Abstract
With the world around us rapidly changing and adapting to modern technologies to simplify living, Physical Security is one strange topic that if often overlooked by majority of us. Commonly used in all walks of life – whether it be entering apartment homes, office buildings, or even grocery and store shopping – Physical Security plays a pivotal role in not only ensuring our safety and the safety of a company’s assets and its employees. With the threat of breaches always looming over us, it is now more important than ever to have mechanisms in place that would prevent any potential attacker from even making an attempt to trespass. The paper here presents various aspects related to deterring physical threats and various deterrence methods employed from known attacks. It also throws some light on the policies and control mechanisms employed by organizations to ensure they
meet the company standards and compliance.
Introduction
Background
Break-ins are a direct result of the lapses and vulnerabilities present in the security systems. Physical Security provides the means and frameworks for implementations of various protocols, methods, and use of proper mechanisms, employed by organizations and civil bodies to ensure that only company’s assets and personnel are protected from harm or damage, but the site is inaccessible to unauthorized people.
Physical security involves multiple layers of security each having its own objective to fulfil. While the primary goal remains the same, these objectives are broadly classified under five main categories viz. Deter, Detect, Deny, Delay, and Defend. Aptly suggestive by their names, each of these objectives aim to protect persons and prevent harm from any acts of espionage, theft or terrorist attacks.
Research Goal
The paper lays out the importance of one of the objectives mentioned above – deter. The goal is to present the reader, the value of this objective and its role in Physical Security. Deterrence methods primarily focus on discouraging potential intruders through warning signs, perimeter markings and related mechanisms by convincing them that an attack is unlikely, owing to presence of strong defense systems in place. The paper walks through some of the threats associated for any given building complex, various deterrence methods & mechanisms employed, policies & guidelines for implementation of these procedures, cost & budgetary concerns, business continuity plans, and risk mitigation, and overall issues relating implementations of Physical Security in various industries.
Associated Threats
Even before one starts with deterring threats, it is crucial to first identify the threats that pose serious dangers to life and property. A partial knowledge can trigger incidents that would be hard to contain and might be often fatal in some cases. Given that outdoor perimeter security is often overlooked in most of the places – owing to a casual human tendency to avoid confrontation and concerns over costs associated with employing and maintaining personnel; identification is therefore crucial to line up the threats associated to any facility, be it civil, business, or industrial.
With building complexes varying by their types of use demand different levels and kinds of security, it is essential to understand the layout and vulnerabilities, and how different kinds of physical threats need to be approached. The threats can be addressed within each stage of implementation, design, and maintenance. As a result, the paper has classified threats at three broad levels. These are as follows – theft & burglary, vandalism, sabotage, and terrorism. While theft, burglary and vandalism are the most common examples of acts of harm towards individual or a business, sabotage and terrorism pose higher risk and must be dealt with appropriate measures involving government support in some cases.
Deterrence Methods and Standards
With the identification of the threats complete, it is now time to have appropriate methods and mechanisms that would deter any potential attacker from indulging in any suspicious activity. The goal of these methods is simple – intimidate and hinder any acts of thefts and to convince the attacker that the building or facility is equipped with the essentials needed to monitor, record, and capture individuals through strong defense systems employed at the site.
The deter objective is one that is far away from the main location of the assets and serves as the first line of defense in Physical Security. Comprised of a mix of techniques involving perimeter securing, fences, lighting, and natural surveillance; the goal is to avert the perpetrator from even attempting a system breach. Often referred to as a psychological battle for security teams to assert control and instill fear in potential raider, deterrence is an effective technique and is achieved through some of the systems as explained below.
1. Physical Barriers & Combinational Barriers
Physical barriers are great deterring agents as they lay out the plan of the entire organization or complex. Having tall mounted fences, walls and vehicular barriers in place are examples of such agents where they act as the psychological agents to intimidate outsiders from breaking in. Physical barriers aren’t limited to walls and fences, but can extend to guard towers, warning posts, and utility opening among others. The barriers not only act as a deterring agent but also helps in delaying and preventing attacks by clearly marking the boundaries of the facility and making intrusion seem less easy (Pariafsai, 2016).
When fully integrated with tall fencing, barbed/razor wires or metal spikes, physical barriers restrict and impede access by emplacing on the property perimeter. Combinational barriers are detection mechanisms used inside facility to detect fire,
smoke mitigation, or any safety related hazards.
2. Natural Surveillance & Security Lighting
Natural surveillance to a large extent manipulates the potential attacker’s opportunity and motivation by increasing his/her chances of apprehension and thereby reducing crime deterrence significantly. An increased presence of human individuals in a neighborhood for example reduces the potential for attack. Through CPTED, buildings are now oriented and overlooking pedestrian movement & traffic on road with strong glass shielding individuals on the inside and creating highest possible levels of clear visibility. The same is applied in the placement of windows, open areas and trimmed natural vegetation that provide clear lines of sight by reducing hiding. A strongly parameterized fence with proper lights also acts as a good deterring factor (Cozens & Love, 2015).
Proper lighting fixtures installed on aisles, pathways, doors & exists, elevator entrances and stairwells clearly identifies persons or objects and creates a psychological deterrent to criminal activity in the area being protected. Illuminated building entrances providing a clear line of sight from both inside and outside, visible placement of CCTV equipment, and using low emission lights to avoid blind spots are some other ways that helps creating an atmosphere that is safe and difficult to penetrate.
3. Perimeter Intrusion Deterrence/Detection and Electronic Surveillance
One of the best approaches to design IDS is a Concentric Circle Protection layer and defining each layer by the perimeter and the area it covers. While the very first layer of defense are the perimeter boundaries, entrance and exits point of the facility, the layers grow as we move inward where focus is more on security and surveillance deemed towards protection of company’s assets and allowing for controlled access within the facility. Companies employ variety of tactics to ensure they are able to detect any possible intrusion beforehand and have mechanisms in place that deter such intrusions. 24x7 video surveillance through well placed security cameras, drone activity, and infrared cameras are some of the many ways that deter any potential attacker from entering the premises (Frattini et al., 2019).
Once inside, the inner security layer relies on biometrics such as facial, thumb or retina scan recognition features which are way more psychological deterrent and creates a significant impact. Furthermore, presence of armed security personnel both inside and outside facility perimeters is another advantage over any perpetuator with some companies even using robots to monitor facilities 24x7
(Iftikhar et al., 2019).
4. Alarms and Sensors
Alarms are an integral part of the security enforcement. Having clearly visible alarms in forms of speakers and illuminating alert lights, is a big advantage over intruders who look out for such signs to trespass. Installation of alarms for the most part on gates, doors or even windows is a potential deterrent for the intruder to stop in his/her tracks even if they manage to open it. A high-pitched noise and blinkers are more than enough for the deterrent. Most companies use notifications as and when the alarms go on for tracking purposes (Kloepple, 2018).
Sensors are an automated piece of work that are implemented to detect and communicate any intrusion to the security monitoring team. While these may not be visible to the naked eye but are quite suitable in setting off the alarm thereby deterring any potential for intrusion by an outsider (Frattini et al., 2019).
5. Access Control
Doors along with gates are the most conventional forms of deterring outside threats. A well secured and heavily built door is enough to send a perpetrator away. Gated communities equipped with security sticks for entrance are known to provide controlled access to authorized individuals. Coupled with padlocks, deadbolts, and other lock forms, doors have been in the society for quite some time. Deadbolts provide an extra layer of security besides the door handle. Similarly, electronic locks reinforce security by providing users ability to use passcodes that only they have access to. Security glass is an invigorated technique that offers wide range of security protection as deemed necessary by the usage. Depending on the situation, security glass can cater to wide ranges such as ability to shield stones, bullets or just protecting the insides of a home (Almutawa et al., 2013).
Smart cards are standard based ID cards can use to validate an individual personality and decides the precise degree of access. Sometimes magnetic or driven by radio frequency, they are used in places that require authentication. Doors are usually equipped with a card reader to allow for controlled access thus serving as a
deterrent for any individual who plans to enter otherwise.
Risk Mitigation & Business Continuity
The potential of any event that results in disrupting critical business functions, destruction of assets, or loss of personnel in extreme cases, is a risk associated to the event.
The likelihood of the event to happen and its consequences is a measurement of the risk. Risk evaluation is typically defined as the combination steps of identifying and measuring the risks. It is a task that involves comparing the estimated risk against the set risk criteria to determine the significance of the risk (Al Hour, 2012).
There are eight attributes that come associate with a risk – advance warning, likelihood, impact, day of week, location, time of day, predictability, and scope. Within the context of physical security, risk mitigation typically involves identifying risks, threats and vulnerabilities beforehand and performing regular future analysis as much as possible. Given that deterrence is the first line of defense, investment in threat assessment would allow for those threats to be analyzed in detail, which in turn would eliminate any vulnerabilities thereby significantly mitigating risks associated with those threats.
A great deal of time, effort and resources are required to build an effective business continuity plan. By identifying business process critical towards Business Impact Analysis, assessing risks associated with such processes under Risk Assessment, and building a comprehensive plan, allows for business continuity. With all the mechanisms in place to deter any unforeseen events, there still exists a great likelihood that the system might fail (Zhang et al., 2009).
The business continuity plan serves as a series of steps that the organization needs to act followed by an immediate attack. The plan provides a set of guidelines to reduce the
Physical Security Deterrence
Physical Security Deterrence
Physical Security Deterrence
Page
1
Page
1
Page
2
chaos at the point of incident and to position the security team for an immediate recovery once adequate facts become available. Business continuity is aimed at restoring critical business functions related to efforts in security deterrence by carefully appointing designated appointees with appropriate tasks in hand in event of an incident (Al Hour, 2012) The teams and their supervisors are responsible for restoring back security systems to deter any further attacks.
Industry Issues & Concerns
Physical Security is a very wide topic and can differ widely based on the industry where it is applied. Owing to the types and solutions provided by industries vary case by case basis, issues concerning the implementation of mechanisms to deter threats are difficult to bundle up. However, certain concerns are common across all industries and can be categorized under old facilities, overwhelming operations, lack of training, and blackmarket replicas. Old facilities often pose a serious threat and undermine the security of the entire workplace. Complexes with old buildings and structures become high target points and are prime vulnerable for intruders to focus and ultimately reduce the deterrence to act upon. Risk assessment is a critical step in overcoming this issue. Many a times the multitude of operations and steps taken by the security team can be so massive that they lose focus on the evident – deterring threats. If the security operations team is overburdened with false alarms going off every now and then, the change is towards ignoring those alarms and losing attention towards actual threats (Urhuogo-Idierukevbe, 2019).
While there are some industry level issues there are certain concerns that every industry needs to deal with. This can be summed up under rogue employees and casual attitude. It has been widely observed that most of the security breaches are work of the people on the inside letting unauthorized user access to the facilities. At the same time, a casual attitude of employees such as piggy-backing, leaving work-stations unattended, and leaving secure entry points open when smoking are common examples of behavior that encourages outsiders to challenge the security of the organization as a whole.
Budgetary Concerns
In evaluating the best physical security measures, the initial step is to assess the amount of money that will be spent towards mechanisms for deterring physical threats. The budget for overall physical security is distributed across various silos such as money to be spent on infrastructure, maintenance and regular updates on the equipment, cost incurred when managing security teams such as armed guards or personnel, and equipment supporting monitoring and surveillance activities. The first fiscal concerns are the business perils and valuables by considering areas of critical concerns in terms of controlled access, perimeter fencing, and securing business facilities. Concerns arise where companies have to put these distributions into perspectives of overall running cost and recurring cost incurred in terms of finances, competitive edge and public relations.
While it doesn’t go to say that all companies are concerned about the cost incurred in security, there are many others who spent a ton of their budget in protective measures to deter attacks. Government agencies that produce weapons, carry research in isolated and unknown places spend huge amounts of money to support their cause and guard
information as much as possible. Similarly, critical public places such as airports and train stations spend considerable amount to prevent terrorist attacks. On the other hand, a small consulting business would spend a fairly smaller amount and rather focus on protecting its assets (Urhuogo-Idierukevbe, 2019).
Policies & Guidelines
The policies for Physical Security are absolutely critical in maintaining and preserving any facility. Strict adherence to policy is a key in ensuring that all safety and security requirements set forth by the management is met and in compliance with the industry, city, state or federal standards. Policies are set for each of the above listed counter measures to ensure each of them is in working state and that the industry or neighborhood can rely on. A workplace security policy is fundamental in creating an environment that is not only safe for working but provides adequate protection from outside threats. Regardless of the type of business, housing complex, area of expertise or company size, a security policy is mandatory and must be issued at all times. The policy not only helps in keeping the place secure but also makes the operations run smoothly while adhering to any state rules and regulations (Ščurek & Holubová, 2019).
The security policy outlines the company’s goals for security, encompassing both internal and external security threats. The policy when enforced correctly saves numerous security issues by laying out the basic rules, definitions and standardized guidelines to be followed across the organization. A typical example can be in a manufacturing firm that requires all its employees to be wearing hard hats and ID badges at all times.
Guidelines are means for enforcing the policy by laying out standardized definitions and practices to ensure that those are strictly followed by everyone for their own safety and protections. Guidelines usually include rules that are meant to streamline particular processes based on a routine or practice set. An example can be laying out the standards to setup an acceptable video camera for intruder detection and crime prevention.
Conclusion
To conclude, deterrence in physical security forms an important component of any facility in securing personnel and company assets. The above-mentioned physical security play a critical role in convincing intruders and potential attackers, that the likelihood of success is substantially low. Implementation of deterrent security controls are found in the combined use of physical barriers such as walls, visible surveillance equipment such as closed caption television (CCTV), lighting, alarm etc. Obviously, the probability for both observation and action are greatly improved by these measures thereby reducing the chances of intrusion. Facilitated by policies and guidelines laid out under the security policy and plans for risk mitigation and business continuity, deterrence does play a significant role in achieving the primary goal under physical security i.e. acting as first line of defense.
References
Al Hour, A. (2012). Facilities management and physical security in business continuity management: Choosing to Survive (pp. 160-181). IT
Governance Publishing. Retrieved March 28, 2020
Almutawa, F., Vandal, R., Wang, S. Q., & Lim, H. W. (2013). Current status of photoprotection by window glass, automobile glass, window films, and sunglasses. Photodermatology, Photoimmunology & Photomedicine, 29(2), 65
72. Retrieved from https://doi.org/10.1111/phpp.12022
Cozens, P., & Love, T. (2015). A Review and Current Status of Crime Prevention through Environmental Design (CPTED). Journal of Planning Literature, 30(4), 393–412. https://doi.org/10.1177/0885412215595440
Frattini, F., Giordano, U., & Conti, V. (2019). Facing Cyber-Physical Security Threats by PSIM-SIEM Integration. 2019 15th European Dependable Computing Conference
(EDCC), Dependable Computing Conference (EDCC), 2019 15th European, 83
88. https://doi.org/10.1109/EDCC.2019.00026
Iftikhar J., Hussain S., Mansoor K., Ali Z. & Chaudhry S. A., Symmetric-Key Multi Factor Biometric Authentication Scheme, 2019 2nd International Conference on
Communication, Computing and Digital systems (C-CODE), Islamabad, Pakistan, 2019, pp. 288-292
Kloepple, S. (2018). Lighting Upgrade Breathes New Life into Data Center: Low-voltage wiring and led lighting makes for a more energy-efficient and visually appealing data center in Cleveland. Buildings, 112(11), 10
Pariafsai, F. (2016). A review of design considerations in glass buildings. Frontiers of Architectural Research, 5(2), 171
Ščurek, R., & Holubová, V. (2019). The Physical Security of Buildings of Public Universities. Journal of Security & Sustainability Issues, 9(2), 505
Urhuogo-Idierukevbe, I., Addo, A., Anderson, T. L., & Khan, F. M. (2019). Physical Security Best Practices. Journal of Physical Security, 12(3), 15–29
Zhang Xiao, Li Zhan-huai, & Chen Jian-quan. (2009). A Common Information Infrastructure for Multi Command Center System. 2009 Second International Symposium on Information Science and Engineering, Information Science and Engineering (ISISE), 2009 Second International Symposium On, 249–253.
https://doi.org/10.1109/ISISE.2009.30
Page
10
Page
10
Page
14