Cybersecurity GRC 13 items
Network Access Control (NAC) Deployment Review
Reviews a network access control deployment covering authentication, device posture, guest and IoT handling, dynamic segmentation, and enforcement.
IEEE 802.1XNIST 800-53CIS
Free PDF · enter your email to download.
Authentication
- Is 802.1X authentication enforced on wired and wireless access ports? *
- Are certificate-based (EAP-TLS) methods used for managed devices where feasible?
- Is MAC Authentication Bypass (MAB) restricted and inventoried for non-802.1X devices? *
- Is the RADIUS/policy server highly available and integrated with the identity provider? *
Device Posture
- Is endpoint posture (patch level, EDR presence, disk encryption) assessed before granting access? *
- Are non-compliant devices quarantined to a remediation VLAN? *
- Is device profiling used to classify unmanaged and IoT devices? *
Guest & IoT
- Are guest devices isolated to a segregated network with captive portal onboarding? *
- Are IoT/OT devices placed in dedicated segments with least-privilege access policies? *
- Are unknown or unauthorized devices denied or restricted by default? *
Enforcement & Monitoring
- Is dynamic VLAN or SGT/ACL assignment used to enforce role-based segmentation? *
- Are NAC authentication and enforcement events logged to a SIEM? *
- Is there a documented fallback/monitor-mode process to avoid production outages during rollout?
Download the full Network Access Control (NAC) Deployment Review checklist
Get it as a clean, printable PDF — free.
