Technology Industry
Industry: Email Alert RSS FeedDeploying Identity-Based Access Control
Enterprise Networks & Servers, Jun 2004 by Welcher, Peter J
The policy issue arises with colleges because of hesitancy, either on cost or support. Both can be complex issues.
Re cost, it costs money to upgrade Windows, or to buy the Funk or Meetinghouse driver. I've got two kids in college, I understand how sensitive parents are about cost. Colleges are very hesitant to dictate more cost for their students. Part of that goes with being an open environment. Part of it may also relate to staying competitive.
Most RecentTechnology Articles
Operating systems upgrades may not be feasible, since they may require the cost of a new PC. That's a show-stopper for many families. Concerning purchasing drivers for older Windows variants, one could argue that $40 per student is cheap, compared to the support costs of worm containment. That's where policy becomes a problem. Some colleges feel they cannot afford to support the wide variety of desktops or the sheer number of PCs their students have. And installing drivers or requiring installation of drivers means you own any support problems the student subsequently encounters. So do you provide "legacy support?" Is a component of it lesser connectivity as an incentive for students to opt for the buy-and-install-drivers solution?
One counter-argument is that students who get virii do impose very real costs on the college. If they get a worm that creates traffic, it may adversely affect other users or even knock out the network.
Colleges often try to provide anti-viral software to their students. Who then ignore it, don't install it, turn it off, etc. The necessary teeth might then be access control (NAC? Web-based?), or it might be a hefty fine if your PC gets infected and starts trashing the network. I personally think stringent standards up front ("You must have one of the following anti-viral products installed") with fee for non-compliance may be where we all end up. But even there, how does one induce the unwilling to periodically update their virus signatures and refrain from turning the protection off? That's where NAC will be of intense interest to colleges.
This is also why 802.1x arises in college environments right now. Student PCs are a very scary unknown right now, not under any anti-viral control. So it is highly desirable to identify student machines and isolate them (quarantine them?) in student VLANs. Then run traffic from those VLANs through firewalls or IDSes. That at least addresses damage containment now.
Having a focal IDS allows identification and treatment of infected PCs. Down the road, NAC may provide more enforcement without major labor burden. At that point, maybe student PCs become trusted again, and the policy split becomes "NAC-approved" versus "guest and non-NAC-approved PCs."
To sum that up, what's messy with clients right now is figuring out what is technically feasible, and what the policy ought to be. The interaction with culture and expectations of the surrounding environment make this particularly sensitive for colleges.
In a few years, most people will be running OS variants that support 802.1x. No doubt we'll all have some other hot issue then. In the meantime, we do have the challenge of transition and "legacy support." Either users have to have OS upgraded, have to have supplicants installed, or there has to be some way to support legacy non-802.1x devices. The latter is another potential article. I 've got two techniques that you may find useful, ones that work right now. Which to use depends on your policy and needs.
CXO UnpluggedSmart Business interviews on BNET
Brought to you by CBS MoneyWatch.com
- Best- and Worst-Paid College Degrees
- 6 Things You Should Never Do on Twitter or Facebook
- How Much Sleep Do You Really Need?
- 6 Big Myths about Gas Mileage
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Technology Articles
Most Recent Technology Publications
Most Popular Technology Articles
- BizRate to monitor in-store customer satisfaction for Office Depot stores - Market Intelligence
- Speed control of separately excited DC motor
- Building cost comparison between conventional and formwork system: a case study of four-storey school buildings in Malaysia
- Political stability and economic growth in Asia
- Failed businesses in Japan: a study of how different companies have failed, and tips on how to succeed, in the Japanese market



