Physical Security
PHYSICAL SECURITY 4
Running Head: PHYSICAL SECURITY
Case Study 4
Physical Security
Prepared for Dr. George Trawick
By Anna Papp
CIS 565, Strayer University
August 27, 2017
Security Problems that Cisco Faced
The corporate Security, Technology and Systems (STS) Team manages the physical security for more than two hundred seventy one Cisco facilities in fifty countries worldwide. Their responsibility was to make sure that only those with authorized access have access to these facilities in addition to detecting and responding to all unauthorized entries. Securing and cost-effectively controlling this across the global enterprise is one of the primary challenges for Cisco. Cisco needed to address physical security management problems such as providing one access card for all needs that is unique to each user, though also administering general access to the global user population of more than forty six thousand employees and contractors; managing the physical security system in all fifty countries worldwide despite having limited resources; and managing the global integration, service, and support issues for all systems. They needed a system to provide on-demand, real-time information from any alarm system at any location worldwide.
The earlier security model unfortunately did not include a network-based control system. Employees who were traveling to other sites faced the problem of not being able to gain entry unless it was manually programmed into that sites local badge authorization database. To remotely monitor the sensors used at the other sites forced the STS team to lease individual (and expensive) phone or leased lines to carry those signals back to the main security operations center. Lack of connectivity limited video surveillance cameras to recording information for later viewing, rather than the team being alerted of a security breach. Due to the security systems being isolated from one another, a dedication site administrator was required at each facility.
Security systems during that time had been deployed with little or no managerial oversight, with the exception of two main campuses located in the United States. The ability to monitor systems remotely was nonexistent. Once a system had been installed, facility administrators were then required to administer system databases with no corporate consistency. Maintaining these systems and databases required skills outside of the expertise of the security personnel. The security staff also had to manage service and system integration support. They needed skilled equipment-maintenance people at every location to support the system, and skilled database systems administrators (DBAs) to support the database systems.
Challenges Faced by Cisco
Cisco’s STS team needed to define and develop a corporate-security philosophy. This was to enable higher levels of employee productivity because it would make it easier for employees to work at any time of the day or night while security is being maintained. Contractors, vendors, and other temporary employees would be restricted depending on their location or the time if day that they would need to have access to a facility. In addition to this, there was a need in defining and developing a corporate physical-security design standard. The team saw the need to develop a security system for the entire enterprise that had centralized management. Meaning data distribution and reconciliation would take place in regional security servers. The plan was to use corporate IP WAN to reduce networking costs and to not impact the other corporate traffic. The final challenge was to build a system that reached globally. They needed to find a solution to support the large number of locations that they had worldwide and implement database administrators that would monitor and maintain the centralized database servers.
Compare Cisco to Borsa Istanbul
Borsa Istanbul was established at the end of 2012 to bring together three existing financial exchanges in Istanbul. They served one hundred fifty to two hundred twenty brokerage houses and had up to twelve hundred people connecting to its LAN every day. Cisco’s problem was with their infrastructure that involved physical access to their company where Borsa Istanbul needed a way to ensure their systems were able to handle the increased traffic and network speeds, as well as to quickly identify and fix any problems that appeared. They also run a range of specialized financial applications and is developing its own software, as well as planning to implement NASDAQ OMX’s market technologies for trading, clearing, market surveillance and risk management.
Due to the nature of the business, there will be heavy traffic that exchanges information of a highly secure and time-sensitive nature. All companies, Istanbul Stock Exchange, Gold Exchange and the Derivatives Exchange are part of the stock exchange. Borsa Istanbul not only had to focus on how they were going to join it all together but also how they were going to monitor network performance or troubleshoot any problems to avoid anything affecting trading on the exchange.