Skip to content

Solution

Access control audit readiness

An assessment is scheduled and access control is the part you are least sure about.

What is going on

The control objective is not "own a NAC product" — it is being able to demonstrate which devices are authorised, who decided, and that the decision is enforced. Most organisations can produce a purchase order and not much else.

What this is designed to achieve

A defensible access control posture and the evidence pack that goes with it, gap-analysed against the framework that actually applies to you.

It starts with

A gap analysis against your applicable framework, so remediation is prioritised by what the assessor will actually ask.

The phases it runs through

  1. Phase 1

    Discover

    What is actually on the network?

  2. Phase 2

    Design

    What should be allowed, and who decides?

  3. Phase 5

    Sustain

    Will this still be working in a year?

How the method works