Skip to main content

Deployment Best Practices Series - Operations Acceptance of the Solution

Background:

Operations Acceptance of NACA is very important for a successful deployment. If Staff does not accept the solution than it will not be utilized to its capabilities or be maintained. This post is all about educating staff in order to ensure a successful deployment.

Introducing NACA to the Operations Staff:


NACA has to become an integral part of network and security operations in order to have a successful deployment. The following are some of the topics that Network Operations must be informed about:
  • Clean Access Servers (CASs) act as an extension to the routers and switches in the network
    • This causes network operations the need to understand how the CASs reside in the data path of users
  • In an Out-of-Band (OOB) Deployment, netops has to understand the integration between the Clean Access Manager (CAM) and all access switches
    • This requires the staff to have knowledge about SNMP Servers & SNMP Traps
Security Operations have many topics that they must know about to ensure acceptance of the deployment, some of those include:
  • How to enforce security policy with NACA
  • How to Review logs and report on users found non compliant
. . In order for the operation staff to understand these topics, they must have training and experience with NACA and the concepts. It is your job as a deployment engineer to ensure that these topics are covered and operations can hit the ground running with NACA.

Introducing NACA to the Help Desk Staff:

Help Desk is the nerve center of a NACA deployment. Ensuring that the HD staff can help users when issues happen is imperative to making them successful. Keys to empowering your help desk staff are:

  • Train them about common issues
  • Ensure they have proper access and knowledge of how to access the information needed to troubleshoot or help users
  • Have a documented escalation path (e.g. help-desk - operations -engineering - Cisco TAC)

Summary:

Operations & Help Desk Staff are sometime forgotten about, but their knowledge and support of the NACA deployment is critical to a successful deployment.

Comments

Popular posts from this blog

Cisco Zero Trust Architecture

 As a follow up to the previous post around Zero Trust Architecture , Cisco has been delivering zero trust architectures for customers for many years. With the platform approach provided by Cisco Zero Trust organizations gain better visibility across users, devices, containers, networks, and applications, verifying their security states with every access request. Adopting this model provides a balance between security and usability. Security teams can make it harder for attackers to collect what they need (user credentials, network access, and the ability to move laterally), and users can get a consistent and more productive security experience, regardless of where they’re located, what endpoints they’re using, or whether their applications are on-premises or in the cloud. Cisco Zero Trust provides a comprehensive approach to securing all access across applications and environment, from any user, device and location. It protects the workforce , workloads and workplac...

Intrusion Prevention Best Practice - IPS Placement

Background In today's organizations, attacks come from everywhere. As cliche as it sounds, networks are borderless and because of this organizations face more sophisticated threats. As networks evolve, many organizations struggle to have intrusion prevention or other security architecture evolve at the same pace. Visibility is everything: you must be able to detect and respond to threats before they cause significant damage. The following entry is all about how to gain visibility at the different areas of the network. IPS Overview Wikipedia defines Intusion Prevention Systems as a "network security appliance that monitor network and/or system activities for malicious activity. The main functions of intrusion prevention systems are to identify malicious activity, log information about said activity, attempt to block/stop activity, and report activity." By deploying IPS, organizations are able to identify, classify, and stop malicious traffic, including worms, spyware ...

Cisco Releases Idenity Services Engine (AKA ISE)

Introduction After years of innovation around Network Access Control, Cisco has released its next generation NAC solution: Identity Services Engine. ISE is combines existing loosely coupled devices AAA, profiling, posture and guest management - in single, scalability appliance. As part of the Cisco TrustSec solution and Cisco’s SecureX architecture for Borderless Networks, the Cisco Identity Service Engine provides a centralized policy engine for business relevant policy definition and enforcement. This policy work horse enables centralized, coordinated policy creation and consistent policy enforcement across the entire corporate infrastructure, from head office to branch office. ISE Features & Benefits Visibility: Single Platform & Pane of Glass - Let IT see who and what is on the network for advanced discovery and troubleshooting Dynamically collects & consolidates endpoint information to make adaptive policy decisions based on ‘context’ Integrates functions previously d...