<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BestInternetSecurity.net &#187; Physical Security</title>
	<atom:link href="http://www.bestinternetsecurity.net/category/physical-security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.bestinternetsecurity.net</link>
	<description>Information Security Resources</description>
	<lastBuildDate>Fri, 10 Jul 2009 02:27:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Physical Security for Power Supply</title>
		<link>http://www.bestinternetsecurity.net/34/physical-security-for-power-supply.html</link>
		<comments>http://www.bestinternetsecurity.net/34/physical-security-for-power-supply.html#comments</comments>
		<pubDate>Tue, 25 Mar 2008 11:46:59 +0000</pubDate>
		<dc:creator>Damen</dc:creator>
				<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Backup Power Supply]]></category>
		<category><![CDATA[Blackout]]></category>
		<category><![CDATA[Brownout]]></category>
		<category><![CDATA[Dedicated Circuits]]></category>
		<category><![CDATA[Electrical Disturbances]]></category>
		<category><![CDATA[Emergency Power Generator]]></category>
		<category><![CDATA[Power Supply]]></category>
		<category><![CDATA[Sag]]></category>
		<category><![CDATA[Spike]]></category>
		<category><![CDATA[Surge]]></category>
		<category><![CDATA[Uninterruptible Power Supply]]></category>
		<category><![CDATA[UPS]]></category>

		<guid isPermaLink="false">http://www.bestinternetsecurity.net/34/physical-security-for-power-supply/</guid>
		<description><![CDATA[There are many possible physical security threats associated with electrical power supply. A few examples, and ones you may already be familiar with, include :

Blackout:  a complete loss of power.
Sag or Brownout:  a decrease in voltage levels, usually of short duration but may last anywhere from fractions of a second to hours.
Surge: a short-term increase [...]]]></description>
			<content:encoded><![CDATA[<p>There are many possible physical security threats associated with electrical power supply. A few examples, and ones you may already be familiar with, include :</p>
<ul>
<li><em>Blackout</em>:  a complete loss of power.</li>
<li><em>Sag or Brownout</em>:  a decrease in voltage levels, usually of short duration but may last anywhere from fractions of a second to hours.</li>
<li><em>Surge</em>: a short-term increase in the level of voltage, generally lasting a fraction of a second</li>
<li><em>Spike</em>:  an instantaneous surge causing a tremendous increase to levels of voltage, usually lasting no longer than one-millionth of a second<strong><sup>1</sup></strong>.</li>
</ul>
<p>In order to address these threats to physical security, a secure electrical system for computing equipment must possess the following properties:</p>
<ol>
<li>Dedicated Circuits</li>
<li>Physical Access Control must be implemented for:
<ul>
<li>Master Circuit Breakers</li>
<li>Transformers</li>
<li>Power Distribution Panels and Feeder Cables</li>
</ul>
</li>
<li>Emergency Power Off Controls must be installed and accessible by the personnel on-duty</li>
<li>Voltage Monitoring/Recording and Surge Protection should be in place</li>
</ol>
<p><span style="text-decoration: underline;"><strong>Ensuring Computer Availability through a Backup Power Supply</strong></span><br />
To ensure that your computer system remains available for use in spite of power supply threats, the power supply has to be made “fault tolerant” through the use of a Backup Power Supply. There are three ways to achieve this:</p>
<ol>
<li><span style="text-decoration: underline;">Alternate Feeders</span></li>
<li><span style="text-decoration: underline;">Emergency Power Generator</span><br />
If using alternate feeders is not feasible, an emergency power generator should be considered as an alternative for mission critical operations. However, this security measure is very costly to maintain and operate. It is advised that a detailed analysis be performed in order to justify the high cost of this security option.</li>
<li><span style="text-decoration: underline;">Uninterruptible Power Supply (UPS)</span><br />
UPS provides just enough time for the computing system to back up data and shutdown before electrical power completely fails. UPS requires regular testing and maintenance work to ensure proper operation.  Additionally, UPS involves the use of hazardous hydrogen gas.</li>
</ol>
<p>In addition to computing equipment, Backup Power Supply is also needed for the following vital systems:</p>
<ul>
<li>Lighting</li>
<li>Physical Access Control Systems</li>
<li>Fire Protection Systems</li>
<li>Communications Equipment</li>
<li>Telephone Systems</li>
<li>HVAC</li>
</ul>
<p><strong><sup>1</sup></strong><em>Source: University of Connecticut Computer Center (1997), <span style="text-decoration: underline;">Electrical Disturbances</span>, Available from: </em><em>http://</em><em>vm.uconn.edu/~year2000/edisturb.html [Accessed 20 March 2008].</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bestinternetsecurity.net/34/physical-security-for-power-supply.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Physical Security : Environmental Control</title>
		<link>http://www.bestinternetsecurity.net/31/physical-security-environmental-control.html</link>
		<comments>http://www.bestinternetsecurity.net/31/physical-security-environmental-control.html#comments</comments>
		<pubDate>Mon, 24 Mar 2008 05:49:27 +0000</pubDate>
		<dc:creator>Damen</dc:creator>
				<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Air Conditioning]]></category>
		<category><![CDATA[Airborne particulates]]></category>
		<category><![CDATA[Dust]]></category>
		<category><![CDATA[Environmental Controls]]></category>
		<category><![CDATA[Environmental Physical Controls]]></category>
		<category><![CDATA[Heating]]></category>
		<category><![CDATA[Humidity]]></category>
		<category><![CDATA[HVAC]]></category>
		<category><![CDATA[Pollution]]></category>
		<category><![CDATA[Positive pressurization]]></category>
		<category><![CDATA[Temperature]]></category>
		<category><![CDATA[Ventilation]]></category>

		<guid isPermaLink="false">http://www.bestinternetsecurity.net/31/physical-security-environmental-control/</guid>
		<description><![CDATA[To understand Environmental Physical Control, we need to understand how your HVAC system affects your computing environment. HVAC stands for three words: Heating, Ventilation and Air Conditioning. Your HVAC system controls various environmental factors that must be monitored to ensure that your computing equipment operates effectively.
Temperature: Between 21 and 23 degrees Celsius (70 to 73 [...]]]></description>
			<content:encoded><![CDATA[<p>To understand <em><strong>Environmental Physical Control</strong></em>, we need to understand how your HVAC system affects your computing environment. <strong>HVAC</strong> stands for three words: Heating, Ventilation and Air Conditioning. Your HVAC system controls various environmental factors that must be monitored to ensure that your computing equipment operates effectively.</p>
<p><strong>Temperature:</strong> Between 21 and 23 degrees Celsius (70 to 73 degrees Fahrenheit) is the general optimal temperature range for computing equipment to operate.</p>
<p><strong>Humidity:</strong> The best relative humidity for computer equipment operation is from 45% to 55% because an environment too humid can cause corrosion.  On the other hand, environments too dry can cause static damage. A static charge of above 20,000 volts is potentially harmful to a system.</p>
<p><strong>Pressurization and Ventiliation:</strong> Positive pressurization and ventilation must be maintained in order to keep contaminants from entering the facility. Airborne particulates should be kept at appropriate levels since dust and other contaminants can impact computer hardware operation.</p>
<p>According to Keranen E. (2006), dust particles can contain moisture, organic material such as carbon and various minerals, and/or various chemicals. All of these can affect the reliability and life span of computing equipment.</p>
<blockquote><p>Integrated circuits (ICs) can suffer from overheating due to the insulating effect of dust as well as suffer from electrical shorts caused by dust across their contacts. The most susceptible ICs are those having a metal lid acting as a heatsink cooling surface. To prevent overheating and failure, this metal surface and heatsink need to be essentially dust-free. Dust acts like an insulating blanket, preventing proper convection cooling.” <strong><sup>1</sup></strong>— E. Keranen (2006) <em>Effects of dust on Computer Electronics and Mitigating Approaches</em>.</p></blockquote>
<p>In addition to dust, an excess concentration of certain gasses such as ammonia can speed up corrosion inside the electronic components of the system, leading to malfunction.</p>
<p>Some devices such as printers should be located outside of the computing facility. A printer’s toner could generate carbon particles, which are moisture absorbent and combustible, threatening the computing equipment’s security.</p>
<p>Of course, non-smoking policies should be enforced within critical computing facilities in order to reduce fire hazards as well as minimize the pollutants related to smoking.</p>
<p><strong><sup>1</sup></strong> Keranen E. (2006) <em>Effects of dust on Computer Electronics and Mitigating Approaches</em>. [Internet]. Computer Dust Solutions, Available from.</p>
<p><a href="http://www.computerdust.com/SPECIAL_REPORT_ON_DUST_EFFECTS_ON_ELECTRONICS.pdf" target="_blank">http://www.computerdust.com/SPECIAL_REPORT_ON_DUST_<br />
EFFECTS_ON_ELECTRONICS.pdf</a> [Accessed 17 March 2008].</p>
<p>Tags: Environmental Controls, Environmental Physical Controls, Pollution</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bestinternetsecurity.net/31/physical-security-environmental-control.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Physical Security &#8211; Choosing the right facility</title>
		<link>http://www.bestinternetsecurity.net/29/physical-security-choosing-the-right-facility.html</link>
		<comments>http://www.bestinternetsecurity.net/29/physical-security-choosing-the-right-facility.html#comments</comments>
		<pubDate>Mon, 17 Mar 2008 08:57:43 +0000</pubDate>
		<dc:creator>Damen</dc:creator>
				<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Boundary Protection]]></category>
		<category><![CDATA[Facility Management]]></category>
		<category><![CDATA[Motion Sensor]]></category>
		<category><![CDATA[Natural Hazards]]></category>
		<category><![CDATA[Nuisance Alarms]]></category>
		<category><![CDATA[Video Surveillance Systems]]></category>

		<guid isPermaLink="false">http://www.bestinternetsecurity.net/29/physical-security-choosing-the-right-facility/</guid>
		<description><![CDATA[Many factors should be considered when choosing the best facility for hosting computer equipment. Some of these factors include:

Local Crime: Is the site a prime area for criminal activities?
Natural Hazards: Does the location have a high occurrence of flooding, earthquakes, thunderstorms, or other natural hazards?
Power Supply: Is there a stable power supply for your computing [...]]]></description>
			<content:encoded><![CDATA[<p>Many factors should be considered when choosing the best facility for hosting computer equipment. Some of these factors include:</p>
<ul>
<li><em>Local Crime:</em> Is the site a prime area for criminal activities?</li>
<li><em>Natural Hazards:</em> Does the location have a high occurrence of flooding, earthquakes, thunderstorms, or other natural hazards?</li>
<li><em>Power Supply:</em> Is there a stable power supply for your computing facilities?</li>
<li><em>Access:</em> Is the locations easily accessible, for personnel, suppliers, and others needed to access to the location?</li>
<li><em>Existing boundary protection:</em> Is the location secure?Security controls such as fencing, adequate lighting, and detection systems, including motion sensor and video surveillance systems, need to be in place. The detection system must be equipped with a reactive system preventing (or at least delay the progress of) intrusion of any trespassers. This can be accomplished with nuisance alarms as well as prearranged response forces, such as the local police or hired security guards.</li>
<li>Nature of Facility:  Is the facility shared with other tenants?It is critically important that the condition of sharing with co-tenants will not undermine the level of security. Strong security measures need to be in force.</li>
</ul>
<p>In addition to facility management, we should also consider other factors of physical security. But choosing the right facility in the first place is the foundation for all other physical security controls to be enforced effectively.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bestinternetsecurity.net/29/physical-security-choosing-the-right-facility.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Physical Security Threats and Controls</title>
		<link>http://www.bestinternetsecurity.net/28/physical-security-threats-and-controls.html</link>
		<comments>http://www.bestinternetsecurity.net/28/physical-security-threats-and-controls.html#comments</comments>
		<pubDate>Mon, 17 Mar 2008 08:40:16 +0000</pubDate>
		<dc:creator>Damen</dc:creator>
				<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Administrative Physical Security Control]]></category>
		<category><![CDATA[earthquake]]></category>
		<category><![CDATA[Electrical Interruption]]></category>
		<category><![CDATA[Environmental Failure]]></category>
		<category><![CDATA[Environmental Physical Security Control]]></category>
		<category><![CDATA[errors]]></category>
		<category><![CDATA[espionage]]></category>
		<category><![CDATA[Fire]]></category>
		<category><![CDATA[Fire Protection]]></category>
		<category><![CDATA[Flooding]]></category>
		<category><![CDATA[hurricane]]></category>
		<category><![CDATA[HVAC System]]></category>
		<category><![CDATA[lightning]]></category>
		<category><![CDATA[Liquid Leakage]]></category>
		<category><![CDATA[Physical Security Controls]]></category>
		<category><![CDATA[Power Protection]]></category>
		<category><![CDATA[sabotage]]></category>
		<category><![CDATA[Theft]]></category>
		<category><![CDATA[tornado]]></category>
		<category><![CDATA[vandalism]]></category>
		<category><![CDATA[Water Protection]]></category>
		<category><![CDATA[wind]]></category>

		<guid isPermaLink="false">http://www.bestinternetsecurity.net/28/physical-security-threats-and-controls/</guid>
		<description><![CDATA[Physical security is the lifeblood of all security controls. If physical security is compromised, all other controls are irrelevant.
Why? Think about it. If someone manages to get into your server, physically accessing your computers, he or she can cause serious damage. Some examples of damage possible can include: removing the hard drives from your computer, [...]]]></description>
			<content:encoded><![CDATA[<p><em><strong>Physical security</strong></em> is the lifeblood of all security controls. If physical security is compromised, all other controls are irrelevant.</p>
<p>Why? Think about it. If someone manages to get into your server, physically accessing your computers, he or she can cause serious damage. Some examples of damage possible can include: removing the hard drives from your computer, stealing computer backup tapes, or simply shutting down the power to your servers. All of these can be accomplished in the blink of an eye, without involving serious technical skills. As we have mentioned before, security is the weakest link in your system. For this reason, we should not overlook physical security.</p>
<p>To understand physical security, we first need to understand <em><strong>physical threats</strong></em>.</p>
<p>The are three types of physical threats:</p>
<p><strong>External physical threats:</strong></p>
<ul>
<li>Flooding, lightning, earthquake, wind, tornado, hurricane, ice, fire, chemical</li>
</ul>
<p><strong>Internal physical threats:</strong></p>
<ul>
<li>Fire, environmental failure, liquid leakage, electrical interruption</li>
</ul>
<p><strong>Human physical threats: </strong></p>
<ul>
<li>Theft, vandalism, sabotage, espionage, errors</li>
</ul>
<p>To prevent these threats from becoming reality, <em><strong>physical security controls</strong></em> should be implemented.  Some examples of effective physical security controls include:</p>
<p><strong>Exterior physical security controls:</strong></p>
<ul>
<li>Fences, Barriers</li>
</ul>
<p><strong>Entrance physical security controls:</strong></p>
<ul>
<li>Doors and Gates with Locks</li>
</ul>
<p><strong>Administrative physical security controls:</strong></p>
<ul>
<li>Badges and Escorts</li>
</ul>
<p><strong>Property physical security controls:</strong></p>
<ul>
<li>Monitoring/Detection Systems, Lighting</li>
</ul>
<p><strong>Environmental physical security controls:</strong></p>
<ul>
<li>HVAC System, Power Protection, Water and Fire Protection</li>
</ul>
<p>All of these controls require detailed and careful planning prior to setting up an office with computing facilities. We will discuss physical controls in more detail later.</p>
<p>Tags: Administrative Physical Security Control, Environmental Physical Security Control, Water Protection</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bestinternetsecurity.net/28/physical-security-threats-and-controls.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
