Network Security | News

ForeScout Developing Mobile Security Connectors for its NAC

ForeScout Technologies, a security products company, will shortly release a set of plug-ins that help security administrators manage Android and Apple mobile devices and coordinate with mobile device management systems through its network access control (NAC) appliance. ForeScout Mobile modules work with ForeScout CounterACT, the company's NAC, to identify mobile devices; force users to register; and automatically allow, deny, or restrict access to network resources and wireless access points based on pre-configured policies out of the box or set by the security administrator. The individual mobile devices don't require the installation of agents to function with the NAC.

The announcement comes as organizations are putting increased attention on the management of mobile devices, including mobile security. According to a recent survey done by Boston Research Group of 365 North American IT security professionals in companies with 1000 employees or more, two out of three respondents are concerned about mobile security risks associated with mobile devices gaining access to network resources. The top concerns are data loss (26 percent), malware (23 percent), unauthorized users and devices (14 percent), and intrusions (13 percent). The study was sponsored by ForeScout.

Seventy eight percent of respondents said that they consider network access control an essential feature for mobile security, as a means to enforce security policies based on identity, device, configuration, security posture, and network activity. And almost all want unified security policy management for both mobile devices and PCs.

"IT professionals see many of the same security risks in mobile devices such as smartphones that have long been a concern for laptops and notebook computers," said Paul McClanahan, research analyst at Boston Research. "Device mobility, wireless access, personal applications, and the high risk of lost or stolen handhelds create a need for added defenses against data loss, unauthorized access, and malware."

Those are the concerns addressed by the new modules the company will be releasing. The modules for Android and iOS are being beta tested and are expected to be available in April.

The iOS module, besides blocking or limiting network access, includes additional capabilities to:

  • Remotely wipe and lock;
  • Enforce password policy;
  • Require apps such as anti-virus or virtualization;
  • Remove or disable native apps such as the camera; and
  • Enforce specific Wi-Fi access

The Android module works with Android 2.1 or greater.

The ForeScout Mobile Device Management Module brings together NAC and mobile device management functions to enable the administrator to handle both PC and mobile device security work from one console. That includes monitoring and reporting on policy adherence, enforcing employee and guest compliance, and remediating devices across the major mobile platforms, including iOS, Blackberry, Android, and Windows. The MDM Module will be available in June as an add-on module for CounterACT. The licensing structure is based on the number of mobile devices being managed. Pricing starts at $2,800 for 100 devices.

About the Author

Dian Schaffhauser is a writer who covers technology and business for a number of publications. Contact her at dian@dischaffhauser.com.

Comments

Wed, Feb 29, 2012 Adam

It's possible to address security concerns and still implement BYOD. What’s needed is to separate the Enterprise apps and data from the personal devices. This can be achieved with a solution like Ericom's AccessNow, a pure HTML5 RDP client that enables remote users to securely connect from various devices (including iPads, iPhones, Android devices and Chromebooks) to any RDP host, including Terminal Server (RDS Session Host), physical desktops or VDI virtual desktops – and run their applications and desktops in a browser. This keeps the organization's applications and data separate from the employee's personal device. All that’s needed is a HTML5 browser. No plug-ins or anything else required on the user device. AccessNow also provides an optional Secure Gateway component enabling external users to securely connect to internal resources using AccessNow, without requiring a VPN. For more info, and to download a demo, visit: http://www.ericom.com/html5_rdp_client.asp?URL_ID=708 Note: I work for Ericom

Add your Comment

Your Name:(optional)
Your Email:(optional)
Your Location:(optional)
Comment:
Please type the letters/numbers you see above

White Papers:

  • Dallas County School District Overcomes Coverage Gaps with MOTOTRBO Digital Radios PDF screen shot

    Dallas County School District needed to quickly resolve their radio coverage gaps throughout the county for more efficient transportation communication and to ensure student safety. Download this whitepaper to see how this district has found their solution with improved coverage area, clear audio and private communications, in addition to improved efficiency and student safety. Read more...