Mobile device Management mit NAC fweisel@forescout.com 2012 ForeScout Technologies, Page 1
Die NAC Lösung Although approaches such as server-based computing and virtualization will also be used to deal with consumerization, NAC provides the flexibility that enterprises need in a BYOD environment, while providing the controls that enable network and security managers to retain control over the network. Gartner, Strategic Road Map for Network Access Control, Lawrence Orans and John Pescatore,11 October 2011, ID number G00219087 2012 ForeScout Technologies, Page 2
Produktivitaetversus Sicherheit Mitarbeiter, Gaeste, Externe Smartphones, ios, etc W-Lan, via kabel, VPN Access Agility Security Datenverlust Zero-day attacks Sicherheitsstatus des Geraetes Compliance und Vorschriften Erfordert Echtzeit Sichtbarkeit Erfordert Echtzeit Kontrolle 2012 ForeScout Technologies, Page 3 2011 ForeScout
Limited Visibility Means Security Gaps Corporate Resources Non-Corporate BYOD Endpoints Network Devices Applications Antivirus out of date Firewall installed but turned off Encryption agent not installed Users ForeScout Comprehensive Visibility Protection Visible Possible No Protection Not Visible Possible 2012 ForeScout Technologies, Page 4
Full Device Information User Behavior User Information Applications OS Integrity Device Information Physical Layer Network Policy Violations Audited Responses Self-Remediation Success Username Authentication Status Group Membership Running Applications Installed Applications Registry Values OS Fingerprint Antivirus Update Status Patch Level IP Address/MAC Device Fingerprint Printer, Non-OS Device Switch, Port, VLAN VPN Status Geographic Location Trouble Ticket Requests Simultaneous Connections Email, Phone, Etc. Login History File Size, Version, Date Application Version External Vulnerabilities OS Processes, Services Open Services VoIP Phone Wireless Device/NAT Attached USB Drive Number of Devices on Port Hub, Router 802.1x 2012 ForeScout Technologies, Page 5 5
See Grant Fix Protect Grant access Register guests Block access Restrict access ForeScout CounterACT ( ( ( ( ( ( ( 2012 ForeScout Technologies, Page 6
Control Automation Advantages Control Costs (OpEx, CapEx) The financial institution selected ForeScout CounterACT [and] was able to save over $1,000,000 per year in endpoint support costs... The automation achieved via ForeScout CounterACT reduces help desk call volume, initiates fewer job tickets for software maintenance workflows, causes fewer image refreshes, and increases user productivity. Continuous Endpoint Compliance: An Ogren Group Special Report April 2011 Control Coverage (risk management) 2012 ForeScout Technologies, Page 7
See Grant Fix Protect Detect unexpected behavior Block insider attack Block worms Block intrusions ForeScout CounterACT 2012 ForeScout Technologies, Page 8
ForeScout Übergreifende Sicherheit Mobile Security Sichtbarkeit Sicherheits Status Konfiguration Network Access Control Gast Registrierung Zugriffs Beschränkung Block von nicht erlaubten Geräten Endpoint Compliance Finden und Beheben von Sicherheitslücken Richtlinien durchsetzen PC, Mac, Linux, ios, Android Threat Management Block von Einbruchsversuchen Block APTs Erkennung infizierter Systeme Agentless Knowledgebase ForeScout Automated Security Control Platform. Scalable Interoperable 2012 ForeScout Technologies, Page 9
ForeScout & the IT-GRC Framework Switches & Routers Endpoint Protection Endpoints Firewall & VPN Wireless IT Network Services Network Devices Smart Phones & Tablets 2012 ForeScout Technologies, Page 10
Deployment Centralized Architecture Out-of-Band Clientless Network-Integration Single Appliance Deploy at the Core ForeScout CounterACT 2012 ForeScout Technologies, Page 11
Deployment Distributed Architecture 2012 ForeScout Technologies, Page 12 12
Mehrstufige Mobile Security Lösung Rightsizing von Mobile Threat Management und Ausgaben Operational Management Provisioning Cost management Inventory Network Security Access control Block threats Network instability Device Security Password Remote wipe Configuration enforcement Detect rooted / jailbroken Sandbox / containerization Unified security management ForeScout CounterACT ForeScout CounterACT + ForeScout Mobile ForeScout CounterACT + ForeScout Mobile + MDM (3 rd party) MDM (3 rd party) User impact Transparent Lightweight Varies Varies Price $ $$ $$$* $$$$ 2012 ForeScout Technologies, Page 13 *Assumes that a portion of the mobile devices are enrolled in a 3 rd party MDM system and the rest are managed by ForeScout Mobile Security Module.
ForeScout Leadership Consistently ranked as a leader Magic Quadrant for Network Access Control, December 2011, Gartner Inc. Forrester Wave Network Access Control, Q2-2011, Forrester Research, Inc. Magic Quadrant for Network Access Control, December 2012, Gartner Inc. Analysis of the NAC Market, February 2012, Frost & Sullivan NAD5-74 2012 ForeScout Technologies, Page 14 63.4 % *This Magic Quadrant graphic was published by Gartner, Inc. as part of a larger research note and should be evaluated in the context of the entire report. The Gartner report is available upon request from ForeScout. Gartner does not endorse any vendor, product or service ]depicted in our research publications, and does not advise technology users to select only those vendors with the highest ratings. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. * Forrester Wave NAC Q2-20111The Forrester Wave is copyrighted by Forrester Research, Inc. Forrester and Forrester Wave are trademarks of Forrester Research, Inc. The Forrester Wave is a graphical representation of Forrester's call on a market and is plotted using a detailed spreadsheet with exposed scores, weightings, and comments. Forrester does not endorse any vendor, product, or service depicted in the Forrester Wave. Information is based on best available resources. Opinions reflect judgment at the time and are subject to change.
Reviews and Awards Top rank and highest score for Strategy and Current Offering John Kindervag, Forrester* highly rated by enterprise users for ease of deployment and flexible enforcement Lawrence Orans, Gartner* ForeScout customers do more with their NAC solutions and reap the benefits of their investment quickly relative to competing solutions. Jeff Wilson, Infonetics 2011 2012 ForeScout Technologies, Page 15 * Forrester Wave NAC Q2-20111The Forrester Wave is copyrighted by Forrester Research, Inc. Forrester and Forrester Wave are trademarks of Forrester Research, Inc. The Forrester Wave is a graphical representation of Forrester's call on a market and is plotted using a detailed spreadsheet with exposed scores, weightings, and comments. Forrester does not endorse any vendor, product, or service depicted in the Forrester Wave. Information is based on best available resources. Opinions reflect judgment at the time and are subject to change. ** Gartner, Magic Quadrant for Network Access Control, L.Orans and J. Pescatore, 2 July 2010
WebEx Mehr Information Danke Whitepapers Test 2012 ForeScout Technologies, Page 16 2011 ForeScout Technologies, Inc.
Awards Secure Computing Magazine Group Test CounterACT s Interface is intuitive and the reporting/dashboard features are slick... a robust NAC solution with plenty of features and a great price point. It is our Best Buy. - September 2011 CounterACT to be a multi-faceted, extremely powerful, exceptionally flexible and exquisitely configurable system being both integrated and agentless, it offers a significant bang for the buck awarded Editor s Choice. - August 2011 For its power, simplicity and revenue potential, the CRN Test Center recommends ForeScout s CounterACT 6.3.4 network access control system. - June 2011 Judged on the product s capability and application, ForeScout CounterACT surpassed 12 other vendors in this prestigious category. - April 2011 Best Overall Security Company of the Year. - Feb 2011 In terms of network visibility, CounterACT was certainly the most sophisticated product in this test. - June 2010 2012 ForeScout Technologies, Page 17