<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>InfoSecMinds &#187; Physical Security</title>
	<atom:link href="http://infosecminds.com/category/physical-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecminds.com</link>
	<description>For like-minded people</description>
	<lastBuildDate>Sat, 15 Jan 2011 09:21:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Physical Security &#8211; At it&#8217;s best.</title>
		<link>http://infosecminds.com/2009/11/09/physical-security-at-its-best/</link>
		<comments>http://infosecminds.com/2009/11/09/physical-security-at-its-best/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 12:24:36 +0000</pubDate>
		<dc:creator>Vinod Puthuseeri</dc:creator>
				<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Airport Security]]></category>
		<category><![CDATA[Metal Detectors]]></category>
		<category><![CDATA[Metor Metal Detectors]]></category>

		<guid isPermaLink="false">http://infosecminds.com/?p=151</guid>
		<description><![CDATA[Just want to illustrate couple of incidents on physical security that we commonly observe. Once while driving through a technology park, I was stopped by a couple of security personnel and they requested me to open the boot of my car and there was the second one running a mirror underneath my car and looking [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Just want to illustrate couple of incidents on physical security that we commonly observe.</p>
<p style="text-align: justify;">Once while driving through a technology park, I was stopped by a couple of security personnel and they requested me to open the boot of my car and there was the second one running a mirror underneath my car and looking at something. Since the amount of different car models that I has come out in market, I assumed that the bottom  of every car must be different and out of curiosity, I just enquired with the security personnel, as to what is he looking for and you will be amazed with the answer. “I am not sure sir, they have asked me to check and I am checking”.</p>
<p style="text-align: justify;"><span id="more-151"></span></p>
<p style="text-align: justify;">In the meantime, the one who was checking the boot of the car just opened up the spare wheel compartment and looked around and closed the boot. Assuming they might be checking for placement of some car bombs, are those the only areas where you can place a bomb..? If not, what is the purpose of this check..? Are we not just wasting time and resources..?</p>
<p style="text-align: justify;">In a similar incident, I was attending a training which was held in one of the hotels. I have attended many training here and have never seen any security checks happening. This time as I drove through, similar to the above scenario one was checking something underneath and the other checking the boot. I had four day training and they did this to me for all the three days and on the fourth day when one of the security personnel was beginning to check, the other shouts at him, “it is fine, please let Sir pass by”. That ended the effectiveness of a security control. Since I did not question him for the three days of checking, he might have sort of built a trust in me and by-passed the control.</p>
<p style="text-align: justify;">So if one passes through a security channel couple of times and obeys the security personnel, he/she has a high chance of been let in without passing through a security channel. This could be one reason for some of the breaches that are happening across the globe.</p>
<p style="text-align: justify;">In a recent visit using the air transport, I was really bugged with a series of security check which made me remove my waist belt all the time and nothing else. Now I think back and try to understand, why security is so annoying to the non-security professionals.</p>
<p style="text-align: justify;">During the trip at one of the airport during departure, I had to pass through a four metal detector at different locations and all the four times the detector would beep at my waist belt. I had to remove the same and place it on the luggage scanner and then pass through the metal detector again. I could see this happening with 90% of the passengers passing through that metal detector and every lounge you go, I could find passengers busy putting back their waist belts, including myself.</p>
<p style="text-align: justify;">What is more annoying is that the same does not happen while I visit a shopping mall equipped with metal detectors. In fact at shopping malls, I have never heard the metal detectors beep even once, for any reason. Anything passing by the detectors, allows it to go through. So what are we trying to implement is a deterrent control using a tool that can help in preventive control.</p>
<p style="text-align: justify;">In looking at both the scenarios of over or under implementation of controls, it is necessary that the authorized personnel take adequate steps to calibrate the equipments on a timely basis and cause minimum impact on the public. It should not reach a situation where human beings are sent through the luggage scanner just because the metal detectors beeps even after complete striping.</p>
]]></content:encoded>
			<wfw:commentRss>http://infosecminds.com/2009/11/09/physical-security-at-its-best/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CISF Security at Infosys</title>
		<link>http://infosecminds.com/2009/07/31/cisf-security-at-infosys/</link>
		<comments>http://infosecminds.com/2009/07/31/cisf-security-at-infosys/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 09:07:51 +0000</pubDate>
		<dc:creator>Vinod Puthuseeri</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Security Management System]]></category>
		<category><![CDATA[Information Security Risk Assessment]]></category>
		<category><![CDATA[Information Security Risk Management]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[ISMS]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecminds.com/?p=146</guid>
		<description><![CDATA[In the recent news Infosys becomes the first private company to get CISF security. I have also been reading in yet another blog about a organization conducting mocks drills for terrorist’s attacks. It is quite interesting to see that organizations are now taking security as a prime concern. As mentioned in my previous blog about [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">In the recent news Infosys becomes the first private company to get CISF security. I have also been reading in yet another <a href="http://vagrasala.wordpress.com/2009/07/01/beyond-fire-mock-drills-to-terrorist-attack-mock-drills/">blog</a> about a organization conducting mocks drills for terrorist’s attacks. It is quite interesting to see that organizations are now taking security as a prime concern. As mentioned in my previous blog about frisking of VIP’s at airports, the exception mentioned there is an age old rule that was implemented when terrorism was a not major concern.</p>
<p style="text-align: justify;"><span id="more-146"></span></p>
<p style="text-align: justify;">It is important for every organization to constantly carry out risk assessment in their organizations to ensure that they are protected from new threats. Today terrorism has become a major threat for organizations as well and hence it is definitely required for organizations to include terrorism as a threat in their risk assessment exercise.</p>
<p style="text-align: justify;">A constant risk assessment exercise does not only help in identifying and protecting against the latest threats, but also looks into the processes and controls that was defined and implemented years ago. Though the processes and controls might be working well, it might not include the risks due to the latest threats and if risk assessments are not conducted on a regular basis, these new threats might go unnoticed.</p>
<p style="text-align: justify;">Hence organization are encouraged to have the risk assessment exercise as an annual activity and also when there is a major change within the organization. It is also important to keep a tab on the new threats that need to be included in their risk assessment exercise.</p>
<p style="text-align: justify;">Now the next arising question is, what are the risks of having these armed CISF securities in the campus?</p>
]]></content:encoded>
			<wfw:commentRss>http://infosecminds.com/2009/07/31/cisf-security-at-infosys/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Frisking of VIP’s at airport&#8217;s</title>
		<link>http://infosecminds.com/2009/07/22/frisking-of-vip%e2%80%99s-at-airports/</link>
		<comments>http://infosecminds.com/2009/07/22/frisking-of-vip%e2%80%99s-at-airports/#comments</comments>
		<pubDate>Wed, 22 Jul 2009 09:01:52 +0000</pubDate>
		<dc:creator>Vinod Puthuseeri</dc:creator>
				<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Airport Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://infosecminds.com/?p=138</guid>
		<description><![CDATA[In the recent incident of Dr. APJ Kalam been frisked at the IGI airport by the staff of Continental Airlines has created some news. The Airline has also tendered an apology to Dr. Kalam for the inconvienence caused – this is as reported in the TimesofIndia daily newspaper on 22nd July 2009. Now does that [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">In the recent incident of Dr. APJ Kalam been frisked at the IGI airport by the staff of Continental Airlines has created some news. The Airline has also tendered an apology to Dr. Kalam for the inconvienence caused – this is as reported in the TimesofIndia daily newspaper on 22<sup>nd</sup> July 2009.</p>
<p style="text-align: justify;">Now does that apology mean that Continental Airlines will not frisk any VIP’s in future while they board the flight..? I see a security concern here.</p>
<p style="text-align: justify;"><span id="more-138"></span></p>
<p style="text-align: justify;">Not having the VIP’s frisked before boarding the flight is a security hole, nevertheless these people are always surrounded with guards and they move with apt protection. But these people (if found an opportunity) could be utilized in carrying materials (those prohibited in flight) to be taken very easily, which will pass them through all sorts of check without any objection.</p>
<p style="text-align: justify;">The materials can be put into the VIP’s pockets or hand baggage without his/her notice or he/she could be threatened to carry some stuff, which he/she might not be able to disclose. This can be done since this is a known security hole.</p>
<p style="text-align: justify;">Now the next concern is the rule that says</p>
<p style="text-align: justify;">“Indian laws exempt dignitaries like former presidents, ex-PMs, Chief Justice of India and even Robert Vadra from being frisked at airports.” – quote TimeofIndia.</p>
<p style="text-align: justify;">Suppose, lets say the law of the country where the airline is flying too (destination) is stringent and has ordered the airline to frisk all passengers boarding that flight. Now if there would have been an incident mid-air, who would take up the responsibility..?</p>
<p style="text-align: justify;">In this scenario, does the airline follow the rule of the country currently landed at OR the rule to which the airline will be flying?</p>
<p style="text-align: justify;">Your thoughts.</p>
]]></content:encoded>
			<wfw:commentRss>http://infosecminds.com/2009/07/22/frisking-of-vip%e2%80%99s-at-airports/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

