{"id":2084,"date":"2009-04-22T02:28:35","date_gmt":"2009-04-22T09:28:35","guid":{"rendered":"https:\/\/svapm.org\/?p=2084"},"modified":"2019-08-07T14:31:46","modified_gmt":"2019-08-07T21:31:46","slug":"physical-security-controls","status":"publish","type":"post","link":"https:\/\/svapm.org\/?p=2084","title":{"rendered":"Physical Security Controls"},"content":{"rendered":"<figure id=\"attachment_2095\" aria-describedby=\"caption-attachment-2095\" style=\"width: 300px\" class=\"wp-caption alignright\"><a href=\"http:\/\/www.flickr.com\/photos\/anonymouscollective\/2291896028\/\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2095\" title=\"security1\" src=\"https:\/\/svapm.org\/wp-content\/uploads\/security1.jpg\" alt=\"Security via Flickr by Anonymous Account\" width=\"300\" height=\"451\" srcset=\"https:\/\/svapm.org\/wp-content\/uploads\/security1.jpg 300w, https:\/\/svapm.org\/wp-content\/uploads\/security1-199x300.jpg 199w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><figcaption id=\"caption-attachment-2095\" class=\"wp-caption-text\">Security via Flickr by Anonymous Account<\/figcaption><\/figure>\n<p>The average person doesn\u2019t immediately think of physical controls as information security measures.\u00a0 But clearly, limiting physical access is just as important as implementing technical and administrative controls.\u00a0 After all, if someone could walk out the front door with one of your servers\u2014blade servers are pretty small, for example, and could nearly fit into the armpit of an exceptionally large guy posing as a package delivery person\u2014in time the culprit would be able to break through your electronic defenses.\u00a0 So, secure the castle.\u00a0 Build fences.\u00a0 Lock doors.\u00a0 Install cameras.\u00a0 Hire guards.\u00a0 Require employees to carry and use badges.<\/p>\n<p>I think most of us \u201cget\u201d physical security.\u00a0 Still, a few basic (and a few not-so-basic) physical security controls worth discussing include:<\/p>\n<p>Room design.\u00a0 A typical office building has drop ceilings and raised floors.\u00a0 Great for wiring, heating and air conditioning, but bad for security.\u00a0 Anyone who has seen almost any spy or high-tech heist movie must surely be aware that ceilings frequently have enough space through which people can crawl.\u00a0 The moral of the story is that putting something really valuable behind a locked door will deter only someone who does not realize that he might be able to go over, under, or around the door.\u00a0 And if every dime-store novelist has figured it out, rest assured that the bad guys have as well.<\/p>\n<p>Cameras.\u00a0 Depending on governing law and the prevailing corporate culture, many companies have policies which prohibit the taking of pictures on the premises.\u00a0 In certain countries people have no expectation of privacy, and everyone pretty much assumes they are being watched at all times.\u00a0 In others, most notably the U.S., people have an expectation of personal privacy, and the issue is touchier.\u00a0 Some companies ban cameras altogether\u2026a great concept, though one which is not very practical in the face of modern cell phones.\u00a0 But why would a corporation\u2019s security team care about pictures taken inside of an office building?\u00a0 Well, one reason is that a seemingly innocuous photo snapped in a hallway could show the type and placement of security cameras, information that could be extremely valuable to a 007-type professional-class thief, or even a bumbling intruder with half a brain.<\/p>\n<p>Access cards.\u00a0 Many corporations now ask employees to swipe in and swipe out, not unlike the old white board version where people signaled their presence in the office by moving a peg or a magnet from one column to the next as they breezed through the doorway.\u00a0 Swiping in, clearly, allows the back-end systems to confirm that the card belongs to someone who was not fired yesterday.\u00a0 Swiping out allows the system to make note of who has left the building.\u00a0 Although theoretically that information could be used to determine who needs to be accounted for in the event of an evacuation, the main reason for swiping out is so logical access can be suspended.\u00a0 If I swipe out and leave the building, and ten minutes later my ID is trying to log into a system from inside the facility, rather than remotely, alarm bells should sound.<\/p>\n<p>Biometrics.\u00a0 Biometrics are the wave of the future for access control.\u00a0 There are various kinds of biometric technologies for which a given bodily or behavioral characteristic is recorded, digitized, and stored.\u00a0 They fall into two main categories \u2013 physiological and behavioral.\u00a0 Physiological factors include the face, fingerprints, hand, iris, and even DNA.\u00a0 Behavioral factors include keystroke speed, signatures and voice.\u00a0\u00a0 In reality, the entire hand, face, or whatever is not entered into the database.\u00a0 Only specific data points are recorded.\u00a0 Then, when a user needs access, he presents his hand, face, whatever to a reader, and the relevant data points are gathered and compared to the stored data.\u00a0 Close enough match?\u00a0 You\u2019re in!\u00a0 For users, otherwise known as people or human beings, acceptance usually hinges on how \u201cintrusive\u201d the technology feels.\u00a0 Most people see fingerprints as fairly innocuous.\u00a0 Retinal \/ iris scanners, which require you to put your face into a contraption, are less well received.\u00a0 While acceptance by users is key for adoption, even more critical for the organization is reliability.\u00a0 Face and voice recognition tend to have a lot of false rejections, that is denying access to someone who is authorized.\u00a0 Keystroke recording, on the other hand, has a higher rate of false acceptance.\u00a0 While false rejections are an irritating inconvenience, false acceptances undermine the integrity of the system.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I think most of us \u201cget\u201d physical security.  Still, a few basic (and a few not-so-basic) physical security controls worth discussing include&#8230;<\/p>\n","protected":false},"author":1483,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"give_campaign_id":0,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[1],"tags":[575,576,572,571,577,261,570],"class_list":["post-2084","post","type-post","status-publish","format-standard","hentry","category-miscellaneous","tag-access-cards","tag-biometrics","tag-infosec","tag-michael-seese","tag-room-design","tag-scrappy","tag-scrappy-information-security"],"aioseo_notices":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2084","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/users\/1483"}],"replies":[{"embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2084"}],"version-history":[{"count":1,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2084\/revisions"}],"predecessor-version":[{"id":14209,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2084\/revisions\/14209"}],"wp:attachment":[{"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2084"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2084"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2084"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}