Physical Security Quesiton

Physical Security Quesiton

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Physical Security Quesiton Shane 12-20-2005
Posted by Shane on December 20, 2005, 9:31 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Alright, I have a client busting my chops on our finding that they
aren't singing in/out unauthoirzed employees and vendors entering their
data center. I've tried explaining the reasoning, but the client would
like additional guidance in the way of published baseline guidelines
and/or standards that support our claim they should maintain a log of
people going into and out of the data center who aren't typically
allowed access, and shouldn't be relying on the receptionist sign in
and data center cameras as the sole means for preventing unauthorized
access.

As we all know recpetionists hardly ever remember to sign visitors
in/out all the time and I demonstrated that fact to them during our
social engineering testing and I was able to piggy back into the data
center on numerous occassions. Not once did the client or any of their
staff bother to look at the footage of their video and care to question
my presence, but this apparently isn't going to be enough.

Any help would be greatly appreciated. Please send your repsonses to
Stealth_Devil@hotmail.com.


Posted by Leythos on December 20, 2005, 9:37 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Stealth_Devil@hotmail.com says...
> Alright, I have a client busting my chops on our finding that they
> aren't singing in/out unauthoirzed employees and vendors entering their
> data center. I've tried explaining the reasoning, but the client would
> like additional guidance in the way of published baseline guidelines
> and/or standards that support our claim they should maintain a log of
> people going into and out of the data center who aren't typically
> allowed access, and shouldn't be relying on the receptionist sign in
> and data center cameras as the sole means for preventing unauthorized
> access.
>
> As we all know recpetionists hardly ever remember to sign visitors
> in/out all the time and I demonstrated that fact to them during our
> social engineering testing and I was able to piggy back into the data
> center on numerous occassions. Not once did the client or any of their
> staff bother to look at the footage of their video and care to question
> my presence, but this apparently isn't going to be enough.
>
> Any help would be greatly appreciated. Please send your repsonses to
> Stealth_Devil@hotmail.com.

Signing in/out has nothing to do with security - a method should be in
place so that no-one gets into the data center without a escort or
without a pass card/code. Only employees that show each other their
cards should be permitted into the data center, since an employee can be
canned at any time, just knowing the person is not enough to allow them
to walk in with you.

Physical security has nothing to do with Camera's or a secretary.

--

spam999free@rrohio.com
remove 999 in order to email me

Posted by Todd H. on December 20, 2005, 10:19 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Alright, I have a client busting my chops on our finding that they
> aren't singing in/out unauthoirzed employees and vendors entering their
> data center. I've tried explaining the reasoning, but the client would
> like additional guidance in the way of published baseline guidelines
> and/or standards that support our claim they should maintain a log of
> people going into and out of the data center who aren't typically
> allowed access, and shouldn't be relying on the receptionist sign in
> and data center cameras as the sole means for preventing unauthorized
> access.
>
> As we all know recpetionists hardly ever remember to sign visitors
> in/out all the time and I demonstrated that fact to them during our
> social engineering testing and I was able to piggy back into the data
> center on numerous occassions. Not once did the client or any of their
> staff bother to look at the footage of their video and care to question
> my presence, but this apparently isn't going to be enough.

They were at least smart enough to hire y'all for whatever reason.
Why did they say they hired you? Is this an audit they've had done
for some sort of regulatory compliance? If so, show them that if they
don't understand the common sense of why this is worrisome, maybe
they'll respect that they're non-compliant with regulation. If
they're a health care entity, point them to HIPPA's physical security
guidelines that talk about secured access to the data center.

Tell them there's an entire domain on physical security within the
most common security certification in the world.
http://www.cccure.org/Documents/HISM/675-680.html

Ask them if they'd run their systems without a password. If they say
"of course not" then make sure they understand crystal clear that
physica access to a box allows people to circumvent password security
trivially. If they aren't preventing people from getting to the data
center, they may as well be running their business off an open kiosk
at a shopping center.

If they're not listening, they're paying you to bang on the table and
give them religion and tell them all the things a person with physical
access can do. Network sniffing, passwords, data corruption, data
loss, data theft, corporate espionage, stealing their servers,
intercepting all communication, rerouting traffic, physically
endangering their employees, making them liable to lawsuits should
someone cause harm to another and they've expended no due diligence
against things despite a documented finding by a reputable security
firm, destroying their entire business.


> Any help would be greatly appreciated. Please send your repsonses to
> Stealth_Devil@hotmail.com.

No thank you.

Please at least have the courtesy to read replies here and participate
in the community if you're asking help from it to the benefit of your
business.

Best Regards,
--
Todd H.
http://www.toddh.net/

Similar ThreadsPosted
REVIEW: "Black Hat Physical Device Security", Drew Miller August 12, 2005, 3:26 pm
Best Practices for secure delivery / transportation of physical media (tapes, CDs, etc.) April 24, 2007, 4:13 pm
online Professional data recovery training for RAID and Logical or physical disk crash April 21, 2005, 11:53 pm
Security Breaches Pandemic - Deloitte Touche 2006 Global Security Survey June 29, 2006, 12:42 am
New site dedicated to security conferences : www.security-briefings.com May 6, 2006, 11:16 am
New It Security News and Information site for security professionals August 6, 2008, 2:46 am
Excellent website for IT Security (Security+) February 8, 2008, 12:32 am
Google Closes Security Holes in Google Base Security November 21, 2005, 5:37 pm
Security IP June 10, 2005, 3:09 pm
BGP Security October 4, 2005, 1:49 pm

The site map in XML format XML site map

Contact Us | Privacy Policy