A system of the invention comprises first and second computers. The first
computer retrieves and incorporates its security state data in a message
requesting a network connection with the second computer. The second
computer receives the message and determines whether its security policy
data permits connection with the first computer given the security state
of the first computer as indicated by its security state data. The
security state data can comprise data indicating whether an anti-virus
application, firewall application, or operating system are running on the
first computer, and are up-to-date. If so, the second computer permits
the network connection to proceed. If not, then the second computer
either drops the connection request or terminates the connection request
by transmitting a disconnection message to the first computer. The
invention also comprises related apparatuses, methods, and
computer-readable media.