Security gap scenario

October 2005 Integrated Solutions

Mr CFO is travelling abroad, therefore has not checked into his office via his access control card at the main turnstile in the New York City office. He has, however, checked into his office in Paris, France and will be working there for the next 10 days. The physical access control system in New York is a different system, completely independent from the one securing the office in France. Therefore, the guards monitoring the system in New York City are not even aware that Mr CFO is not in the building.

In the meantime, a trusted employee has been looking over Mr CFO's shoulder and has acquired his login credentials, which are simply username and password. Knowing he is out of the country for 10 days, and on a very different time schedule, she logs onto the network, during normal working hours, and accesses sensitive files, which she will later share with competitors.

Will an alarm be annunciated anywhere? No. Why?

There is no apparent violation in either the physical access system, nor the network access system, which are operating independently.

* The employee committing the crime is authorised to enter the building during US, EST working hours, so nothing will be annunciated in the physical access system, or even flagged as abnormal.

* The network security system sees Mr CFO logging on and accessing files that he is authorised to view during time periods that are otherwise normal for him. Therefore, nothing will be annunciated or flagged as a network security breach. Effective security management combining both physical and IT controls could result in organisationally and operationally coordinated security.

* If the physical access systems were compatible, the guards monitoring the facilities may have at least known that Mr CFO was entering the facility in France, not locally in New York.

* If the physical access system was communicating activity to the network access system, Mr CFO's credentials may authorise him local access, only where he appears to be physically located.

* If the physical access system was communicating to the network access system, it would annunciate an alarm if Mr CFO logged onto the network remotely or in another location than he appears to physically be located based on the last doors he physically accessed.

* If the physical security department had procedures in place to communicate abnormal events such as this, they would notify the network security department of a possible security breech.

* If the credentials required for Mr CFO to enter the facility in France were also required for him to log onto the corporate network, another person would not be able to utilise his credentials.

By Laurie Aaron, Tyco Safety Products, courtesy of Faulkner Information Services.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Security industry embraces mobile credentials, biometrics and AI
AI & Data Analytics Access Control & Identity Management Integrated Solutions
As organisations navigate an increasingly complex threat landscape, security leaders are making strategic shifts toward unified platforms and emerging technologies, according to the newly released 2025 State of Security and Identity Report from HID.

Read more...
Insurance provider uses Net2 For access management
Paxton Access Control & Identity Management Integrated Solutions Healthcare (Industry)
BestMed selected Paxton Net2 for its access control requirements because of its simplicity of installation and ease of navigation for end users, as well as the 5-year warranty.

Read more...
The power of knowing your client
Ideco Biometrics Access Control & Identity Management Integrated Solutions
One of the most effective ways to combat the threat of fraud, identity theft, and financial crime threats is through a robust Know Your Client (KYC) process, which safeguards both businesses and clients.

Read more...
Managing identities for 20 years
Ideco Biometrics Technews Publishing SMART Security Solutions Access Control & Identity Management Integrated Solutions IoT & Automation
Many companies are now more aware of the risks associated with unauthorised access to locations and sensitive data and are investing in advanced identity authentication technologies to mitigate these threats.

Read more...
Cost-effective and reliable remote connectivity
Agriculture (Industry) Integrated Solutions Infrastructure
Companies that operate in hard-to-connect areas now have access to reliable connectivity due to a collaboration between MTN South Africa, Vox and Tarana technology.

Read more...
Advanced Perimeter Intrusion Detection Systems
XtraVision OPTEX Technews Publishing Modular Communications Perimeter Security, Alarms & Intruder Detection Integrated Solutions Products & Solutions
Making full use of fibre installations around the perimeter by adding Perimeter Intrusion Detection Systems means you can easily add another layer of security to existing surveillance and fencing systems.

Read more...
A critical component of perimeter security
Nemtek Electric Fencing Products Gallagher Technews Publishing Stafix Editor's Choice Perimeter Security, Alarms & Intruder Detection Integrated Solutions
Electric fences are standard in South Africa, but today, they also need to be able to integrate with other technologies and become part of a broader perimeter security solution.

Read more...
Using advanced surveillance technology as a smart city enabler
Duxbury Networking Integrated Solutions Surveillance
Smart cities are increasingly becoming a focus area for African governments and companies. However, the transition to these environments does not come without challenges, especially when it comes to security and resource management.

Read more...
SMART Estate Security returns to KZN
Nemtek Electric Fencing Products Technews Publishing Axis Communications SA OneSpace Technologies Editor's Choice News & Events Integrated Solutions IoT & Automation
The second SMART Estate Security Conference of 2024 was held in May in KwaZulu-Natal at the Mount Edgecombe Estate Conference Centre, which is located on the Estate’s pristine golf course.

Read more...
Dynamic Dashboard enhances security and operational efficiency
Suprema neaMetrics Products & Solutions Integrated Solutions Residential Estate (Industry)
In today’s data-driven world, security systems are overwhelmed by an unprecedented volume of data, from video surveillance and access control logs to intrusion alerts and a variety of IoT sensor data.

Read more...