Solution
Access control audit readiness
An assessment is scheduled and access control is the part you are least sure about.
What is going on
The control objective is not "own a NAC product" — it is being able to demonstrate which devices are authorised, who decided, and that the decision is enforced. Most organisations can produce a purchase order and not much else.
What this is designed to achieve
A defensible access control posture and the evidence pack that goes with it, gap-analysed against the framework that actually applies to you.
It starts with
A gap analysis against your applicable framework, so remediation is prioritised by what the assessor will actually ask.
The phases it runs through
- Phase 1
Discover
What is actually on the network?
- Phase 2
Design
What should be allowed, and who decides?
- Phase 5
Sustain
Will this still be working in a year?