Converging facility and information security
Convergence in this case refers to a coming together of physical and information security practices within organizations. This “coming together” is being driven by two trends: increasingly sophisticated network-based management of facility infrastructure and the increasing importance and sophistication of physical attacks against IT infrastructure. This merger is a difficult one, as facility and information security come from different cultures, and corporate turf wars make either side wary of reliquisinhg their traditional control.
Facility infrastructure requires measures to protect physical assets, through guard services, intrusion alarms, CCTV surveillance, and facility access control systems. Included among the physical assets are information technology resources such as servers, network devices, and communication lines. Denying potential attackers physical access to network equipment is essential to securing that equipment.
Facility access systems themselves are increasingly managed using shared information technology resources. Servers using off-the-shelf operating systems, network connections relying on IP and shared with other data and management consoles based on common Web browsers are becoming common. A compromise of network security could result in ineffective or compromised facility security systems.
Information security and facility security share common concerns. Both protect valuable organizational assets. An attack against one can compromise resources that are the responsibility of the other. A breakdown of facility security can compromise information systems, and an attack against information systems can harm facility security.
Information and facility security convergence implies formal coordination between facility security operations and information security. In some cases, information and facility security functions may be merged and managed under a single executive. More commonly, these functions continue to report to separate executives, establishing formal and informal coordination on matters of common concern.
Some of the benefits of coordinating facility and information security include:
Areas of common concern include investigations, hiring and termination processes (or “user provisioning”), business continuity, and industrial/facility control systems. The user provisioning process is of particular interest, as it opens up use of a single identifier for both facility and system access, relying on a common directory backend for authentication and authorization.
More information on facility/information security convergence may be found at:
http://www.fcw.com/article84751-12-12-04-Print
http://www.csoonline.com/fundamentals/abc_convergence.html
http://www.varbusiness.com/showArticle.jhtml?articleID=51200143
http://www.computerworld.com/securitytopics/security/story/0,10801,108571p2,00.html
0 Comments:
Post a Comment
<< Home