
26
3 PROTECTING WINDOWS COMPUTERS REVIEWER’S GUIDE
SophosLabs also maintains a library of extensive library of global sensitive
data definitions (Content Control Lists) which covers personally identifiable
information (PII) such as credit card numbers, social security numbers, postal
addresses, or email addresses helping you to protect your sensitive data faster.
You can create your own lists specific to your organization such as customer
reference numbers or specific confidential document markers.
SOPHOS NAC
Assess and control your Windows endpoints
Computers attempting to connect to the network are assessed for compliance
by Sophos NAC against a defined security policy. This endpoint compliance
functionality allows you to ensure that all computers are properly protected by:
• Checking if anti-virus and other security applications are correctly configured
and up to date.
• Checking if Microsoft Windows operating system service packs are up to
date.
• Checking if Microsoft Windows and/or Microsoft Update is active.
• Includes separate policies that can be configured for managed, contractor
and guest computers.
Enforcement options to control network access
Sophos NAC uses agent-based enforcement for control of managed computers
and interoperates directly with Microsoft DHCP to prevent unmanaged/
unauthorized computers accessing the network. Endpoint assessment is
performed by:
• The Sophos NAC Compliance Quarantine Agent (resident on the client)
• The Sophos NAC Compliance Dissolvable Agent (downloadable Java
component)
The Sophos NAC Compliance Quarantine Agent, which is deployed from within
Sophos Enterprise Console, provides assessment and control of managed
computers, both prior to and during a network session, at an interval that can
be specified by you. This agent provides self-quarantine for non-compliant
computers.
The Sophos NAC Compliance Dissolvable Agent provides the same assessment
prior to network access for LAN-based unmanaged computers. It is designed
for users who do not or cannot have an agent installed on the endpoint, yet
who must still access specific network resources, such as contractors or guests.
Sophos NAC provides integration with Microsoft DHCP to protect the network
from LAN-connected computers by using an enterprise’s existing Microsoft
DHCP infrastructure, allowing Sophos NAC to quarantine non-compliant and
unauthorized computers.
Komentarze do niniejszej Instrukcji