Designing Access Controls

Choose Endpoint Integrity Testing Methods

Example. After totaling all of the methods that seem desirable according to one factor or another (see Table 3-54),the PCU network administrators decide that the NAC EI agent and the ActiveX agent are the most useful testing methods in the public zones. They will install the agent on computers in computer labs, and they will train support staff in guiding guests through automatically installing the agent.

The NAC EI agent also suits the private and remote zones. The network administrators will publish the NAC EI agent in the directory to deploy it to all endpoints in the private zone. Endpoints in the private zones are members of the domain, so agentless testing is a viable backup option.

Table 3-54. Preliminary Decisions for Testing Method

Factor

Public Wired

Private Wired

Public Wireless

Private Wireless

Remote

Administrative control

ActiveX

Agentless

ActiveX

NAC EI agent

ActiveX

 

NAC EI agent

NAC EI agent

NAC EI agent

ActiveX

NAC EI agent

 

 

 

 

 

 

Post-connect testing

NAC EI agent

NAC EI agent

NAC EI agent

NAC EI agent

NAC EI agent

 

ActiveX

Agentless

ActiveX

Agentless

ActiveX

 

 

 

 

 

 

User sophistication

NAC EI agent

NAC EI agent

NAC EI agent

NAC EI agent

NAC EI agent

 

ActiveX

Agentless

ActiveX

Agentless

ActiveX

 

 

ActiveX

 

ActiveX

 

 

 

 

 

 

 

Administrative workload

ActiveX

ActiveX

ActiveX

ActiveX

ActiveX

 

NAC EI agent

NAC EI agent

NAC EI agent

NAC EI agent

NAC EI agent

 

 

Agentless

 

Agentless

 

 

 

 

 

 

 

Network overhead

NAC EI agent

NAC EI agent

NAC EI agent

NAC EI agent

NAC EI agent

 

ActiveX

ActiveX

ActiveX

ActiveX

ActiveX

 

 

 

 

 

 

Totals

NAC EI agent: 5

NAC EI agent: 5

NAC EI agent: 5

NAC EI agent: 5

NAC EI agent: 5

 

ActiveX: 5

ActiveX: 3

ActiveX: 5

ActiveX: 4

ActiveX: 5

 

 

Agentless: 4

 

Agentless: 3

 

 

 

 

 

 

 

Selections

NAC EI agent

NAC EI agent

NAC EI agent

NAC EI agent

NAC EI agent

 

ActiveX

Agentless

ActiveX

Agentless

ActiveX

 

 

 

 

 

 

3-77