Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Training and Certification
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Communications for Continuity Operations

Oracle Resource Center
NEW! Transforming Data Center
Managed Services
Service Oriented Architecture
Training & Simulation
Networking Communications
Security Directives and Compliance
Data Center Virtualization
Air Force ELSG Contract Guide

More >>



Latest News
ADVERTISEMENT





 

Two converging worlds: Cyber and physical security

By Dibya Sarkar
Published on December 12, 2004

Comment

Click here to comment on this article


Newsletters

You might also be interested in these FCW newsletters:

Daily
Security

To learn more, click here.


Not long ago, government agencies and other organizations had two sets of security guards: one group protecting buildings, offices, labs and other physical structures; the other monitoring networks for hackers and other cybercriminals. But that's changing. More and more, companies, government agencies and other organizations are looking holistically at their security management and practices.

This convergence of cyber and physical security, in part, has spawned the Open Security Exchange, a consortium of private-sector technology companies developing vendor-neutral interoperability specifications and best practices guidelines.

"There is no such thing as security if they're separate; one is increasingly dependent on the other," said Laurie Aron, OSE's vice chairwoman and strategic sales director at Software House. She said lines between cyber and physical security are blurring.

Eric Maurice, director of Computer Associate's ETrust Security Solutions and OSE's executive director, said "convergence" has two meanings. The first is technical convergence. Traditionally, physical security systems such as access control panels or surveillance cameras were operated on dedicated networks. But in recent years, organizations have begun to run physical security systems on their IP networks.

But running nontraditional technologies on such networks has raised concerns about performance and security.

"I'm aware of a few incidents where companies were putting in place a digital video recording system without changing the password," Maurice said. "Traditionally, you talk about hacking and spying as something very abstract. But, in this particular case, I can look at you working at your desk, and you won't even know it."

The second meaning of convergence refers to security disciplines. Security needs to be viewed in a strategic manner, Maurice said, because the majority of computer crimes are committed by individuals such as disgruntled employees or contractors who physically access unauthorized systems.

OSE officials are working with industry leaders to provide standards that allow physical and IT security systems to share information, something that is difficult to achieve, Maurice said.

Among the benefits of convergence, experts say, are consolidated security management and response, better detection and tracking, simplified forensics and consistent policies across the enterprise. Security tug of war Organizations have traditionally spent more on IT security than on securing facilities, experts say. They also cite cultural problems affecting the two security groups, among them a lack of collaboration, coordination and response.


upcoming event

Green Computing Summit, Ronald Reagan Building, Washington, DC
December 2 - December 3, 2008

Trusted Internet Connection and the Comprehensive National Cyber Security Initiative, The Willard Intercontinental Hotel, Washington, DC
December 4, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email