Physical Security Controls
To document the importance of physical security controls as it relates to the massive pervasiveness of online theft and cyber crime
Background information on the identification and authentication of people.
With the advent of the internet it is often very difficult to properly identify the individual in which business is conducted with. With the extreme ease of the internet comes the secrecy of potential criminal lurking through the shadows. Identification and authentication therefore have profound impacts on how to better protect assets from criminals.
The importance of information systems security and how it relates to globalization
Information systems, particularly those that store personal information, often are very senstivie to criminal activity. Therefore physical store techniques mandate that sensitivity information be locked away and under intense surveillance. Aspects such as disposable drives, printers and workstations should also be considered.
C. Brief overview of the paper.
i. The remainder of this paper will discuss proper surveillance, key security features, infrastructure, and proper authentication (Merkow, 2006)
II. SURVEILLANCE
A. Definition and identification of smart cards
i. Memory Cards- Locking the door to the server room is a good first step, but someone could break in, or someone who has authorized access could misuse that authority. You need a way to know who goes in and out and when. A log book for signing in and out is the most elemental way to accomplish this, but it has a lot of drawbacks. A person with malicious intent is likely to just bypass it. A better solution than the log book is an authentication system incorporated into the locking devices, so that a smart card, token, or biometric scan is required to unlock the doors, and a record is made of the identity of each person who enters. (Shelfer, & Procaccino, 2002).
ii. Processing-enabled Cards- Processing-enabled cards are smart cards that include a semiconductor chip. The semiconductor and memory allows the card to perform cryptographic operations. Additionally, processing-enabled cards can reliably and securely store data for up to ten years. This aspect is important for physical security purposes because records are kept of those who use a facility, enter a facility, and exit a facility. It will therefore become easier to detect potential candidates of theft (Shelfer, & Procaccino, 2002).
B. Benefits of the use of Surveillance
i. Deterrent- In many instance surveillance is the best form of security control as it acts as a deterrent to potential criminals. It also reduces the likelihood that criminals will commit criminal acts knowing the company is observing their behavior. Furthermore surveillance can be used as a proactive measure to better predict criminal activity before it occurs
ii. Record Keeping- surveillance through the use of memory cards mentioned above can store vast amounts of information regarding those who have entered or exiting a particular facility. This allows the overall investigation to be conducted more seamlessly as law enforcement is better able to pinpoint threats
C. Potential Uses of Surveillance
i. Systemically important industry's
Surveillance is critical in many sensitive industries. These systemic industries have great implications for society and therefore should warrant the use of surveillance. The direct and indirect costs associated with theft have become staggering. Particularly for cyber theft, attacks can come from within or without the company. Just last week (May 6-12) $45 million was stole through ATM networks around the world. Surveillance allows these coordinated activities to be spotted and acted upon promptly. Smart cards can be used to help curtail the costs of identity theft, while providing a secure means of storing a person's financial data. This is yet another means of physical controls of sensitive information (Sullivan, 2008).
ii. Medical industry
Medical tourism is growing in its importance. As such patient data is stored in various capacities throughout the world. As such the medical industry, particularly due to the sensitivity of information prevailing in their systems, must use surveillance to monitor activity. The use of both surveillance and smart cards could allow for the much needed distributed storage solution (Chan, 2003).
iii. Identification and Authentication
Knowing who is using protecting systems is the most important aspect of physical security. Smart card can be used to store the credentials of users for identification and authentication purpose. When a user needs to be authenticated to a system they simply need to present their smart card to gain access (Shelfer, & Procaccino, 2002).
III. INFRASTRUCTURE
A. Locks, rack mount serves, limited access, and distribution of power
i. The infrastructure within a facility is key to protect the assets of those of the company or firm. Proper locks through the use of smart...
SECURITY and PRIVACY - the following security and privacy requirements apply: The Office does not accept responsibility for the privacy, confidentiality or security of data or information not generated by this office or transmitted from external sources into the system. The Office does not accept responsibility for loss, corruption, misdirection or delays in transmission of personal data through the system. Users are responsible for the integrity of all data and
Security for Networks With Internet Access The continual process of enterprise risk management (ERM) has become an integral component of successful organizational assessment, because the process of accurately identifying various risk factors, and interpreting their potential advantages and disadvantages, ensures that a business remains capable of anticipating and addressing internal and external contingencies. The following ERM implementation plan for the security of internet-accessible networks is intended to provide a navigable framework
To offer an information security awareness training curriculum framework to promote consistency across government (15). Security awareness is needed to ensure the overall security of the information infrastructure. Security awareness programs is the can help organizations communicate their security information policies, as well as tips for users, to help keep systems secure, and the practices the entire organization should be utilizing. However, as Kolb and Abdullah reiterate, "security awareness is not
They need to know what their responsibilities are not only as individuals but also as team members and corporate employees. David cites an excerpt from a corporate security document that illustrates his point: "A security policy serves many functions. It is a central document that describes in detail acceptable network activity and penalties for misuse. A security policy also provides a forum for identifying and clarifying security goals and
This researcher rejects the existence of online communities because computer mediated group discussions cannot possibly meet this definition. Weinreich's view is that anyone with even a basic knowledge of sociology understands that information exchange in no way constitutes a community. For a cyber-place with an associated computer mediated group to be labeled as a virtual settlement it is necessary for it to meet a minimum set of conditions. These are:
Security Information is the Power. The importance of collecting, storing, processing and communicating the relevant information presently is viewed as crucial in order to achieve success in almost all the fields be it business firms, individuals or organizations. An integrated set of components assisting collection, store, process and communication of information is termed as information system. Increasing dependence on information systems is noticed in order to excel in the respective fields
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now