The Future of Physical Security
Total Page:16
File Type:pdf, Size:1020Kb
“The convergence between physical and cyber security affects not just our daily lives but also our nation’s security. In their new book, Bill Crowell, Dan Dunkel, Brian Contos, and Colby DeRodeff tap into their wealth of public and private sector experience to explain how we should manage risk in an ever converging world.—Roger Cressey, former Chief of Staff, White House Critical Infrastructure Protection Board, and NBC News terrorism analyst “Take advantage of the years in the government and commercial arenas that the authors have, their knowledge of current and emerging technologies, and their insight on other’s successes and failures. There is no other text available which packs such comprehensive and useful knowledge into a single volume – this book will be on your desk, not your bookshelf.”—Dr. Jim Jones, CISSP,Senior Scientist, SAIC, and Assistant Professor, Ferris State University “In my opinion the authors do an exceptional job explaining the need for more comprehensive approaches to achieving operational risk management within business and governmental organizations. The authors clearly demonstrate why convergence of physical and logical security is a natural evolution with significant advantages to all participants… I believe that the book is a must read for anyone responsible for enabling security solutions in complex organizations.”–Dr. Larry Ponemon, Chairman and Founder of the Ponemon Institute “The consistent and persistent message in this book is needed and well presented - Corporate executives must understand and implement converged security or get left behind.This message is presented using a nice balance of historical exam- ples and contemporary business issues and case studies. The authors make their points by presenting information from the public, private, and government per- spectives. Thus, this book is appropriate for any leader in the field of security (physical or IT). It is also an appropriate read for those in the legal, HR, and PR worlds.”—Dr.Terry Gudaitis, Cyber Intelligence Director, Cyveillance i “Physical & Logical Security Convergence takes an in-depth look at how the issue of convergence is impacting enterprise security,particularly from the insider threat perspective. Solutions are commonly a reaction that lag behind evolving threats, be they technology or management focused. In the new world, we need bottom up approaches that converge solutions that keep up with evolution. This book is a primer for convergence in an evolving risk environment.”—Dr. Bruce Gabrielson, NCE,Associate, Booz Allen Hamilton “The convergence of physical and information security is a vital development in the corporate world and a critical success factor for all organizations.The authors do an outstanding job exploring the roots of convergence, as well as the techno- logical, political and logistical issues involved in successfully merging the silos of security.More important, they explore the very real opportunities and advantages that arise from security convergence, and illustrate their concepts and prescrip- tions with practical advice from the real world.This book will be an invaluable guide to anyone involved in guiding security convergence or simply wanting to understand the power and benefits of convergence.”—John Gallant, Editorial Director, Network World “Filled with historical anecdotes and interesting facts, “Physical & Logical Convergence” is a comprehensive definition of converged security threats and considerations. In this day and age, convergence has become a business reality requiring organizations to realign their security and compliance remediation efforts. The authors capture the key aspects of planning for, design and addressing security aspects of this new technology landscape. As expected from an ESM per- spective, also provided is a conceptual overview of addressing compliance audit and monitoring requirements of converged components.”—Mark Fernandes, Senior Manager, Deloitte ii Physical and Logical Security POWERED BY ENTERPRISE SECURITY MANAGEMENT Brian T. Contos CISSP William P. Crowell Former Deputy Director, NSA Colby DeRodeff GCIA, GCNA Dan Dunkel New Era Associates FOREWORD Dr. Eric Cole Technical Editor BY REGIS McKENNA Elsevier, Inc., the author(s), and any person or firm involved in the writing, editing, or production (collec- tively “Makers”) of this book (“the Work”) do not guarantee or warrant the results to be obtained from the Work. There is no guarantee of any kind, expressed or implied, regarding the Work or its contents.The Work is sold AS IS and WITHOUT WARRANTY.You may have other legal rights, which vary from state to state. In no event will Makers be liable to you for damages, including any loss of profits, lost savings, or other incidental or consequential damages arising out from the Work or its contents. Because some states do not allow the exclusion or limitation of liability for consequential or incidental damages, the above limitation may not apply to you. You should always use reasonable care, including backup and other appropriate precautions, when working with computers, networks, data, and files. Syngress Media®, Syngress®,“Career Advancement Through Skill Enhancement®,”“Ask the Author UPDATE®,” and “Hack Proofing®,” are registered trademarks of Elsevier, Inc.“Syngress:The Definition of a Serious Security Library”™,“Mission Critical™,” and “The Only Way to Stop a Hacker is to Think Like One™” are trademarks of Elsevier, Inc. Brands and product names mentioned in this book are trade- marks or service marks of their respective companies. KEY SERIAL NUMBER 001 HJIRTCV764 002 PO9873D5FG 003 829KM8NJH2 004 BPOQ48722D 005 CVPLQ6WQ23 006 VBP965T5T5 007 HJJJ863WD3E 008 2987GVTWMK 009 629MP5SDJT 010 IMWQ295T6T PUBLISHED BY Syngress Publishing, Inc. Elsevier, Inc. 30 Corporate Drive Burlington, MA 01803 Physical and Logical Security Convergence: Powered By Enterprise Security Management Copyright © 2007 by Elsevier, Inc.All rights reserved. Printed in the United States of America. Except as permitted under the Copyright Act of 1976, no part of this publication may be reproduced or distributed in any form or by any means, or stored in a database or retrieval system, without the prior written per- mission of the publisher, with the exception that the program listings may be entered, stored, and executed in a computer system, but they may not be reproduced for publication. Printed in the United States of America 1 2 3 4 5 6 7 8 9 0 ISBN: 978-1-59749-122-8 Publisher:Amorette Pedersen Managing Editor:Andrew Williams Production Manager: Brandy Lilly Page Layout and Art: Patricia Lupien Technical Editor: Dr. Eric Cole Copy Editor:Audrey Doyle Cover Designer: Michael Kavish Indexer: Nara Wood For information on rights, translations, and bulk sales, contact Matt Pedersen, Commercial Sales Director and Rights, at Syngress Publishing; email [email protected]. Acknowledgments Brian Contos Dedications To the beautiful women in my life who gave me the inspiration to author yet another book: my amazing wife Monica-Tiffany, our incredible daughters Zoey and Athena, my patient mother Marie and supportive sisters Karrie and Tracy. And to my father Tom who instilled in me commitment and tenacity. Illegitimis nil carborundum Acknowledgements It’s always hard to single people out for thanks when you write a book. Most of my knowledge over the last decade comes from combined experiences with var- ious individuals and organizations. Even the concept of physical and logical con- vergence itself was a culmination of conversations with dozens of brilliant minds in the private and public sector, academia, and the media. Only after conver- gence displayed such obvious and extensive support from these individuals did I finally convince myself that a book had to be written. While I can’t possibly mention everyone, some individuals went well beyond an exchange of ideas in their contribution. Some actually reviewed sundry versions of the manuscript and provided expert insight. For their outstanding commitment I would like to thank all the book reviewers.Their input was invaluable and helped shape this book. I would also like to give special thanks to Dr. Eric Cole for providing world-class feedback, technical analysis, sanity checks and comic relief. To all the individuals at ArcSight that in one way or another helped make this book a reality: Robert Shaw,Tom Reilly, Kevin Mosher, Larry Lunetta, Jill Kyte, Cynthia Hulton, and Dave Anderson.To be fair, the entire ArcSight team throughout the Americas, Europe and Asia Pacific should be thanked. v I would like to give special thanks to ArcSight’s CTO and Executive Vice President of Research and Development Hugh Njemanze. Hugh has not only provided valuable feedback for both of my books to date but has become a mentor and confidant over the years. Finally, I’d be remiss if I didn’t acknowledge my co-authors Bill, Dan and Colby for all their hard work and dedication. William P. Crowell Dedication To my wonderful wife, Judy, who endures all of my endeavors with love and support, and who fills all of my days with fun and the inspiration to do more. Acknowledgements Many people have contributed to the developing knowledge base on the con- vergence of physical and logical security and to my own understanding of where convergence is going and why. In 1998, shortly after being named CEO of Cylink Corp., Regis McKenna, one of Cylink’s Directors began talking to me about the move to IP based video services and the role that TCP/IP would play as the basic infrastructure for moving security information from video cameras to users. He envisioned a whole new way in which retail stores and enterprise facilities would monitor video security services and a way for the cost of secu- rity to be reduced. He had just done a restart of a small streaming video soft- ware company that he had named Broadware Technologies. Regis asked me to join the board of Broadware and my trek into the world of video surveillance and physical security began. Interestingly, the Chairman of Cylink Corporation, Leo Guthart, was the Vice Chairman of Pittway Corporation and President of Ademco as well as having been a Director at Cylink for 18 years.