squishy. The bottom line: stick to the argument that you need NAC to solve specific problems, not that NAC can be a profit center.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comments (2)
Login
Forgot your account info?

NAC in generalBy shorejsi on June 12, 2008, 7:47 pm Part of the slow uptake of NAC can be attributed to the fact that it is often a solution in search of a problem. The 'Health Checks' generally rely on your installed...

Reply | Read entire comment

Hard Savings of NACBy Anonymous on June 12, 2008, 5:38 pmAlthough the ROI is difficult to calculate for NAC in the general case, some hard savings can be assessed in specific cases. For example, a customer of ours reduced...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.

Whitepapers

Advancing the Economics of Networking

Aging network systems and old habits have dictated how businesses spend their IT budgets. As a...

Implementing HA at the Enterprise Data Center Edge to Connect to a Large Number of Branch Offices

This paper reviews the problem of creating a network where the dynamic availability of services is...

Enterprise Data Center Network Reference Architecture

Using a High Performance Network Backbone to Meet the Requirements of the Modern Enterprise Data...

Webcasts

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Stay out of the headlines: Detecting and preventing network intrusions

How do YOU stay out of the headlines? There is no denying that risk exists in our computer-driven...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

IP address management in 2008 - six things to know

Read this Network World Special Brief to learn how Enterprise IT managers must update their...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...