Security From Doorway To Desktop: Tying Together Physical Access Systems And It Networks

y’s world, the role of security is changingGramm-Leach-Bliley (GLB), and Sarbanes-Oxley
dramatically. As technological capabilities have finally(SOX)
caught up with security theory, many organizations areVarious vendors have tried to solve the problem using
now looking to bridge building and network accessconventional approaches. These include multifunction
systems for unified enterprise security management.cards, identity management solutions, and consolidating
Despite their common purpose, physical access andreporting systems. However, these methods have
logical access technologies exist in parallel worlds.been unsuccessful for a couple of reasons. They
Physical access technologies, such as building securityproved to be very costly and extremely time
systems and employee access cards, are controlledconsuming to implement - often taking several years. In
by the corporate security department. Applicationaddition, they failed to offer a comprehensive
passwords and firewalls are the domain of the ITconverged solution that is unable to prevent security
department. Each group’s respective networks,violations from happening in the future or prevent the
technology paths, and user interfaces are completelyuse of a card by an unauthorized person.
separate.Physical and logical convergence enables organizations
That situation is changing, however, as physical andto create a single, converged security policy for use
logical security concerns mount and persistent issuesacross systems across the company. Taking
such as inadequate security policy and enforcementconverged security a step further than simply
continue. Organizations are now asking why physicalleveraging the building access keycard for network
and logical security systems cannot work together toaccess, organizations are gaining the ability to grant or
share data and strengthen each other. Additionally, it isrefuse network access based on a user’s
now possible for companies to successfully merge thephysical location, user role and/or employee status.
two culturally and technologically disparate worlds ofThis means that users must physically sign-in to use
building access and network access without newthe organization’s facilities and network—and
investments.cannot access their company’s VPN while
For years, physical access security systems acted asalready logged into the building. This prevents
the first line of defense against unauthorized logicalredundant user log-ins, further raising the protection of
access. After all, if a person could not gain entry to aeach user’s identity and the organization as a
corporate building, that person could not gainwhole.
unauthorized access to corporate applications andLocation-based authentication ensures that IT
data.resources are being accessed and utilized by
That changed with the advent of remote access.authorized users as determined by where they should
Remote access via VPNs, the Web, and wirelessbe, and eliminates the potential for redundant
networking has opened up IT resources that can noquestionable user log-ins from different locations.
longer be protected by physical access systemsTying together physical and IT security effectively not
alone. Companies are gaining a more firm securityonly consolidates user credentials from disparate
posture by tightly associating building, LAN and VPNnetwork, remote access, application and physical
access.access accounts, but also provides a single point for
With the convergence of physical and logical securityadministrators to instantly lock-out user access across
technologies, organizations now have newboth physical and logical assets. With this approach,
opportunities to:events and alarms from physical security access
• Strengthen and gain greater control over totalsystems are incorporated into network access
securitydecisions, providing a finer layer of authentication for
• Add a practical and affordable secondclosing security holes and providing organizations with
authentication factorbroader monitoring and reporting capabilities in order to
• Better enforce both physical and logical securitybetter demonstrate regulatory compliance.
policiesWhen physical and logical access security
• Enable the enforcement of companycomponents work together, companies use them to
anti-passback/tailgating building access policiescomplement and reinforce one another. Convergence
• Better coordinate security resources in critical andallows organizations to manage all forms of security
emergency situations; and achieve compliance withunder a single umbrella for maximum control. Security,
regulations, such as the U.S. Homeland Securityalong with all types of risk, both operation and
Presidential Directive -12 (HSPD-12), Federal Informationcorporate, are now being done better and ultimately
Processing Standard 201 (FIPS-201), Health Insurancemore cost effectively.
Portability and Accountability (HIPAA),