1
THE INTEGRATION OF PHYSICAL AND LOGICAL ACCESS
CONTROLS IN SECURITY FRAMEWORKS
Introduction
Background information of physical and logical access control integration
What is Physical access control?
Access control physical security also makes sure that none of the wrong persons
is allowed in the premises. This means that you are shielded from intruders and this
has benefits to users of computers. Physical access control security can also play a
role in making a positive, easy movement of people through a building especially
those who have been granted access. There are a number of access levels that can be
provided for various users, which implies that only when employees have the
appropriate permission, they may get to sensitive areas of the building. Access levels
are normally granted where access levels are assigned to individual users or to the
group of users at a specific level for instance executives or contractors. An example of
physical access control is; for all employees to have entry to the main door and use
the entry card, key fob door entry systems or PIN to gain entry into the building but
restricting them from accessing certain areas within the building such as areas with
secure, sensitive or privileged information. Before, security access was controlled by
guards who would normally control the authorization or non-authorization of access
at some strategic gateways. In the present world, physical security access control is
automated. Physical access control systems (PACS) employs key fob, swipe cards and
personal identification numbers (PINs) to ascertain authorization not physical keys.
2
Physical security access control policies enable you to control access to your building
at a granular level as well as granting or denying access to individuals.
Physical security access control policies enable you to control access to your
building at a granular level as well as granting or denying access to individuals,
physical access control plans and systems can be used to:
Use lockdowns in case of an incident
Restrict entry into places that have a lot of traffic.
Inform the clients’ location in the event of an evacuation.
Components of physical access control systems
There are several key components that make up a physical access control system:
The Access points
These are considered as the physical access points where measures of security
have to be put in place to ensure that no unauthorized person gains access. Some of
the typical physical access types include commercial door locks, turnstiles as well as
security gate systems or any other kind of a physical barrier.
Identifying personal credentials: All the PACS must ensure that the users have
some form of identification to authenticate that they are allowed into the physical
space. Personal identification methods include key fobs and key cards, token,
application in phones, numeric identification, password or code, encrypted cards,
fingerprint identification, face recognition and license plate identification. Another
research regarding access control used ID badges by 60% of the companies while
more developed technologies are gradually being implemented; 32% of the companies
3
utilize mobile IDs while 30% are using biometric identification with 25% Companies
using license plate identification.
The Readers
Regardless of what credential to use to assure the identity of the users, these will
be used in access points which involve readers or a keypad. After the user has entered
his/her PIN or card, the information will be channeled to a control panel seeking
permission to access.
Control panel
Information from a reader is directed to the control panel and the latter will
confirm authorization. If it is approved then approval will be granted and the entry
point opened to allow the user to make an entry. If a credential is not captured the user
cannot be granted access into the building.
The Access control server
This could either be traditional, that is on premise, or cloud based. Regardless of
physical or cloud based implementation, an access control server required to securely
store the user information, access control information and logs. The server monitor
activity whereby the administrators can view some reports on entry attempt or even
non-successful entries.
The PACS, therefore, has to be integrated with doors with the electronic locks
that can be preset to unlock on presentation of valid credentials. You may decide to
install fail safe or fail secure locks although depending on which parts of the building
you are protecting, there may be certain rules regarding which lock has to be used.
For instance, entry doors require the use of fail-safe locks to meet fire laws so that
folks can walk out anytime.
4
Benefits and challenges of unified access control frameworks
Forbes has reported that an average of twenty billion dollars every year is spent
by the American people on home security devices. Pragmatic interests make
businesses need a more complex approach to security. One such is by integrating
standalone or centralized access control system – fundamental elements of today’s
security architectures.
The benefits of centralized access control systems include:
Improved revocability and authentication — all sites any member can visit can be
identified using a smart card or other token.
Increased productivity — a centralized system allows for property management
to be simplified because all the control operations are done within the platform.
Potential savings — one system for all the locations is much easier to implement
and maintain, therefore the costs are covered.
Scalability — an ACS that is located and operated at a single place is easier to
modify to accommodate more features in the future.
Access control systems are the most crucial part of a security that help in
managing accesses to areas and assets in an enterprise organization.
Unlike ACS deployed centrally, the one mentioned above is an independent
system for security purposes; as such it is able to work on its own, without relying on
the links to the central server or any specific connection. The benefits of standalone
access control systems are as follows:
I. More decision — a standalone ACS provides discrete control of each point of
entry or establishment.
5
II. Increased safety — secure your locations better since each entry point strictly
applies unique control panels and security equipment.
III. Increased flexibility — incorporate new control points that are as simple as a
door handle or gate when required.
IV. Easy to implement — a standalone access control system’s main element is a
local database and does not necessarily require virtually any hardware or software
changes.
V. Implementation flexibility — standalone ACSs provide compatibility benefits for
business security systems that have been implemented.
Challenges of centralized access control systems include:Challenges of
centralized access control systems include:
The Complication of many Systems & Networks
The overall governing of many systems and networks poses challenge in the
application of SOC 2 access controls. This can be due to the proper stakeholders’
access setting and control across the multiplex system differentiating the structure of
the infrastructure. Further, it is difficult to achieve uniformity of access control
policies and its implementation across the systems and the networks they link since
they are configured differently and possess different specifications.
The second is the choice between greater security and improved productivity
of the end user
Finally, the final great hurdle in the actualization of the access control in SOC
is to ensure the security and efficiency of higher-level user productivity control These
measures when not professionally applied may include measures like strict
authentication of users, or restriction of access to certain areas, this may in one way or
6
the other influence bad the productivity of the users. The appropriate level of
protection is a critical factor, which must be established in an appropriate manner as a
means of providing sufficient protection, on the one hand, and minimizing the impact
on legitimate users, on the other.
A Review on Changes in Threat-solvers
Furthermore, having to track the new threats that may be emerging in turn
makes it even more challenging to implement access control of SOC 2. While the
online threats remain constant, dynamic and even more complex, it is also imperative
for access control mechanism to advance since there are new hole that the attacker can
always find. It thus important that, access control policies and practices are
consistently evaluated, remeasured, and updated to counter new threats
comprehensively.
The Interconnectedness of physical and cyber security systems
What is Security Convergence?
Security convergence involves integration of apparently heterogeneous
physical/information infrastructure security systems to guarantee the most secure and
consistent state of an organization. Security convergence assist in acquisition of
cooperation and clarity among the various facility teams and IT teams who deal with
the physical and cyber technologies. According to the security convergence strategy,
the management of a company can protect the organization’s image, enhance the
performance of the business and mitigate possible risks.
Case on a Cyber Attack to A Physical Security System
7
Threat actors consider the IoT layer to be the least defended by companies
and may well target IoT devices to gain access to data or to extort money from a
company, disrupt trusted third parties, or cause intentional downtime.
One example of potential cyber attack situation is organization that installed
security cameras which are monitored through a network. This is especially so in the
absence of adopting a converged security program and where the physical security
and cybersecurity teams had no working relationship with each other; each could
think the other had taken care of such basics such as resetting default passwords
among others. At other occasions, malicious individuals are granted permission to
infiltrate the corporations’ security and the hackers would then sell this access to the
highest bidder in the black markets.
Benefits of Security Convergence
However, its with a raised eyebrow that one notes that the subject of security
convergence has advantages that extend beyond guarding an organisation’s networks
and computer systems against hackers and malevolent viruses. Over the recent past,
there has been a desire for single sign on technologies that where the user has a
corporate account to log into various systems. Currently a user’s password represents
his/her corporate identity and may record activities on physical as well as digital
control devices. For instance, a badge card reader can be linked with the user’s
Microsoft account. It can show when someone turns on their computer or when he or
she walks into a conference room for a meeting.
Management of the corporate identity is the hot issue all oVer the world today.
Such converged technologies help understand how people work and, for example, can
consolidate security management and oversight. If an employee is fired, in a few
8
minutes, his/her badge is deactivated, extinguishing account privileges on servers,
emails, forbiddenatical areas within a building, etc. Unlike the conventional methods
which require HR to notify different departments to revoke the permissions
individually, it does not have room for something to be overlooked.
Security integration is also being utilized for energy savings where corporate
logos are associated with a building automation system. For instance, an applicant
should note that through machine learning and AI skills, a certain system gains
knowledge that a certain room is always occupied on Saturdays for a four-hour time
slot and, in the process, tweak the HVAC.
In fact, convergence comes with many other benefits to organizations apart
from their business security management. All of it contributes to the architecture of a
company to simplify the management of systems, and to facilitate a positive
experience for users in the end.
Security Convergence can therefore be potential challenged in the following
ways:
In the case where certain brands have a number of branches, security cameras’
operation was previously local, and someone might supervise the security of one
building only. Security convergence enables people to monitor camera displays in
different places, which will also save manpower expenses. The main issue arises if the
company, let’s say, ends up having hundreds of cameras in different cities to oversee
rather than just a handful of them. Similarly were an issue is identified at a location,
the person monitoring must know where exactly the threat is happening, to whom he
should report, or the municipal authorities to contact.
9
Luckily enough is the revealing fact that AI automation is coming to the
rescue by centralizing these systems and ensuring that proper alerts are initiated. With
time, the AI enhancements are going to increase in capacity and thus the monitoring is
not going to require so much manpower.
There are two main issues with converged security: The first is security while
the second is privacy. AI can track people within a building, and with the use of a
picture taking device, record a one-time sequence of the activities they indulge in. It
may even have the capacity to assess people on the basis of facial features. Others
may consider it an infringement of the right to privacy hence corporations may have
to come up with policies on the same.
One of the criticism of converged security is privacy. Such system can track
the movements of people in and around a building and make a record at a particular
time. It can maybe capture people through facial recognition as well. Others will
probably raise an eyebrow at the idea of monitoring; corporations are going to have to
establish lenient policies concerning privacy.
How to Put into Practice the Security Convergence_Framework
Establishing transparency among departments may well be the cornerstone
prerequisite of a secure convergence plan. Discussing with the facility teams with the
IT teams would be the first step in addressing the problem. In this way, spouses will
be able to define possible threats and the kind of behavior each of them should adhere
to.
Thankfully, converged technologies do not have to be put in place at one time.
When your organization is in the process of reviewing and upgrading your tech stacks,
invest in systems that allow convergence so that you are not putting your money on
10
technologies that will become obsolete over the next few years. It should be possible
to start from the access control systems for example and go from there. Remember to
also have a look at our Access Control & Purchasing Guide found below for all the
details regarding access controls.
One can always consult an experienced integrator to ensure that new and
advanced cloud based equipment is incorporated with the older technologies being
used by the institution. When the systems are modified, your technology partner can
then put in solutions that are adaptable and can include changes later on.
The main focus being connectivity and ensuring you have the prerequisite
structure that is correctly configured so as to allow for cloud platforms. ASD has a
focus area of implementing flexible technology and OR/technology consultancy.
Contact our team today for more information on what services you may require. We
can show you where you may be lacking and give you recommendations for the first
steps in securing convergence that is both solid and strategic.
Single sign-on of a person within physical and cyber facilities
In the ever-changing environment, trends Unified Identity has become an
important part of the cybersecurity and the performance of the user’s digital identity.
Unified Identity deals with the integration of several digital identifiers including
usernames, passwords and multi-factor authentication into one harmonized system. It
means that this innovative approach is profoundly changing the relationships between
human beings and technology providing a lot of opportunities apart from the security
sphere.
The Sharing of one and the same Identity
11
Unified Identity is about singular identity that is used to access as well as
authenticate users on various platforms and applications. Because people have many
online profiles as well as use numerous online services, having a single integrated
identity is less problematic and more convenient. It is usually achieved through the
so-called Single Sign-On (SSO) wherein a person uses the same set of credentials
proper to different systems.
The unified digital identity is the essence which holds the capability of actualizing
the digital economy – World Economic Forum
Advantages of having a Single name
Inasmuch as unified identity has its advantages and disadvantages, it has its
share of advantages that both the users and organizations enjoy.
Here are some of the key benefits:
Enhanced security
Single identity means that the user gets access to all his/her applications and
services with the account. It makes it possible for the businesses to enforce the
security rules and procedures and in the process recognize the violators. It also
minimizes password fatigue which is witnessed whereby the user uses many
passwords throughout a single session.
Improved user experience
This strategy simplifies the process of the users signing into the system and
takes less time as compared to the conventional method. It also enhances the
performance and minimizes user’s frustration in the process of using a given software.
Increased operational efficiency
12
Different identity approach can help to routinely update various work of
identity management procedures. Some of the functions are users management
whereby users can be added or deleted, management of permissions according to the
roles of the users, and authorization. Thus, this also frees the IT staff from such tasks
and they can focus and channel their effort on other valuable projects.
Greater flexibility and scalability
It is possible to express a unified identity strategy in support of many forms of
authentication. These are; Biometric, Multi factor and Single sign on (SSO). This
makes it possible for the businesses to be able to cope with the ever changing security
and compliance standards and at the same time enhance scalability.
Better regulatory compliance
With a single identity system, the business can monitor the access and use of
applications as well as the services through the different interface. This makes it
easier in data privacy regulations and audit purposes respectively.
Unified identity has many applications in different areas of technology, including:
Enterprise identity and access management (IAM):
It is possible to develop a singular identity approach with an organization’s
system. This can be done in order to grant the employee one identity and password
through which they can login and use all their necessary applications and services.
This can enhance the process of signing in, eliminate the issue of password exhaustion
and ultimately enhance the aspect of security.
Customer identity and access management (CIAM):
13
This strategy can utilized as when implementing customer facing applications. It
ensures that users have a comfortable and safety login to their accounts regardless of
device. This enhances interactions between the users and the customers, enhance
customer relations, and makes marketing more personalized.
Internet of Things (IoT):
An example of identity strategy that can be applied is a principle of application
which can be utilized to accomplish the goal for one identity across devices,
applications, and services. This is not only beneficial because it increases security and
efficiency as well as enables novel business models.
Federated identity:
It was earlier discussed that this strategy can be used to enable users to
authenticate in multiple domains or organizations. This can be helpful in creating
partnerships, fostering trust and creating new partnerships that will lead to new
business deals.
The role-based access control (RBAC) for physical and logical resources
RBAC, or role-based access control, is a powerful method of administrations of a
network that limits access by a person according to his or her position in an
organization.
The roles in RBAC pertain to the levels that the employees are allowed to access
the network. All employee gets to see is what he or she needs to see in order to do his
or her job properly. As for the way access can be granted, the factors may include
authority, the responsibility for the job or competency of the employee. Also, it is
crucial to stress that the access to the computers and their resources can be limited
only to particular operations, for example, the possibility to view, create or edit a file.
14
Therefore, lower-level employees normally cannot access to the data and
information if they do not require it for their job. This is especially helpful if you have
many employees and you interact with third-parties and contractors to help you with
your business, these are hard to monitor the network access. Implementing RBAC
will assist in the protection of your organization important data and applications.
Examples of RBAC
In RBAC there are ways to manage what the end-users can do at the most
general and at the most specific level. You can distinguish whether the user is an
administrator, a specialist or an end-user, and link roles and access permissions to
organizational positions of your employees. Access rights are provided only in
sufficient degree to allow the employees to perform their tasks.
What if an end-user has a new role which requires a different set of applications?
It is suggested that you assign their role to another user and you can also add or
remove member or a role group using role assignment policy.
Some of the designations in an RBAC tool can include:
Management role scope – it defines what objects of the management role group
can manage.
Managerial sub-group – you can invite and exclude individuals.
Management tasks – these are the forms of task that can be done by a given
management role.
Management role assignment – this assigns a role to a role group.
15
When a user is being added to a role group, the user then gets all the roles in the
said group. If they are taken away, one is locked out. Users can also be added to many
groups if they require some kind of temporary access to some data or program and
then removed afterwards.
Other options for user access may include:Other options for user access may include:
The type of connector that assumes the role of a primary point of contact to a
given account or role.
Account access – one end-user has the access to the billing account.
Technical – assigned to users that operate in a technical environment.
Authorized – access for users that have administrative responsibilities.
The Benefits of RBAC
Therefore, it is critical to manage & audit networks access as they are keys to
information security. Some of the access can and should be granted only if the
employee actually needs to have it in order to do their job. In an organization that has
many employees for example, hundreds or thousands of employees, then security is
easily maintained through restricting access to such critical information based on the
user’s position in the organization. Other advantages include:
Eliminating as much paperwork as possible and cutting down on the number of
people in the IT department. In other words, with RBAC, you can minimize
paperwork as well as password changes each time a new employee is hired or his/her
organizational role is modified. However, with RBAC, you are able to add new roles
and switch between them easily and apply them universally across operating systems,
platforms and applications. It also minimizes the chances of mistakes that may likely
occur when granting permission to users. Still, time is saved with other clerical
16
errands aside from being one of the economic advantages that RBAC has to offer.
RBAC also assists in the management of third party users since you do not have to
assign them roles from the scratch.
Maximizing operational efficiency. RBAC provides a simple and therefore
logical definition of a model that is based on roles. The bottom line is all the roles can
be made to mirror the business and organizational structure of the firm and users can
work smarter and more independently without the need for lower-level access control.
Improving compliance. It is important for all the organizations to know the
federal, state and local laws that govern the organization. Since RBAC system has
been implemented properly, it becomes easier for companies to achieve statutory and
regulatory requirements on privacy and confidentiality since IT departments as well
as executives have control on how data is accessed or used. This is especially
important in organizations that deal with a lot of sensitive data such as health care and
financial institutions that deal with PHI and PCI data respectively.
The following are the best practices that a business should consider when
implementing RBAC:
1. The introduction of RBAC model in your organization should not happen
anyhow. In essence, there are a sequence of general actions to get the team on
board without creating potential confusion and possible frustrations in the
workplace. Here are some things which should be planned in advance.
2. Current Status: Make a list of all sorts of software, hardware, and application that
have some form of security. In most of these cases, what you will be entering will
be a password. You may also wish to include server rooms which are locked and
secured. Physical security can be a very important aspect in the protection of data.
17
Also, enumerate the status of who is allowed access to all of these programs and
areas? This will help you to have an insight of the current data situation.
3. Current Roles: It may only take a little discussion to establish what the each
person on your team does whether you do not have a list of roles and roster or not.
It is wise to structure the team in a way that does not interfere with creativity and
if it is something that is enjoyed the current culture.
4. Write a Policy: If any changes were made then they require writing so that all the
existing and prospective employees can get to see it. However, when using a
RBAC tool, having a document that outlines your new system will be of great
assistance to avoid such problems.
5. Make Changes: Once the current security status and roles are understood (let
alone a policy is written), it is time to make the changes.
6. Continually Adapt: RBAC is most probably going to need some fine-tuning in its
initial implementation, with the first version of the implementation being
probably somewhat modified. In the early stages, you should assess your roles
and security status quite often. Secondly, evaluate how effectively you want the
creative/ production process to be, and secondly, determine the degree of security
your process offers.
Another of the primary processes of any company is data protection
In an RBAC system it is possible to ensure that the company’s information is
compliant with the privacy and confidentiality standards. Besides, it can protect
critical business functions, such as IP access, which is critical to the business from a
competitive perspective.
18
Another important element is the centralization of access events’ monitoring and
auditing.
Centralized access control simply refers to the practice of access control where
all the operations are coordinated from a single point.
Centralized access control may therefore be defined as a situation whereby
control of access to a number of entry points or resources is located or controlled from
a central point.
In a centralized access control system, all the access permissions credentials,
and authentication processes are controlled centrally through a centralized access
control management system. It also becomes easier to manage and enforce access
policies in an organization across locations or devices.
Centralized access control allows users to log in to all application, site,
computing system, etc. , with the same credentials irrespective of the place they are
accessing it from. It is worth stating that all information assets in the control of the
user are managed under a single identity approach.
The organizations can cause the centralized access control to allow the efficient
administration in the hybrid workplace and secure the buildings or areas to facilitate
the efficient examination of the access control across the multiple sites.
How centralized access control works
Centralized access control is a system whereby management of access is done
through a single management system. Users can select from one of the multiple
authentications methods which include passwords, biometrics or smart cards. Central
controlling decides access rights according to certain policy standards and interacts
with access points at entryways. It is also possible to audit and investigate the access
19
events which are logged and monitored in real time. It is controlled by the
administrators and they can also interface it with others security systems.
This single solution of identity management for all the enterprise applications
provides the user a single browser-based console for integrated access control. The
central access manager or console supports many IT services including the installation
and configuration of the components, network health check, and access to all works
resources employees require to accomplish all usual tasks.
Pros and Cons of Each IT Model
There are pros and cons associated with each IT model as is the case with any
system in an organization. This way you will be able to analyze each approach and
compare the strengths and weaknesses of each of them and draw a conclusion on
which one is better.
Centralized access management has less user interactions and this means that
people can be able to use many applications and data with a single login. In addition,
it empowers your IT group to see ‘who has access to which each all app,’ which gives
them more control. Furthermore, it also enables them to have a better control on the
users themselves. However, if a centralized AM solution is developed, installed and
managed poorly then it becomes the weak link that consists of the entire system,
which is exposed to security threats.
On the other hand, decentralized access management assist your IT team in
dealing with the single point of failure concern by keeping data and improving trust. It
is based on such Web3 technologies as blockchain and user-controlled decentralized
identifiers (DID). DIDs allow users to own their data, and enable a convenient way of
20
authentication across SaaS applications and blockchain technology offers a secure
cryptographical ledger.
Decentralized solutions usually are more efficient from the point of view of
costs because there is no need to include all the nodes in the network to reach
consensus. But they can be less flexible in terms of administrative control as
compared to what centralized AM can provide to organizations. In addition, the
approach adopted in the decentralized system risks exposing the system to more
threats as monitoring ends user behavior and usage of the resources is challenging.
The Integration of physical access systems with network access control (NAC)
Network Access Control Defined
With NAC it is possible to know who is allowed to connect to the network, what
they can see within the network and who cannot connect to the network.
For example, within an organization, people such as salespeople, engineers,
managers and receptionists will need the company’s network. However, not all should
be allowed access to such materials as the company’s financial data or any other
sensitive information. Other people will only require restricted access and controls
such as contractors, freelancers and other guests. For instance, guests may be allowed
to view documents but they cannot edit any of the contents. One of the ways that
companies can use to achieve this is by implementing Network Access Control that
would allow only the authorized personnel to access the network and block out any
malicious traffic .
New network security technology as well as NAC has been influenced by cloud
technology. The presence of new devices and technologies connecting to the networks
such as IoT, mobiles, BYODs from the remote workers and cloud resources makes it
21
even more essential and crucial for the organizations to control and say who can
access the network, from where and which data they can access.
The holistic threat detection by Event Management (SIEM)and security
Information
SIEM stands for "Security Information and Event Management," which is itself
derived from the acronym SIEEM, for "Security Information and Event
Management." Sometimes it is even referred to as SIME for "Security Information
Management and Event Management." The SIEM security management solution
integrates and unifies two aspects of security management: SIM, for "Security
Information Management" in the communications equipment industry, and SEM, for
"Security Event Management."
Inclusions of all and every SIEM system can be summarized by three aspects of;
data collection from various sources, analysis of the data to determine deviation, and
taking of an action. For instance, once, a particular issue is identified, a SIEM system
may record more details, raise an alert, and order other security measures to halt the
progress of an activity.
The first adoption of SIEM in large enterprises was for Payment Card Industry
Data Security Standard compliance while the more recent concern with advanced
persistent threats has made other organizations look at the positives that SIEM tools
have to offer as well. Having a capability of viewing all the security-related data from
a particular viewpoint is advantageous as it can help organizations of any size to
detect outlying characteristics.
At its lowest level, a SIEM system can be rule-based or make use of a statistical
correlation engine in order to find relation between different entries in the event logs.
22
Present day SIEM systems go further with user and entity behaviors analytics and the
security, orchestration, automation, and response (SOAR).
The operation of SIEM systems concerns the use of a number of collection
agents formed in a tiered structure in order to collect security-related events from end-
user computers and terminals, servers and networking equipment and devices, and
also specialized security hardware such as firewalls, anti-virus software and Intrusion
Prevention Systems (IPS) . The collectors send event to the central management
console where security analysts look at the clutter and correlate it or prioritize security
events.
In some systems, pre-processing is performed at the collectors, servers or PoPs
where only some restricted events are forwarded to a centralized management node.
Thus, the amount of information that is being conveyed or archived can be effectively
minimised. While, due to recent advances in machine learning system can detect
anomalies better, analysts have to respond anyway and in a certain sense constantly
train the system about the environment.
How does SIEM work?
SIEM tools collect event and log data generated by host systems across an
organization’s IT structure and delivers it in a single interface. Host systems consist of
application, security equipment, antivirus filters, and firewall. SIEM tools filter the
data and put it into a various categories such as login successes, failed logins, detected
malware and other potential unfavourable actions.
It alarms the organization by producing security alerts when it confirms some kinds
of security. These alerts can be set to be low or high priority based on a set of rules
predefined in the organizations.
23
For instance, the user account that performed 25 failed login attempts in 25
minutes can be regarded as suspicious, however, it is recommended to set the lower
priority because it is apparent the user forgot their login data.
But a user account attempting 130 failed login in 5 mins sounds like a genuine brute
force attack in process and hence will be marked as a high priority event.
Why is SIEM important?
Because the basic function of SIEM is to generate alerts and filter large
amounts of security data, it simplifies the security management for enterprises and
provides the software prioritized security alerts.
SIEM software helps to notice scenarios that otherwise could stay unnoticed.
It involves the examination of the log entries that contains s of Malware ‘attacks’.
Also, since the system pulls events from multiple sources on the network, it
reconstructs the timeline of an attack, allowing an organization to understand the type
of attack that occurs and its impact to the business.
A SIEM system can also assist an organization in achieving its compliance
because it can produce reports containing all the logged security events getting from
these sources. And if the company does not have SIEM software, then the log data
needs to be collected and the reports generated by the company itself.
It also assists the company’s security team in the enhancement of the process
of managing incidents because, aside from noting the path of an attack in the wide
network, it also reveals the sources that got breached and offer the required tools
that halt the on-going attacks.
24
Benefits of SIEM
Benefits of SIEM include the following:
It reduces the time it takes to determine threats by a very large measure thus
reducing the harm caused by the threats.
SIEM provides a broader perspective on constructing an organization’s
information security status and gives an easier way of collecting and analyzing
information to ensure that systems are secure. Everything about an organization is put
in a central data base for storage and easy retrieval as and when the need arises.
Some of the use cases that will involve data or logs for which companies can use
SIEM are for security programs, audit and compliance reports, help desk or network
troubleshooting.
This is done to ensure that SIEM is capable of accommodating the large amount
of data needed by the organizations to scale out and add more data.
SIEM gives threat intelligence and generates security alarms. It can also carry
out thorough forensic examination in the case of colossal security breaches.
The Limitations of SIEM
SIEM’s limitations:
SIEM takes a rather long time to integrate because it needs support that will help
in its integration with many hosts and Security controls in an organizations
infrastructure. It goes without saying, that to get SIEM started could take 90 days or
more.
It's expensive. Basic implementation of SIEM systems can cost in the hundreds
of thousands of dollars. And conversely, the related expenses may reach meaningful
25
proportions, such as the cost of personnel required to implement and supervise a
SIEM solution together with the yearly service and software or agents necessary for
data processing.
This is to mean that analyzing, configuring and integrating reports needs the
work of experts. That is why some of the SIEM systems are operated centrally from a
security operation center, which is a centralized center that is manned by an
information security team that deals with the various security challenges of an
organization.
In essence, most of the SIEM tools rely on rules to process all the captured data.
The issue is that a company’s network could create as much as thousands of alerts
daily. One can easily get confused because of the overwhelming number of logs with
irrelevant data that might trigger an attack alarm.
This means that a misconfigured SIEM tool might fail to detect some crucial
security incidents thus leading to a poor information risk management framework.
SIEM features and capabilities
Important features to consider when evaluating SIEM products include the
following:
Data aggregation: Information and network management targeting the various
applications, networks, web servers and databases is done.
Correlation: Generally a subset of potential capabilities in a SIEM tool,
correlation is when the tool seeks to build similarity between events.
Dashboards. Targets, applications, databases, networks and servers are used to
gather data that is then compiled in charts to analyze it and not to miss any events.
26
Alerting. Subsequently in the event of a security breach these SIEM tools can
alert users.
Automation. There can also be some incorporations of automation which can be
visible in the analysis of security incidents and the generation of responses for
such incidences.
Users should also ask the following questions about SIEM product capabilities:
1. Integration with other controls. Does the system have capability to issue other
directions to the rest of enterprise security controls so as to counter or avoid an
ongoing attacks?
2. Artificial intelligence (AI). Has the development of the system involved machine
learning and deep learning where the system would improve on the obtained
accuracy?
3. Threat intelligence feeds: As an addition to the features which the system should
possess, the question arises whether threat intelligence feeds selected by the
organization can be used in the system or should be replaced with a specific feed?
4. Extensive compliance reporting: Is the system preloaded with business specific
compliance reports that will meet the organizations compliance requirements and
does the system allow the organization to add on to, or create new compliance
reports?
5. Forensic capabilities: Can the system take any extra attributes of security events
by following the headers, and substances of the packets of concern?
Physical and logical access control single sign on (SSO) solutions
What is SSO?
27
Single sign-on is one of federated identity management functions that allow the
use of several applications using a single password. For instance, if an employee is
using identity credentials to log in to the workstation then SSO authentication also
allows access to applications, software, systems, and cloud services.
Similarly, imagine somebody coming in a Google service such as the Mail
service of the company. SSO then, authorizes them; their user account is then granted
access to other Google apps like YouTube or Google Sheets. And, if they log out of
any of these application, they are logged out of the others as well.
Why is SSO important?
In its simplest form, SSO solution can also be referred to as an authentication
service and essential component of Identity and Access Management. Consequently,
it also becomes the useful preparation for the Zero Trust security model that does not
imply inherent trust and continuously requires the authentication of users.
Why does this matter?
If a system fails to identify who a particular user or an entity is then there is no
way of controlling or preventing their activities, this is a serious threat to data security.
This is even more so considering today’s social media, project management or storage
applications and services which are numerous and each of which may require a new
set of logins and passwords.
The current studies show that the average enterprise now deploys 210 different
collaboration and cloud services and the average employee now has access to 36
cloud services at the workplace. It is quite a handful when it comes to passwords, and
sadly, many organizations are far too decentralized in their IT management to
properly address passwords.
28
Thankfully, this is where SSO implementation comes in as a perfect solution to
the above problem. Common formation of multiple passwords into one log-in makes
the work more convenient and at the same time contribute to the optimal security of
accounts for all the participants.
What are the benefits of SSO?
On balance, the advantages of SSO implementation include the followings,
which would be beneficial for users, enterprising and customers as well. For example:
Improved user friendly interface, efficiency and reduced cost
Reducing passwords into one common set of users’ identity can save a lot of
time in the authentication process; this period should enable them to get the best out
of the available resources. This is especially important while working in a new-type
environment that has a combined on-premise/ cloud orientation of the most crucial
applications.
Finally, all these hastened processes result in increased performance among the
employees in the workplace. In fact, even service like SSO which is actually quite
small since it only got rid of the wastes from signing in to multiple accounts daily can
have monetary return on investments.
An example from the research:
Spending three minutes of an employee’s time may cost a company with a staff
of 5 thousand people $1. 5 million per year.
An SSO solution can reduce other non-value added activities like logging support
tickets to the company’s help desk over password issues.
Reduce number for incidents through better approach to password management
29
Weak password practices are behind at least 45% of breaches — with many of
them caused by attackers gaining access to login information. This was always
the case when users had to recall multiple username-password combinations,
which let them to reuse the same credentials on different platforms.
The ‘password fatigue’. This highly insecure since this means if one account has
been breached, any other service can then be breached as well. Namely, the
attackers would use the same password to get access to other applications of the
victim’s account.
It even solves the problem of password fatigue by keeping all logins to a single
sign on. While malicious users would be able to access other services if they gain
the pass word of a given account, SSO in theory makes the use strong pass word
easy for individuals to develop, remember, and use them.
However, in real life, the situation proves not always to be as simple as that. That
is why it is recommended that the SSO solution is accompanied by other security
features — but more on that in the following section.
Easy implementation of policies and dealing with identities
SSO attempts to take care of passwords in a centralized platform, hence it
becomes easier for the IT staff to justify policies and rules concerning passwords. For
example, periodic password changes are exponentially easier to handle in SSO since
the user only has one login credential they have to alter.
Most importantly, when properly adopted, federated identity management saves
login details within a security-encapsulated database. On the other hand, an
organization holds generic username-password combinations in dependent systems
where it has no control over how it is handled, let’s say in a third party application.
30
This makes it more challenging to guarantee that credentials are in compliance with
data safety protocol.
How does SSO work?
Single sign-on (sso) illustration SSO is often referred to as a function of
“identity federation”. In other words, identity federation is a form of trust between
two parties for the purposes of user identification and the sharing of all necessary
information for the purpose of the authorization of access to specific resources. This
primarily entails the use of Open Authorization (OAuth) whichis a framework in
which applications are given the authority to grant the access without the actual login
details.
The SSO authentication workflow is a fast and simple process:Generally, the
SSO authentication workflow is a fast and simple process:
The first step is when the user accesses the request for a resource in the SSO
setup and enter the login.
The resource’s service provider, for example, the host website, can send the user
to an identity provider of its choice like Entrust.
To synchronize with the identity provider, the user’s identity is then verified by
checking their credentials by one of multiple SSO protocols.
In the event the user is successfully verified, the identity provider creates a single
sign-on token, which is also referred to as the authentication token. In short, it’s a
digital asset that signifies an authenticated session of the user.
The identity provider returns the SSO token to the service provider and the later
validates it. If it is required, the application, system or service provider can make
additional authentication request to confirm the identity of the user further.
31
Conclusion
Toward the future trends in integrated access control technologies
Main access control trends for year 2024
The trends in the physical access control system keep evolving at a very fast
pace, and the trends that are expected to unfold in 2024 are critical in determining the
direction of the future of physical security. Just read on to find out which technology,
features and capabilities are likely to dominate the physical security and access
control market in 2024.
Automation of access system reduces the risk of intruders and have a higher
level of security as compared to manual systems. What this does is it frees security
professionals from having to spend hours viewing footage or trying to find trends and
problem-zones through raw observation. Here, integrating more progressive
technology like security surveillance with use of AI analytics it is easy to control and
regulate access in a secured zone or perform the task of monitoring as well as analyze
patterns and trends.
1. The area in which cyber and physical security are joining forces
Even though security convergence cannot be considered as one of the new cyber
or physical security trends 2024, the rapid increase of IoT devices companies’
demand for approaching their security more comprehensively. Today and in the future
of physical security, we predict that there will be an integration of IT and physical
security in the operations of enterprise.
32
When companies merge cybersecurity and physical security divisions and
practices, a number of benefits are to be gained. indeed, the effort leads to the
reduction of duplications, faster response times and better cooperation. This, in turn,
opens the opportunity for more automation in all the platforms thus enhance security
postures throughout the organization.
2. It also speaks to an industry that wants the ability to open doors and access
through touchless technology.
No contact access is one of access control technology trends of 2024. It is being
commonly used in such areas with high flow density as public and commercial
domains for safety and practicality. Most of the touchless access control systems that
are leading the trend today integrate a pre-existing security and safety system with a
touchless solution that does not require any contact or tokens at the door.
In looking at the touchless access control technology trends, 2024 will continue to
see increased adoption in the following areas- This is because access control
requires a user to perform a certain action at a certain distance such as waving a
hand in front of a reader whereas physical signals and motion sensing technology
are improve.
Improved Automated Verifiers – Instead of issues like key card and fob to every
user, business entities opt for mobile credentialing solutions. These are leverage
Smartphone application and close contact technology to enable feature phone
users to open doors that are inclose proximity. Mobile access control as one of the
access control trends in 2024 and one of the key elements of the future access
control market will remain a reliable technology with increased functionalities for
end users and operators.
33
Biometric technology for access control – Biometric access that provides
strategic vision of the future of access control. Biometric technology is
identification through an individual’s physical identification factors such as facial
features, fingerprints and more. Mobile systems can also build on the
morphological biometrics that we employ to initiate our smartphones (FaceID,
fingerprints, etc. ), as another level of protection.
A transition to a touchless system may be capital intensive initially to perform
first-time modifications to conventional control systems; nonetheless, it is quite a
fixture for providing enhanced security in advanced building designs. After this
investment is made, it is cheap and efficient to support access control trends as it is
easy to use and very secure.
3. Remote management and security
Remote security and remote access management are among the key areas that
have revolutionised our security in the recent past. And this phenomenon is also
expected to enter one of the most important physical security and access control
technology trends in 2024.
This access control trend emerged to assist building owners to secure the
buildings even when they are empty thus enabling many businesses to keep their
commercial buildings open while supporting working from home.
The irrecoverable positive impact of remote security in the future of access
control is that organizations adopt a versatile approach to the security, no matter
where the team is located. On this factor of anywhere access, the teams do not need to
comply with the time lost during a critical security incidents. It allows them to change
34
the users’ permissions and door schedules whenever they want them and the changes
are immediate.
Remote door access control is especially useful when granting vendors and
employees’ access to the building, even though the actual person does not need to be
at the site constantly. The only issue here is making sure that remote unlocks are done
by only the right person and for that integrating video and access (which is another
access control trend anticipated to be famous in 2024) assist in eradicating this
weakness.
4. The Security system unification
Elect Schwarz’s Proposal Access control systems have traditionally been
operated independently. However, a brief look to the access control trends for 2024
clearly shows that the future of physical security will belong to integrated systems.
Selecting systems with open, interoperable platforms has gradually become a new
norm for access control and video security while it is starting to spread to visitor and
building management and analytical solutions as well.
Combining the systems’ features, it is possible to build the best of the
technologies in both systems to benefit the consumer while at the same time assists
building managers and owners in maximizing the potential of a building, productivity,
and sustainability.
Integrating video with access control technology enhances control due to
coherent and comprehensive monitoring of a compound. Although, to successfully
implement this 2024 access control trend, it means dealing with providers that will be
providing software that well integrates both functions.
35
Acquiring IT assets developed with an open architecture to integrate with the
applications currently in use and future solutions that may be added subsequently for
the scalability of a firms’ systems. The data collected by full-building integrations can
also be vital in future-proofing operations: monitoring energy usage of a building
based on how many people are in the building, security, to detect when there is
abnormally increased or decreased motion and activity and to predict future
performance trends.
The Best practices in regard to integrated security frameworks implementation and
sustenance
For what purpose do organisations decide to come up with security frameworks?
There are numerous possible causes which are why businesses start their
implementation journey.
For some it is compulsory imposed by customer or supplier requirement for
instance to possess a certain certification like ISO/IEC 27001. For others it could
involve integrating technologies, cultures and working patterns as part of a merger or
acquisition plan and where everyone want to end up as a unified entity.
Regardless of the general reasons behind the implementation, at the base of any
securitisation practice, is the process of trying to bring order to organisations’ systems
of operation such that within the organisation only one model of working practice is
used.
Standardisation therefore results to ‘many business benefits such as improved
security, enhanced productivity, efficient output and of course improved compliance.
The following are the 7 tips for implementing security frameworks:
36
From the elementary measures to be taken before the process of implementation
to the best practices to follow in order to avoid the loss of the gains made by the
security framework are some of top implementation tips as offered by Christoffer and
Julie.
1. Very well, make sure that your objectives of implementation are properly
stated.
Reasons to spur security frameworks implementations will however not be
universal and therefore what you need to do should be something more than the
accreditation.
It is often the easier part of the process to get certified or reach another personal
or organisational objective, for example, make sure your business is GDPR compliant.
Still, doing what is required to adhere to these procedures and processes, can be quite
a challenge. This maintenance prescribes its governance and periodic re-evaluation.
Over time, you will have matters like deviations, a desire to report incidences and
track audits among others.
Unless you have enough motivation to ensure that the substructure and support
systems required for and sustaining your implementation phase are safeguarded and
maintained, it will be difficult to retain the certifications or compliance that you once
earned.
2. Take the high-level activity and make it operational that can easily be
understood
Your framework is going to contain many overall statements or goals which
although necessary, have to be transmitted in a manner that is comprehensible to
employees.
37
For instance, in the statement ‘appropriate controls must be implemented to
support this process’ one can find obvious lack of documents that describe exactly
which actions/controls this employee is supposed to make.
Your team must always be clear on what specific actions need to be taken, or
who is supposed to be contacted during certain risk management situations like
instances where there is a breach, or where a customer demands their data or when a
new supplier is being added to the system, for your security framework to survive.
Christoffer advocates that when rebranding, he would employ a technique that
he tagged “we do what we say and we say what we do” which entails that each
statement is accompanied by activities, roles and responsibility. Spending time to
understand and dissect out the detailed strategies and plans that exist in your high-
level action plan help to alleviate confusion later on and ensure your framework’s
success.
3. Express change in layman terms
Any communication that involves instructions for the employees, needs to be
written, in the language and context understood by the reader.
The legal documents will not make any sense to the employees unless they work
in the legal and compliance department because the documents contain numerous
industry-specific terms and the company’s general goals. Hence, if you desire to
communicate your employees and to encourage them to perform the tasks assigned to
them, documents have to be clear to any of your subordinates, be it an IT specialist or
a customer service representative.
They also have to look like the reader’s every day On the same note, these
documents have to look like the reader’s every day. For instance, explain to them their
38
daily working processes and then explain the risks involved in sending particular
types of emails or taking calls in public places.
What is more, creating understandable, almost didactic-like procedures,
guidelines, and rules will save efforts and help you get your colleagues’ support and
keep the implementation of your security frameworks on track.
4. Also, readers need to stop focusing only on the IT department.
As a result of the participation of systems and technologies, many companies
consider the implementation process as the IT activity and task. Continuing that same
logic, a bottom-up approach is typically implemented with many activities in between
the DPO and the IT sector.
However, when it only takes one employee to high risk your company or cause a
data breach, you must engage everyone across your organisation and your compliance
endeavours as well as your compliance activities or mechanisms must include daily
work and workers. And when your approach for managing risks and compliance
involves staff across the company rather than each department working on its own,
you get the real benefits and the real changes.