Showing posts with label office security. Show all posts
Showing posts with label office security. Show all posts

8.26.2008

First Biometric Facial Recognition Security System Using RFID Technology Eyes Canadian Market

[08/22/08] @ MoreRFID.com

RFID ProSolutions, Canadian leaders in RFID technology consulting and engineering, and American RFID Solutions, an industry-recognized leading manufacturer and solution provider, have announced a strategic reseller agreement for the distribution of TES, Trusted eSentry Security, a new, innovative biometric facial recognition system in Canada.

TES is a biometric/RFID security system that allows for the automatic identification of individuals using a combination of facial recognition and HF or UHF RFID technology (access cards).

"The ID cards are already used to control access to restricted areas but by adding a second reading of distinctive authenticity through biometric recognition; we've taken security to new heights," said Harold Clampitt, CEO & Founder of American RFID Solutions. "And this is the level of protection confidential information, valuable goods and sensitive environments require."

"The beauty of the system is that there is no central data base that can cause accusations of copying or stealing information," stated Andre Lacaille, President of RFID ProSolutions. "Systems that require prints are known for leaving evidence behind because of the physical contact that is required and therefore the information can be copied."

The system was recognized earlier this year as a Best in Show finalist for the RFID Journal Awards in Las Vegas and has a read rate of 99.999999% which makes this system one of the most secure in the world. The system works independently or through a network to interface with existing systems to form an increased secured perimeter.

"We are extremely excited about introducing this system to Canadian organizations and security integrators; this is an important addition to our portfolio of solutions" says Jebb Nucci, Vice President of Operations for RFID ProSolutions.

About RFID ProSolutions

RFID ProSolutions, a division of ProAction Management Group, offers their services in needs analysis, process design, solution selection and development, implementation and change management support. Specialized in RFID technology, RFID ProSolutions is a project management and solution-driven firm that focuses entirely on bringing the best possible products and the most innovative solutions to meet their customer's business needs.

About American RFID Solutions

American RFID Solutions is the developer of the Trusted eSentry Security System, TrackStar and eDOTS, and offers turnkey solutions, consulting and products in the areas of active, passive, RTLS, near field and far field RFID technologies. http://americanRFIDsolutions.com

8.11.2008

The 9 Things You Should Know as a Security Director

Writer Christopher J. Wetzel and online magazine SecuritySolutions.com, part of Access Control & Security Systems, had an excellent article in their July 2008 print and web edition that details the nine major points any security director and/or integrator worth their salt should know about the industry.

http://securitysolutions.com/enduser/enterprisecorporate/rules_security_integration/

With rapidly changing trends and fundamentals, it's best to keep up with what you need to know as a security director for a firm, and with security and the company network becoming symbiotic and security becoming more important to all aspects of business and life, you don't want to waste time figuring it out. The 9 points bulleted are:
  1. Get a security firm that is knowledgeable of computer networking.
  2. IT and security directors should understand each other's model.
  3. Let (or make) your IT director comfortable with security hardware.
  4. Security and IT directors should partner together.
  5. As an integrator, expect to compete with other ROI initiatives.
  6. Software is the new hardware.
  7. Physically test new designs and ideas.
  8. Don't depend solely on technology. Merge the physical and the tech.
  9. An integrator is an integrator, not 3 or 23.

6.12.2008

There’s Value In Integrated Security

From Security Products Online

By Marleah Blades · June 3, 2008

When Mike Howard became director of corporate security for Microsoft in 2003, he had to upgrade the company’s global security monitoring hub.

Microsoft wanted effective, integrated security and life safety monitoring -- watching cameras and access control events, performing dispatch, enabling seamless emergency response and continuity -- to protect corporate assets and nearly 80,000 employees around the world.

“As we started to do some due diligence into the center,” Howard says, “we realized that it was made up of a bunch of proprietary systems that didn’t integrate well with each other and were not scalable. In terms of real global presence, it was global in name only.”

The three Global Security Operations Centers that Howard and his global security team have worked for the past three years to develop -- one at Microsoft headquarters in Redmond, Wash., one at the Thames Valley campus in the United Kingdom and one at the Hyderabad, India, campus -- are based on a variety of Microsoft and third -- party applications that integrate with Microsoft products, backed by a technical infrastructure from Lenel Systems International. The GSOCs have built -- in interoperability and redundancy, so if one center goes down, all functions automatically transfer to another campus. Operators can easily pull up and view every camera location at each connected campus, and events can be monitored from anywhere.

Many companies won’t have the capital or technology available to create a system this elaborate to monitor remote offices or locations. Yet the lessons learned from this project apply to security for companies of all types and sizes.

Use technology as a force multiplier. “For smaller companies and for us, the idea is to leverage personnel in strategic hubs and use technology as a force multiplier,” Howard says. “So instead of, for example, having two or three guards in Dublin, you have remote monitoring via cameras that give you the same views of entrances and exits and garages without having to have personnel there.”

Howard notes that the GSOCs have allowed Microsoft to reduce the guard force at one U.K. campus from four to one, and they also were able to give the old monitoring room to one of the business units for other uses.

Evangelize security. “Our team has worked hard to get senior leadership support for the GSOCs,” Howard says. “The first part was just to acquaint senior management with what we’re doing here in global security and our strategy. To a lot of people five or six years ago, we were the guys who ran around in uniforms on campus. There was no knowledge of our investigations, threat analysis, handling of international events, etc.”

After the team briefed the managers on the security program, they focused on the inadequacies of the current monitoring center.

“We wouldn’t have been able to do this if we hadn’t gotten to senior leaders and been very open about the gaps,” says Howard, who took managers to the center to see the issues for themselves. “We were at a parking garage level, the room was very small, and I could take them around to see bundles of cables spliced together and stacks and stacks of servers that were running out of space. Once they saw that, it hit.”

Tie new projects to business value. A security leader will more easily gain support for any big project if he or she can show its business value -- not just how it may improve security, safety and productivity, but also, where possible, how it may be used by other groups to improve efficiencies or create new opportunities. Because the Microsoft GSOCs are built on Microsoft applications, the global security team works with

Microsoft’s sales and marketing departments to perform demonstrations for potential customers who might be interested in similar technologies.

“A typical example involves a scenario in which an earthquake in Redmond shuts down the operations center,” Howard says. “We’ll turn the lights off for our viewers and shut down the computers, and we move load sharing from Redmond to the United Kingdom. Then there is a fictional employee here on campus who can’t get out of his office. We are able to show that the U.K. center can see every camera view on our campus and can dispatch responders in Redmond to take care of that situation.”

These demonstrations make security more than a cost center.

“We’re contributing to the bottom line by influencing revenue, bringing in potential clients and having technology keep employees safe and maximize use of limited manpower,” Howard says.

About the author
Marleah Blades
Marleah Blades is senior editor for the Security Executive Council, an international professional membership organization for leading senior security executives spanning all industries, both the public and private sectors, and the globe. For more information about the council, visit http://www.SecurityExecutiveCouncil.com/?sourceCode=netcentric.

Safe and Risk-Managed

From Security Products Online
By Kevin McDonald · June 2008

While every individual and organization that provides security products or services will have their spin on what security is and how to achieve the desired level, the truth is, security is essentially an unachievable outcome. A common definition of security is, “freedom from danger, fear and anxiety.” Security defined as such is, therefore, unattainable. Anyone who truly understands security knows this, and understands that security is actually a type of risk management. What this means in practice, is that security is all about fear and anxiety and managing levels of fear of danger that are acceptable to the organization.

The day you are free of at least some measure of fear and anxiety is the day you should retire because you’ve lost your core purpose. This is ironic, because many executives and security professionals will actually resist any attempt to introduce fear, uncertainty and doubt in the process of proposing the need for security remediation; or as I insist it should always be referred to, “Security Risk Management” or (SRM). If you are not scared, you are either naive or in denial.

Because human beings are responsible for acts and conditions that threaten security, security in the purest sense is impossible. In fact, it is the involvement of human beings in all things that perpetually assures insecurity. With human involvement come issues of intellectual competition, lack of education, inevitable error, injection of personality, potential acts of ignorance, laziness, retribution and unintended consequences. Whether you are talking about IT, personal or national security, your primary responsibility is identifying the real risk of loss and its impact. Your secondary responsibility is to balance the risk with the available solutions and financial and personnel resources. SRM must be a continuous and systematic process of analysis of the threats, their relative importance to the organization and then the ability to sustain a program of mitigation and further analysis.

The single biggest challenge in risk management is our human differences. While one individual may look at business SRM from the perspective of intellectual or financial asset protection, another might see it as preservation of reputation and brand. An honest person may see weakness where another sees opportunity. One may be keenly aware of a technical risk, while another is focused on social engineering. An executive sees potential loss of goodwill and customers, while a security manager is worried about his professional reputation and job. Anyway you look at it, risk management is first about a negotiation of priorities.

For some, it is only the existence of enforceable regulations with the threat of punishment that causes the implementation of SRM to become a priority. In the past, SRM was mainly focused on the direct protection of military information, financial assets and closely guarded secrets. The historical driver was business and government survival and a laser focus on keeping the bad guys away from those assets. Today, companies and individuals must guard not only their assets but those of others. This has also created some imbalance toward the protection of soft assets at the expense of other assets. Because the motivations for regulation are always political, one constituent may be served well to the detriment of another. One goal may be in direct contrast to another, and a middle ground must be found.

In recent years we have seen an exponential increase in the legal requirement to protect the hard assets (money, intellectual property and even identity) of those we do business with. I have included identity in hard assets because in the wrong hands, identity can result in significant loss of hard assets. Another aspect that is most challenging to place a value on is privacy and safety. These are what I will call soft assets at risk from emotional assaults like the release of an embarrassing medical history or passport travel records. Interestingly, they are also the assets that are being protected by ever expanding regulations.

So, with all of that said I can hear you asking, “What do I do? Where do I start?” Let’s start with analysis of the risks. To do proper analysis, you first need to win over the stakeholders and decision makers. In the majority of environments that I have consulted, this is a huge barrier to success. The significant disconnect between security practice managers and the boardroom is pervasive. To overcome disconnect, the security practice manager must learn to first listen and executives must be willing to engage those who are responsible for protecting them. The security practice manager must work to understand how the company makes its money, what are its real assets and who or what might do the company harm. Then you must agree on what a potential loss might do and what losses are tolerable. Only after the executives and security practice managers agree on what really matters can there be basis for risk analysis.

I know it’s difficult, but speak the language of the business executive and always be sure that they truly understand your points. You must work to avoid the tendency to speak in technical or industry jargon. This is true in any business category. Don’t rattle off acronyms, complex engineering or other high-level language. Recognize that you are generally talking to people whose education relates to issues of profit and loss, strategy, resource management and other broad-form business concepts. If you try to bowl them over with your intellect, or the-sky-is-falling theories, you may end up with an executive who thinks you are insulting them. In your negotiation, be sure to accurately identify the ways and reasons a risk is being introduced and balance that with the potential exposure. If a sales person needs Internet access to do their job, barring him from going online is not an option. If they don’t need it, the risk of giving that sales person Internet access, may well outweigh the desire to have it. Don’t make these decisions in a vacuum. If you go too far down the road without understanding the impact, you may find your whole program unraveling.

Once you have agreed on what is at risk, the level of importance of each asset and how much loss is tolerable you can begin to identify a program of Security Practice Management. Start with a calculation of the potential losses, then add in what you believe would be covered by insurance and other liability management instruments, and find your potential hard-dollar exposure. Don’t forget lawsuits, loss of goodwill, trust of clients, etc. Now decide what you are willing to spend, (potential investment budget) and begin allocation of resources by priority. There is never enough money, people or time to cover it all, so be sure that you don’t put money in to a low-priority risk, at the expense of one that can have a major impact. Thin and wide in the world of risk management equals no management at all.

However, even if you install the latest and greatest technology, close the holes in the fence and put locks on your doors there is always some new risk, some new attack technique and some agent that can cause harm. Treat security risk management as a systematic program of constant analysis and disciplined remediation and then buy lots of insurance. Remember at the root of every effective Security Practice Management strategy is understanding how to manage fear and anxiety, and not about totally eliminating them. It’s not about fear mongering, it’s about taking a practical and pragmatic approach to identifying and managing potential exposure.

About the author
Kevin McDonald
Kevin McDonald is executive vice president Alvaka Networks

2.15.2008

A Growing Threat

Reposted from Security Products website article

By John Flaa · January 2008

Critical infrastructures look to ID cards for enhanced protection

In the United States, people encounter a perpetual tradeoff between freedom and security. The nation depends on a complex system of critical infrastructures to maintain a high quality of life and the freedoms enjoyed every day. New threats to security have these organizations taking a second look at their vulnerabilities, however, scrambling to minimize disruption and to maintain the integrity of their operations.

In the past, national security was perceived as the role of government. Today, Department of Homeland Security efforts to protect critical infrastructures from physical attack are a shared responsibility of the public and private sectors, as well as individual citizens.

Prime Targets
Critical infrastructures are generally prepared for natural disasters, which are often predictable days in advance. Terrorist attacks, however, are new and immediate, requiring a different mindset and different levels of preparedness. With proper design, management and operation, organizations can reduce their risks, often without significant investment.

The National Strategy for the Physical Protection of Critical Infrastructures and Key Assets report, published by the Bush administration in 2003, identifies the industry segments and key assets that would disrupt the safety, security or economy of the United States if compromised. They include agriculture and food, water, public health, emergency services, the defense industrial base, telecommunications, energy, transportation, banking and finance, chemicals and hazardous materials, postal and shipping, national monuments and icons, nuclear power plants, dams, government facilities and commercial key assets.

These industry segments are being encouraged by the government to adopt security plans. Some already have a base level of security, but others are just beginning. DHS introduced the national infrastructure protection plan in 2006 to provide structure between public sector and private industry initiatives, but because there are no standards for most utilities, each must determine for itself an effective security program.

Broad Security Solutions
In the past, security meant a combination of guards, guns and gates. Today, organizations seek the broadest possible solution to integrate all elements of an operation, from access control to logical security. In many cases, this starts with a simple ID card.

Access control is often the main reason utilities and critical infrastructures introduce ID card systems. The Wisconsin State Laboratory of Hygiene, a public health and environmental laboratory, performs bioterrorism testing of materials such as anthrax. Prior to Sept. 11, 2001, anyone could enter the building, located in the middle of the University of Wisconsin campus. Now, anyone who needs access to the lab must show an authorized ID card. Ensuring that only legitimate cardholders have access to protected areas enables all employees to enjoy greater freedom.

Transportation is another area that plays a vital role in the U.S. infrastructure, and it was designed to be open and accessible. However, an upset here can cause a ripple effect felt nationwide, so after 9/11, it was the first area to receive increased attention. The FAA required every airport in the United States to revalidate identification cards for all employees, ensuring all of the ID cards used at airports were active and up to date. For Los Angeles International Airport, which saw 67 million passengers that year, this meant creating 44,300 new badges, which were produced in-house by two employees with Fargo Professional series card printers.

Today, the focus has shifted to ports. TWIC is being phased in at 12 high-risk ports throughout the country, starting with enrollment in October at the Port of Wilmington, Del. TWIC cards are tamperresistant biometric credentials for as many as 750,000 employees who need unescorted access to ports and vessels.

DHS set aside $400 million to help fund port security initiatives, including money for the ID cards. While a good start, this ID card is basically a photo ID, indicating that a person has passed a background check. What’s missing is any integration with systems at the port facilities themselves, many of which are operated independently. Most ports are vast and sprawling with multiple access points.

Many have railroads running throughout, adding yet another layer of vulnerability. Many transportation companies operate under tight budgets. For example, Metro Transit, a unit of Minneapolis/St. Paul’s Metropolitan Council, considered cost effectiveness when it bought a printer to produce its ID cards. Bringing inside the production of its 20,000 yearly Metropass cards for bus and light rail transit improved the security of the cards and saved the organization money.

Adding Logical Security
Preventing unwanted and unauthorized entry to buildings and grounds is a primary objective of critical infrastructure security systems, but these organizations also need to protect their internal networks. The growth of the Internet and advances in wireless technology have increased the power, and the vulnerability, of computer networks and IT architectures, leaving data and infrastructures at risk. Today, employees and customers have the necessary tools to damage computer systems or steal individual identities around the clock and from virtually any location. Traditional password systems, which can be stolen, copied or forgotten, are being replaced with sophisticated authentication systems, many of which start with an ID card.

While critical infrastructures have yet to adopt ID cards widely for network security, the trend is moving in this direction. ID cards, especially those with smart card technology, can provide single-use access or administrative control, which is especially appealing to critical infrastructures with expansive facilities or complex IT systems.

Security and privacy often go hand in hand, especially in the healthcare marketplace. HIPAA encourages healthcare facilities to implement electronic systems and mandates that these systems guarantee privacy and security of patient information. As a result, more healthcare organizations are using smart cards, proximity cards and biometrics to secure their computer networks.

The Right Technology
Organizations today can choose from a wide range of ID card technology to fit their security needs, from visual ID cards to those with embedded biometrics. Most choose something in the middle.

Magnetic stripes and bar codes are inexpensive methods of encoding text onto a card and collecting critical data. Magnetic stripes contain digital data, such as access privileges, employment history or background information, that is transferred onto the card by special encoders. A reader translates the data for computer processing, and bar codes provide access to more complete information in a secondary database.

Smart cards use internal microprocessors or memory chips with non-programmable logic to manipulate information—much like a miniature computer. This enables organizations to incorporate multiple applications and functions into one smart card, thus justifying the slightly higher cost.

Many critical infrastructures still have a low level of perceived threat and thus have not adopted the robust security offered by smart cards. They could learn a lesson from how schools have maximized the benefits of these cards, often combining multiple functions onto one card. Students at the 3,200- student Everglades High School in Florida, for example, have been using ID cards for school identification for about 12 years. Four years ago, the staff added a smart chip to its cards, enabling debit card privileges in vending machines, the media center and at a number of other student activities. EHS students can even purchase yearbooks and prom tickets with their ID cards. The goal is to become a cashless campus.

At one New York high school, substitute teachers must carry a smart card containing a microprocessor chip embedded with their Social Security number and certain encrypted security codes. The smart card program is tied into the criminal justice system, providing immediate confirmation of criminal violations. Special attention is paid to individuals with a criminal history.

Critical infrastructures that want to take security programs to another level can add holographic solutions to their ID cards to prevent them from being counterfeited. Options range from economical foilstamped holographic seals to custom holographic overlaminates with hidden micro text, sophisticated flip images that appear to be animated or pseudo color that changes when the card is tilted.

Biometrics represents the ultimate in authentication and, as a result, can be the most expensive addition to ID cards. Iris scans and palm prints are powerful security tools. In a few years, this technology will be more commonplace, but for now, it is used primarily by critical infrastructures threatened by the greatest amount of disruption if attacked. For example, the Department of Defense is matching biometric data stored on its 4 million common access cards with a live image from a biometric sensor.

Responding to Disasters
Critical infrastructures are sometimes better at responding to disaster than preparing for it, and ID cards are an important part of a disaster management program. Following Hurricane Katrina, ID cards were used to credential evacuees and provide them with some form of personal identification, which also helped the Salvation Army maintain security in the temporary shelters. Evacuees also were able to receive their Social Security payments and cash checks.

Often during a disaster, first responders from federal, state and local agencies work together in a single command structure to credential people quickly and authorize access to certain areas. The need for a clear and constant tracking system is critical. The first responder authentication cards, compliant with HSPD-12 and FIPS 201, identify first responders at the scene of an incident, enabling them to move in and out of secured areas. The cards allow physical access into buildings, logical access to networks, incident command and control, and property and firearms accountability.

Preparing for the Unthinkable
Applications exist today for in-house production of ID cards that fit almost any budget. Funding also is available to help offset costs. Having a localized system gives organizations the flexibility needed to create an ID system that is relevant to their facility.

People want to know that critical infrastructures are taking every precaution to preserve the safety and continued operation of this nation. Visible ID cards provide small but tangible assurance.

About the author

John Flaa
John Flaa is the customer knowledge manager at Fargo Electronics.

1.03.2008

Security Benchmarking - A guide to obtaining upper management financial support

Securityinfowatch.com has a good article on on Security Benchmarking in regards to obtaining upper management financial support to advance your security program. It is an article by Sean Ahrens, CPP, CSC, full of some really good tips to all of you security professionals out there struggling to get the financial support for your new security initiatives that you realize is important but management won't write a blank check for.

Security Benchmarking
A guide to obtaining upper management financial support and to advancing your security program

As security professionals, we are continually being asked to do with more with less. As a corporate security professional takes on these new responsibilities, their core organizational offering becomes strained. This article delves into security benchmarking, which can provide another viable means to obtain funding for important security projects, thereby assisting your organization in being “proactive about tomorrow's uncertainties.”

The most important thing that a security professional needs to realize is that the days of walking into an executive's office and getting a blank check are, for the most part, over. Security professionals need to become knowledgeable and proficient in the business etiquette of requesting funds. To do this, a security professional should become familiar with topics including value, cost, risk, and most importantly, their independent evaluation through the business proposal. A good business proposal will indicate the costs compared to risk; and the costs compared to the expected value of the implementation.

Security professionals should also be aware that security risks, from a corporate executive's standpoint, are generally classified as low-impact, low-risk with a high probability. As a result, many executives choose to absorb or transfer these risks, rather than mitigate them. There are few methods to motivate an executive to finance a business proposal for additional funds to support a security management program. Some examples include:

• Codes, Standards and Guidelines — For the most part, as it relates to security, this is not recognized by executives currently. However, this influx takes time and you can expect changes in executive's attitudes as these are continually developed and integrated into the business community.

• Legislative requirements such as Sarbanes-Oxley (SOX), Health Insurance Portability and Accountability Act (HIPAA), etc.

• Current organizational security statistics, calls for assistance, losses through theft, damage, and litigation, etc.

• Benchmarking — Statistical evaluation of like programs within like organizations.

In the absence of internal incident reporting statistics. standards , codes or legislation, many executives are apt to provide funds for a business proposal if you can show a statistical correlation through benchmarking. Benchmarking compares what you want to do with what other organizations are currently doing or planning to do. In many instances, benchmarking your organization will have a greater benefit than statistical incident data.

Individual organizations and their senior management teams are continually comparing themselves to like organizations. From a process and liability standpoint, it is easy to convey that there is liability associated security programs that are delinquent compared to other like organizations being benchmarked. Also, the data presented is more readily verifiable as opposed to security incident data.

The Process

No matter what you are trying to do, ideally, the benchmark process is preceded by an idea that leads into a business proposal. A well-articulated business proposal or white paper backed by reliable, verifiable and quantifiable benchmark statistics, will both assist in validating your opinion to senior management, and also aid in your plan's implementation. A business proposal, at the minimum, must include an executive summary, which will include subsets of the entire proposal, such as:

• The problem statement;

• Methodology;

• Proposed resolution;

• Implementation Plan;

• Impact on budget;

• Return on Investment;

• Return on Investment (ROI) over “x” amount of years;

• Statistical data; and

• Respondents contact information.

The Benchmark

It is important to note that the benchmark is a tool, which substantiates the need for funding to support security management programs. Security professionals need to take into account the costs and the perceived ROI.

An important part of the benchmarking process is to validate and identify to senior management the need for security by comparing your organization to other like organizations. However, before you start your benchmarking process, you should be reasonably sure that the data you collect will validate your business proposal. I have worked with organizations that conducted benchmark analyses only to learn that there was no validation in what they wanted to prove, and that the data collected actually contradicted their assumptions. An unsubstantiated benchmark wastes a lot of time and the data cannot be released.

A benchmark, if correctly implemented, should clearly identify synergies and consistencies, in the areas you wish to compare like organizations or business units of related companies. Typically, security professionals will know that they have a need for benchmarking, but are unsure what they want to learn. The best method for vetting this would be an open and collaborative staff white board session. During this white board process, a multitude of topics and ideas can be expressed.

The second part is to validate and score all available topics for inclusion into a potential question pool. One suggestion is to associate each question to a rating on a scale of 1-10. Only questions in the 7-10 range should be selected for final inclusion into the development of the benchmark.

Once the question pool has been scored, you may have to further vet this process and narrow the question pool. The benchmarking process must not be qualitative, that is, in the form of open-ended questions such as: describe your organizational structure; to who do you report; and what types of security are in use. Questions, no matter how they are administered, must be quantitative and focused, which is easily achieved by providing multiple-choice answers. By implementing a quantitative process, there will be a clearer and more defined statistical correlation with the items that you wish to benchmark, validate and present to upper management.

Creating a Survey

Once you have the questions, you need to determine the depth of your benchmark. Clearly, whenever applicable, it is important to seek out like organizations, which are commensurate in staffing and geography. It is not necessary for you to obtain 50 or 60 respondents. Ideally, your respondents should be chosen using sources that identify competitors — which executives can relate to and will want to outpace. In a hypothetical scenario, showing an executive that 5 out of 6 competitors have selected digital video recorders will carry more weight than simply asking to deploy a DVR.

Consider how the survey will be administered — will it be on paper, online or via phone? In some instances, certain types of businesses, such as banks, may elect not to participate in a blind online survey. In these cases, allow plenty of time for a telephone interview. Typically, the most cost-effective route is to use a semi-free service such as SurveyMonkey.com. However, the best method to guarantee results for your benchmark will be through time-intensive phone calls and interviews.

A byproduct of the phone interviews is networking and relationship-building with organizations that are most likely dealing with the same issues. Timing is also critical to your survey, and should be considered throughout the administration of the benchmark. Avoid the holidays and end-of-fiscal year because like you, your respondents will be busy and less likely to participate.

The quantity of questions is also very important — the fewer the amount of questions, the more likely you will obtain responses. When faced with an extremely long questionnaire that cannot be reduced or vetted any further, identify leverage for the participant to take the survey, including free gifts, such as a gift card, or offering access to the final results of the benchmarking study.

Obviously, the number of respondents will determine the budget, but leverage can be found in networking and other avenues.

Consider Timing

Timing is critical — realize that even with the correct amount of leverage, organizations you wish to benchmark will be slow to respond. A benchmark process may take several months, which should be calculated when considering business budgeting cycles. Correlating your benchmark just before a budgeting cycle will allow enough time to present results and provide the best opportunity for obtaining additional funding.

As security professionals, we will continually be called upon to do more for our respective organizations; however, meeting those challenges does not mean that we have to do it with less. Use these concepts to validate to executive management the need for additional funding, and benchmark similar organizations to assist you in meeting your goals and assist your organization in being “proactive about tomorrow's uncertainties.”

Sean Ahrens, CPP, CSC is a project manager for security consulting and design services with Schirmer Engineering and has more than 16 years experience in the security industry, 11 of which has been as a practicing consultant. Mr. Ahrens volunteers his time on the ASIS International Commercial Real Estate Council (CREC). He can be reached at (847) 272-8340 or via e-mail at sean_ahrens@schirmereng.com.

- The Hackett Security Team

11.28.2007

Change your access system passwords regularly!!!

From Security Products
Tip of the Week

Our Tip of the Week is from James R. Black, senior security consultant from TRC Solutions in Irvine, Calif. "Most companies never bother changing the default passwords on alarm and access control system software, leaving the systems more vulnerable than necessary. Companies should understand how readily available this information is. Type your system name and the phrase 'default password' into Google and you?ll likely to find the administrators password. You?d be surprised how many hacking Web sites exist specialize in gathering security passwords. Unfortunately, thieves exploit these vulnerabilities more often than you think. Every business owner should confirm these defaults or administrative back doors have been changed. Consult the manufacturer directly if you cannot get confirmation that this has been done."

If you have a tip of the week or a question to share for publication, please e-mail it to tips@1105media.com. Please include your name, title, company name, city and state with your submission. Due to security concerns, we are unable to accept tips sent in the form of an e-mail attachment

For more tips, visit Security Products online.

10.12.2007

Average Cyber Loss Increases For U.S. Companies

Security Products (http://secprodonline.com/) and The Computer Security Institute (CSI) have a great article on increase of company losses due to cyber-crime.



Average Cyber Loss Increases For U.S. Companies

The Computer Security Institute (CSI) recently released its 2007 report with news that the average annual loss reported by U.S. companies in the 2007 CSI Computer Crime and Security Survey more than doubled, from $168,000 in last year's report to $350,424 in this year's survey. This ends a five-year run of lower reported losses.

Financial fraud overtook virus attacks as the source of the greatest financial loss. Virus losses, which had been the leading cause of loss for seven straight years, fell to second place. Another significant cause of loss was system penetration by outsiders.

Additional key findings include:

Almost one-fifth of those respondents who suffered one or more kinds of security incident said they'd suffered a "targeted attack," i.e. a malware attack aimed exclusively at their organization or at organizations within a small subset of the general population.

Insider abuse of network access or e-mail (such as trafficking in pornography or pirated software) edged out virus incidents as the most prevalent security problem, with 59 percent and 52 percent of respondents reporting each respectively.

When asked generally whether they'd suffered a security incident, 46 percent of respondents said yes, down from 53 percent last year and 56 percent the year before.

Click here for the original article

- The Hackett Security Team