9 min read

Network Access Control (NAC) Assessment

How Network Access Control solutions enforce device and user authentication at the network edge, and how auditors evaluate their effectiveness.

CISAPractice|

Network Access Control (NAC) refers to technologies and policies that govern which devices and users are permitted to connect to an organization's network, and under what conditions. NAC acts as a gatekeeper at the network edge, enforcing authentication and device posture requirements before granting network access, and represents an important preventive control that CISA candidates should understand within the broader network security domain.

Core NAC Functions

A NAC solution typically performs several functions: authenticating the device and/or user attempting to connect (commonly through 802.1X port-based authentication), assessing the device's security posture (checking for up-to-date antivirus signatures, current patch levels, and required endpoint agents), and enforcing a policy decision based on both authentication and posture results, ranging from full network access, to restricted access (such as placement into a quarantine or guest VLAN), to outright connection denial.

NAC Deployment Models

Pre-Admission vs. Post-Admission Control

Pre-admission NAC evaluates a device before granting any network access, preventing non-compliant devices from connecting at all. Post-admission NAC allows initial connection but continues to monitor device behavior and posture, capable of dynamically restricting or terminating access if a device's compliance status changes or anomalous behavior is detected after the fact.

Agent-Based vs. Agentless

Agent-based NAC requires a software client installed on endpoints to report detailed posture information, providing rich visibility but requiring deployment and maintenance overhead. Agentless NAC relies on network-based scanning and fingerprinting to assess devices without requiring installed software, which is particularly valuable for IoT and BYOD devices where installing an agent may not be feasible.

Common NAC Use Cases

  • Enforcing that only corporate-managed, compliant devices can access sensitive internal network segments
  • Automatically routing guest or unrecognized devices to an isolated guest network with internet-only access
  • Segmenting IoT and operational technology devices into dedicated VLANs isolated from corporate IT systems
  • Detecting and quarantining devices that fall out of compliance, such as a laptop with disabled endpoint protection or overdue patches
  • Preventing unauthorized devices plugged into open network ports (a classic physical security bypass) from gaining network access

Auditing NAC Effectiveness

Policy Configuration Review

Auditors should review the specific NAC policies configured to confirm they align with the organization's intended network segmentation and risk tolerance, verifying that posture requirements (patch levels, antivirus status) are set at genuinely meaningful thresholds rather than trivially easy to satisfy.

Physical Testing

A valuable, practical audit test involves physically connecting an unauthorized or non-compliant test device to a network port in a controlled manner (with appropriate authorization and safeguards) to confirm the NAC solution actually detects and appropriately restricts the connection, rather than relying solely on configuration review or vendor claims.

Coverage Assessment

Auditors should verify NAC is deployed comprehensively across all network access points, including wired ports, wireless access points, and VPN connections, since gaps in coverage (such as an unmonitored wired port in a conference room) can completely undermine the control's value regardless of how well it is configured elsewhere.

Exception Handling

Auditors should review the process for granting exceptions to NAC policy (such as for legacy devices that cannot support modern authentication protocols), confirming that exceptions are formally approved, time-limited, and subject to compensating controls such as network segmentation isolating the excepted device.

Exam Relevance

CISA candidates should understand NAC as a preventive network security control enforcing both authentication and device posture at the point of network connection, and should recognize that effective NAC auditing requires both configuration review and practical testing to confirm the control functions as designed across the full scope of network access points.

Related Tags

Technical Deep DiveNetwork SecurityAccess Control

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free