Security gap scenario

October 2005 Integrated Solutions

Mr CFO is travelling abroad, therefore has not checked into his office via his access control card at the main turnstile in the New York City office. He has, however, checked into his office in Paris, France and will be working there for the next 10 days. The physical access control system in New York is a different system, completely independent from the one securing the office in France. Therefore, the guards monitoring the system in New York City are not even aware that Mr CFO is not in the building.

In the meantime, a trusted employee has been looking over Mr CFO's shoulder and has acquired his login credentials, which are simply username and password. Knowing he is out of the country for 10 days, and on a very different time schedule, she logs onto the network, during normal working hours, and accesses sensitive files, which she will later share with competitors.

Will an alarm be annunciated anywhere? No. Why?

There is no apparent violation in either the physical access system, nor the network access system, which are operating independently.

* The employee committing the crime is authorised to enter the building during US, EST working hours, so nothing will be annunciated in the physical access system, or even flagged as abnormal.

* The network security system sees Mr CFO logging on and accessing files that he is authorised to view during time periods that are otherwise normal for him. Therefore, nothing will be annunciated or flagged as a network security breach. Effective security management combining both physical and IT controls could result in organisationally and operationally coordinated security.

* If the physical access systems were compatible, the guards monitoring the facilities may have at least known that Mr CFO was entering the facility in France, not locally in New York.

* If the physical access system was communicating activity to the network access system, Mr CFO's credentials may authorise him local access, only where he appears to be physically located.

* If the physical access system was communicating to the network access system, it would annunciate an alarm if Mr CFO logged onto the network remotely or in another location than he appears to physically be located based on the last doors he physically accessed.

* If the physical security department had procedures in place to communicate abnormal events such as this, they would notify the network security department of a possible security breech.

* If the credentials required for Mr CFO to enter the facility in France were also required for him to log onto the corporate network, another person would not be able to utilise his credentials.

By Laurie Aaron, Tyco Safety Products, courtesy of Faulkner Information Services.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Advanced Perimeter Intrusion Detection Systems
XtraVision OPTEX Technews Publishing Modular Communications Perimeter Security, Alarms & Intruder Detection Integrated Solutions Products & Solutions
Making full use of fibre installations around the perimeter by adding Perimeter Intrusion Detection Systems means you can easily add another layer of security to existing surveillance and fencing systems.

Read more...
A critical component of perimeter security
Nemtek Electric Fencing Products Gallagher Technews Publishing Stafix Editor's Choice Perimeter Security, Alarms & Intruder Detection Integrated Solutions
Electric fences are standard in South Africa, but today, they also need to be able to integrate with other technologies and become part of a broader perimeter security solution.

Read more...
SMART Estate Security returns to KZN
Nemtek Electric Fencing Products Technews Publishing Axis Communications SA OneSpace Technologies Editor's Choice News & Events Integrated Solutions IoT & Automation
The second SMART Estate Security Conference of 2024 was held in May in KwaZulu-Natal at the Mount Edgecombe Estate Conference Centre, which is located on the Estate’s pristine golf course.

Read more...
Dynamic Dashboard enhances security and operational efficiency
Suprema neaMetrics Products & Solutions Integrated Solutions Residential Estate (Industry)
In today’s data-driven world, security systems are overwhelmed by an unprecedented volume of data, from video surveillance and access control logs to intrusion alerts and a variety of IoT sensor data.

Read more...
HELLO visitor access management
Products & Solutions Access Control & Identity Management Integrated Solutions Residential Estate (Industry)
HELLO is an on-premises visitor and contractor access management solution designed to be fully integrated and complementary with smart, on-trend technologies, securing estates and businesses alike.

Read more...
Using KPIs to measure smart city progress
Axis Communications SA Residential Estate (Industry) Integrated Solutions Security Services & Risk Management
United 4 Smart Sustainable Cities is a United Nations Initiative that encourages the use of information and communication technology (including security technology) to support a smooth transition to smart cities.

Read more...
Enhancing estate security, the five-layer approach
Fang Fences & Guards Residential Estate (Industry) Integrated Solutions Security Services & Risk Management
Residential estates are designed to provide a serene and secure living environment enclosed within gated communities, offering residents peace of mind and an elevated standard of living.

Read more...
Creating employment through entrepreneurship
Technews Publishing Editor's Choice Integrated Solutions Residential Estate (Industry)
Eduardo Takacs’s journey is a testament to bona fide entrepreneurial resilience, making him stand out in a country desperate for resilient businesses in the small and medium enterprise space that can create employment opportunities.

Read more...
MySecurityApp for SME security firms
Surveillance Integrated Solutions
Solution House Software has introduced MySecurityApp, a platform that expedites security operations management for startup and growing security companies by delivering a comprehensive and user-friendly mobile app designed to simplify setting up and growing security companies’ operations.

Read more...
MySecurityApp for SME security firms
Surveillance Integrated Solutions
Solution House Software has introduced MySecurityApp, a platform that expedites security operations management for startup and growing security companies by delivering a comprehensive and user-friendly mobile app designed to simplify setting up and growing security companies’ operations.

Read more...