The Convergence of Physical & Logical Access
For many security professionals, recent high-profile data breaches have shifted attention to external cyber threats. Despite this newfound focus, the Institute for Critical Infrastructure Technology reports that more than half of all cybersecurity incidents can be traced to insiders with legitimate access to corporate facilities and networks. Another survey from the Ponemon Institute reveals that the majority of respondents are more concerned by outside threats than those that originate internally. While external threats are very real, working to confront internal vulnerabilities can prevent incidents from happening in the first place. By addressing both physical and logical access in a more unified approach, organizations can reduce their risk for a costly breach while also improving user experience and operational efficiency. This idea is frequently referred to by the industry buzzword of ‘convergence.’ From a technical standpoint, convergence is defined as “the merging of distinct technologies, industries, or devices into a unified whole.” In terms of access control, convergence can be viewed as “the merging of physical and logical access control technologies to provide a more unified and simplified approach to identity management.” “Convergence means a simplified approach,” said Sheila Loy, Director of Healthcare Industry, Identity and Access Management at HID Global, “That can mean many different things, but it’s essentially making it easier for the user to get both digital access and door access. That usually comes in the form of a card or a mobile device – something that can do both.” While the notion of convergence is nothing new, this approach to security is becoming an increasingly viable way to mitigate threats. To explore this further, ASIS International recently partnered with HID Global to survey security professionals regarding their experience and related plans on convergence projects. The data in this paper is based on the responses of 745 ASIS International members who have direct responsibilities in physical and/ or information security. The benefits of convergence: Improved user experience, operational efficiency and security Security administrators are looking for solutions that are easy, convenient and fast. By introducing solutions that better blend physical access control (PACS) with logical access control (LACS), organizations of all types will enjoy three key benefits including: 1) positive user experience, 2) enhanced administrative experience, and 3) improved security. Positive user experience Oftentimes, the weakest link in even the strongest of security systems lies within the end user. If interactions with security technologies are confusing or cumbersome, employees will take shortcuts that introduce unnecessary vulnerabilities. Converged PACS and LACS solutions help reduce this risk by boosting convenience, particularly by requiring employees to only carry one card or mobile device. This type of solution also eliminates the need to constantly refresh passwords. In today’s world, most end-users wear an ID badge to access facilities, which is a form factor they are accustomed to using. Even more, many employees either use a user name and password or a one-time password fob or token to access networks. While this approach may provide an additional layer of security, it is prohibitive in terms of convenience. Alternatively, providing a single form factor for both physical and logical access creates a more streamlined user experience, which ultimately increases user adoption to desired security policies. “Building occupants who have entitlements to both physical areas and logical applications will see an enhancement in their experience,” said Brandon Arcement, Director of Product Marketing at HID Global, “Convergence results in greater employee efficiency and a more pleasant work environment for building occupants. It’s easier for employees to carry one card or one mobile device to access both systems, rather than having to carry a card for the door as well as a fob for the computer or having to remember passwords.” In terms of logical or network access, one major pain point for end users is the need to remember and frequently reset their passwords. When ASIS International members were asked, “How access to network and logical applications is done today,” a resounding 85% of respondents indicated that they use a user name and password. 85% of respondents also indicate that they have an organizational policy regarding the creation of passwords such as requiring numbers or special characters. Not only is this inconvenient for users and administrators, it presents another common security risk – employees writing their passwords on notes left visible on their desk. Enhanced administrative experience Converged access control solutions provide an improved administrative experience. When survey respondents were asked to rank a series of benefits of PACS and LACS convergence, the top response was ‘easier to manage employee credentials,’ followed by ‘one card for multiple applications.’ These top responses reflect two key angles within an improved administrative experience. First, many applications used to manage credentials are now web-based with secure, simple access for administrators. This allows security teams to issue, modify, or revoke credentials away from the office or during off-hours. The second angle is the ability to deploy a converged ‘high value’ form factor that allows for multiple applications. For example, using one card for multiple uses reduces costs for additional or replacement cards, as well as reduces the time required to produce multiple credentials for individual applications. According to survey data, the value of leveraging smartcards for applications beyond physical access is more than theoretical – 73% of respondents agree that they have interest in using smart cards for applications beyond traditional physical access control. Finally, more converged access control solutions provide security administrators with more visibility into audit data. This makes achieving compliance easier, thus reducing the potential for associated fines and damaged reputations. Improved security The most important benefit of any technology is improved security. Innovative technologies for physical access include contact and contactless cards with encryption that adds additional layers of security upon entering doors, elevators or parking garages. Meanwhile, digital certificates loaded onto that same smart card can ensure trusted login to networks and applications, as well as encrypt e-mails and digitally sign documents. Converged solutions improve security in three key areas: Increased adoption rate of converged…