Bridging The Great Divide: The Convergence Of Physical And Logical Security

e of security is changing dramatically. Manycritical and emergency situations and achieve
organizations are now looking to bridge physical andcompliance with regulations, such as the U.S. Homeland
logical access systems for unified enterprise securitySecurity Presidential Directive -12 (HSPD-12) or Federal
management, and as these companies are realizingInformation Processing Standard (FIPS). HSPD-12,
the benefits of a converged solution, the industry iswhich mandates a common identification standard for
beginning to redefine the role of security.U.S. federal employees and contractors, was issued
All organizations need to protect their corporateby the U.S. Executive Office of the White House in
assets — whether it’s preventing the2004. The convergence of these two technologies
theft of office equipment, providing a safe environmentprovides the two-factor authentication that ensures
for employees and their belongings, or keeping hackerscompliance with these regulations.
and industrial saboteurs from wreaking havoc withWhen physical and logical access security
networks, applications and databases. Yet, becausecomponents work together, organizations can use
physical and logical security has traditionally beenthem to complement and reinforce one another. For
handled by separate organizations and technologies,example, a network access policy could be
few companies could envision the benefits from theirestablished that would grant a user logical access to
convergence.applications only if that user had first swiped his or her
Physical and IT security departments have beenemployee badge that day when entering a facility or
operating as distinctive entities for years. Securityrestricted area. Furthermore, companies can grant or
concerns around networks and databases haverefuse network access based on a user’s
caused organizations to ask why physical and logicalphysical location, user role and/or employee status.
security systems cannot work together to shareThis means that all users must physically badge in to
real-time data and strengthen each other.use the organization’s facilities and
As a practical definition, “converged security”network—and cannot access their company’s
refers to the integration of physical access systemsvirtual private network (VPN) while already logged into
and related technologies (such as magnetic cards andthe building. This prevents fraudulent user log-ins, further
readers) with identity management and userraising the protection of each user’s identity and
authentication technologies (such as enterprise singlethe organization as a whole.
sign-on, tokens and proximity cards). This integrationTailgating is a common security problem in which a
enables an organization to establish and manage aperson without an ID badge gains access to a facility
single, consolidated repository of all user authenticationby following closely behind another person who has
credentials and to employ a centralized means forjust swiped his or her badge. With convergence, logical
establish access policies for all physical and logicalaccess security can be set up to alert corporate
resources.security whenever employees who have not swiped
The concept of converging physical and logical accesstheir badges attempt to log onto PCs, thereby
security is not new. It has been around for some time,providing a means to better enforce badge-swipe
but historically, implementation has been a problem.compliance and facilitates the enforcement of
Because physical and logical security systemscompany anti-passback/tailgating building access
traditionally operated in totally independent worlds withpolicies.
no reason to interconnect, convergence has alwaysConvergence provides companies with affordable,
been costly and complex. Various vendors have triedtwo-factor authentication (complex passwords and a
to solve this problem using approaches such assecond form of identification), which is recommended
multifunction cards, pure identity management solutionsby experts as the best protection against unauthorized
and consolidating reporting systems. For a variety ofapplication access. Convergence at the system level
reasons, these efforts have not been successful andenables reuse of the existing card based infrastructure
proved costly and extremely time consuming toand would allow even badges with magnetic stripes to
implement - often taking several years coupled withbe used as the second factor, sparing organizations
major investments. However, an opportunity nowthe cost of additional smart cards, tokens, or biometric
exists for the worlds of physical and logical accessscanning systems while at the same time
security to come together at last.strengthening IT security.
Physical and logical convergence makes it possible forWith the convergence of physical and logical security
organizations to havesystems, organizations have the ability to coordinate
• One identity-based system for managing allresponses to problems and/or emergency situations.
physical and logical access;For example, when employees resign or are
• A unified network policy for both network andterminated, there is often a lag time of days or even
remote access that leverages card status and userweeks between when their physical access rights and
location information from physical access systems;logical access rights are terminated. This situation often
• Tight correlation between building, LAN and remoteresults in disgruntled former employees logging in
VPN access for a tighter security posture;remotely and stealing confidential data. Convergence
• Enforcement of company anti-passback/tailgatingprevents this problem by allowing organizations to
building access policies;terminate physical and logical access privileges
• Exchange of events and alarms from the physicalsimultaneously.
access system to the logical access system;What organizations are ultimately looking for is greater
• An identity-based reporting system for use incontrol over all aspects of their company’s
forensic investigations; andsecurity. Convergence allows organizations to
• A streamlined workflow for creating, deleting andmaximize the security potential of both systems to
modifying user identities from both systemsprotect corporate assets at the while not forcing
simultaneously.dramatic workflow changes on the employees.
With the convergence of physical and logical securityOrganizations of all sizes and types are taking the first,
technologies, organizations now have newpositive steps toward physical and logical access
opportunities to better coordinate security resources insecurity convergence and a more secure future.