NAC and Patching

| | Comments (0) | TrackBacks (0)

When I was looking at different NAC solutions, I remember one vendor being aghast at my plans for NAC, "NAC isn't patch management" he sputtered. While I agree that no one is looking to supplant their SMS/patchlink whatever with NAC, making sure every computer meets a baseline requirement is an important goal.

We continued looking at vendors and eventually went with Forescout's Counteract. As I've been implementing it, one of the things that struck me was that Microsoft SMS 2003 is even worse that I thought. We used Forescout to run a check for June 2008 Microsoft patches. What I found was 5% of the systems didn't have those patches because their SMS was hosed.

Using NAC to gather vulnerability information has a lot of advantages. Unlike vulnerability scans, in many cases I was not restricted by personal firewalls. The Forescout uses a connector so it can run scans on the local machine with admin credentials. A vulnerability scan runs once per week and not every system may be online. With Forescout I have a more accurate view of the patching in the enterprise because the scan can be set to run as the client comes online.

Forescout NAC has given me insight to the network that I didn't have before. Unfortunately its putting in a 100 watt bulb after you've been using 40 watts. With the sudden brightness, you see the cobwebs and dirt that you hadn't noticed before.

The next steps are to fix the SMS on the 5% systems that are broken. Plans are being drawn up to upgrade to SCCM which uses WSUS for updates. I'm hoping that version will be more robust.


Categories

0 TrackBacks

Listed below are links to blogs that reference this entry: NAC and Patching.

TrackBack URL for this entry: http://www.infosecblog.org/mt-tb20071121.pl/758

Leave a comment

Powered by Ajax Comments

About this Entry

This page contains a single entry by Roger published on July 15, 2008 7:34 PM.

Zlib Compression Denial of Service was the previous entry in this blog.

Firefox 2.0.16 and 3.0.1 released is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.2-en