Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental)...

40
Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security

Transcript of Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental)...

Page 1: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Dr. Bhavani ThuraisinghamThe University of Texas at Dallas (UTD)

June 2011

Physical (Environmental) Security

Page 2: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Domain Agenda• Site and Facility Design Criteria• Perimeter Security • Building and Inside Security• Secure Operational Area

Page 3: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Site Location Considerations• Emergency services• Hazards/ threats• Adjacency

Page 4: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Threats to Physical Security• National / environmental• Utility systems• Human-made/ political events

Page 5: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Threat Sources and ControlsThreat

• Theft• Espionage• Dumpster diving• Social engineering• Shoulder surfing• HVAC access

Controls• Locks• Background checks• Disposal procedures• Awareness• Screen filters• Motion sensors in

ventilation ducts

Page 6: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Domain Agenda• Site and Facility Design Criteria• Perimeter Security • Building and Inside Security• Secure Operational Area

Page 7: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Perimeter and BuildingBoundary Protections

• First line of defense• Protective barriers

– Natural– Structural

Page 8: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Fences• Federal, state or local codes may apply• Parking should not be allowed near fences

Page 9: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Controlled Access Points• Gates are the minimum necessary layer• Bollards

Page 10: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Perimeter Intrusion Detection Systems• Detect unauthorized access into an area

– Electronic ‘eyes’

• Note that some perimeters IDSs can function inside the perimeter as well.

Page 11: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Types of Lighting• Continuous lighting• Trip lighting• Standby lighting• Emergency exit lighting• Emergency egress lighting

Page 12: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Access and Visitor Logs and More Rigorous forms of Logging

ABC CompanyEntrance:___________________ Date:________________

Name Institution Name of Person VisitingTime In Time

Out

Page 13: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Closed Circuit Television (CCTV)• CCTV Capability Requirements

– Detection– Recognition– Identification

• Mixing Capabilities• Virtual CCTV Systems

Page 14: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Guards and Guard Stations• Guards

– Deterrent– Possible liability

• Guard stations

Page 15: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Domain Agenda• Site and Facility Design Criteria• Perimeter Security • Building and Inside Security• Secure Operational Area

Page 16: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Doors• Isolation of critical areas• Lighting of doorways• Contact devices• Guidelines

Page 17: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Building Entry Point Protection• Locks• Lock components

– Body– Strike– Strike plates– Key– Cylinder

Page 18: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Types of Locks• Something you have – Keyed• Something you know – Combinations• Something you are - Biometric

Page 19: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Lock Attacks• Lock picking• Lock bumping

Page 20: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Lock Controls• Lock and key control system• Key control procedures• Change combinations• Fail

– Soft– Secure– Safe

Page 21: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Other Electronic Physical Controls• Card access• Biometric access methods

Page 22: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Windows and Entry Points• Standard plate glass• Tempered glass• Acrylic materials• Polycarbonate windows• Entry points

Page 23: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Intrusion Detection Systems (IDS)• Closed circuit television• Sensors and monitors

Page 24: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Escorts and Visitor Control• Visitor access control best practices

– Picture identity– Photographs– Enclosed area– Authorized escort

Page 25: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Access Logs• Computerized log• Closed circuit TV

Page 26: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Domain Agenda• Site and Facility Design Criteria• Perimeter Security • Building and Inside Security• Secure Operational Area

Page 27: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Equipment Room• Perimeter enclosure• Controls• Policy

Page 28: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Data Processing Facility• Small devices threat• Server room• Mainframes• Storage

Page 29: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Communications and Power• Wireless access points• Network access control• Utility and power rooms

Page 30: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Work Area• Operators• System administrators• Restricted work areas

Page 31: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Equipment Protection• Inventory• Locks and tracing equipment• Data encryption• Disabling I/O ports

Page 32: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Environmental Controls

System• Electric power• HBAC• Water / plumbing• Gas• Refrigeration

Threat• Loss of power• Overheating• Flood / dripping• Explosion• Leakage

Page 33: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Fire Protection• Prevention – reduce causes• Detection – alert occupants• Suppression – contain or extinguish

Page 34: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Materials and Suppression Agents

Type Suppression Agents

Common combustibles Water, foam, dry chemicals

Combustible liquids Inter gas, CO2, foam, dry chemicals

Electrical Inert gas, CO2, dry chemicals

Combustible metals Dry powders

Cooking media (fats) Wet chemicals

Page 35: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Flooding Area Coverage• Water – sprinkler systems• Gas – Halon/CO2/Argon systems• Best practices for systems• Portable extinguishers

Page 36: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Types of Electrical Power Faults• Complete loss of power• Power degradation• Interference (noise)• Grounding

Page 37: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Loss of Electrical Power• UPS• Generators• Goals of power• Power controls

Page 38: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Heating Ventilation Air Condition (HVAC)

• Location• Positive pressure• Maintenance

Page 39: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Other Infrastructure Threats• Gas leakage• Water threats

Page 40: Dr. Bhavani Thuraisingham The University of Texas at Dallas (UTD) June 2011 Physical (Environmental) Security.

Key Performance Indicators• # of physical security incidents detected• # of false positives for biometrics