40
#4. PHYSICAL SECURITY

Security System 1 - 04

Embed Size (px)

Citation preview

Page 1: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 1/40

#4. PHYSICAL SECURITY

Page 2: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 2/40

AGENDA

Power ProtectionGeneral Environment ProtectionEquipment Failure Protection

Page 3: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 3/40

Physical SecurityPhysical security is the first line of defense.Physical security addresses thephysical protection of the resources of an organization, which include people,data, facilities, equipment, systems, etcItconcerns with people safety, how peoplecan physically enter an environment andhow the environmental issues affectequipment and systemsPeople safetyalways takes precedence over the other security factors.

Page 4: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 4/40

Power Protection

Because computing and communicationhas become so essential in thecorporate world, power failure is a much

more devastating event than it was 10 to15 years ago.There are several types of power backup capabilities. Before a companychooses one, it should calculate the totalcost of anticipated downtime and itseffects.

Page 5: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 5/40

Power Protection

There are three main methods of protecting against power problems:

UPSs,power line conditioners, andbackup sources

Page 6: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 6/40

Power Protection A. Uninterrupted Power Supply (UPS) to protect

against a short duration power failure. Thereare two types of UPS:

Online UPS – It is in continual use because theprimary power source goes through it to theequipment. It uses AC line voltage to charge a bankof batteries. When the primary power source fails, aninverter in the UPS will change DC of the batteriesinto AC.Standby UPS – It has sensors to detect for power

failures. If there is a power failure, the load will beswitched to the UPS. It stays inactive before a power failure, and takes more time than online UPS toprovide power when the primary source fails.

Page 7: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 7/40

Page 8: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 8/40

Power Protection

B. Backup power supplies are necessarywhen there is a power failure and theoutage will last longer than a UPS canlast.Backup supplies can be a redundantline from another electrical substation

or from a motor generator and can beused to supply main power or chargethe batteries in a UPS system.

Page 9: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 9/40

Power Protection A company should identify critical systems thatneed protection from interrupted power supplies, and then estimate how longsecondary power would be needed and how

much power is required per device.Some UPS devices provide just enough power to allow systems to shut down gracefully,whereas others allow the systems to run for alonger period.

A company needs to determine whether systems should have only enough power supply to be shut down in a proper manner or actually need to be up and running to keepcritical operations available.

Page 10: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 10/40

Power Protection

The alternate power source should betested periodically to make sure it works,and to the extent expected. It is never good to get all the way to an emergencyonly to find out that the generator doesnot work, or someone forgot to buy the

gas necessary to keep the thing running.

Page 11: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 11/40

Page 12: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 12/40

Page 13: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 13/40

Power Protection Electric Power Issues ...

EMI can be created by the difference between threewires: hot, neutral, and ground, and the magneticfield that they create.Lightning and electrical motors can induce EMI,which could then interrupt the proper flow of electrical current as it travels over wires to, from, andwithin buildings.RFI can be caused by anything that creates radiowaves.

Fluorescent lighting is one of the main causes of RFIwithin buildings today, so does that mean we need torip out all the fluorescent lighting? Well, that is onechoice, but we could also just use shielded cablingwhere fluorescent lighting could cause a problem.

Page 14: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 14/40

Power Protection Electric Power Definitions

Ground The pathway to the earth to enableexcessive voltage to dissipateNoise . Electromagnetic or frequency interferencethat disrupts the power flow and can causefluctuationsTransient noise . Short duration of power linedisruptionInrush current The initial surge of current requiredwhen there is an increase in power demandClean power Electrical current that does notfluctuateEMI Electromagnetic interferenceRFI Radio frequency interference

Page 15: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 15/40

Power Protection

Interference interrupts the flow of anelectrical current, and fluctuations canactually deliver a different level of

voltage than what was expected. Eachfluctuation can be damaging to devicesand people.

The following explains the differenttypes of voltage fluctuations that arepossible with electric power:

Page 16: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 16/40

Page 17: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 17/40

Power Protection

Power degradationSag/dip Momentary low voltage condition,from one cycle to a few seconds

Brownout Prolonged power supply that isbelow normal voltageIn-rush current Initial surge of currentrequired to start a load

Page 18: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 18/40

Power Protection When an electrical device is turned on, itcan draw a large amount of current, whichis referred to as in-rush current. If thedevice sucks up enough current, it can

cause a sag in the available power for thesurrounding devices. This could negativelyaffect their performance.

As stated earlier, it is a good idea to havethe data processing center and devices ona different electrical wiring segment fromthat of the rest of the facility, if possible, sothat the devices will not be affected bythese issues.

Page 19: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 19/40

Power Protection

S urgeA su rge i s a m om entary r i se in vo l tage f rom a po w er so urce . Surgescan cause a lot of damage very quickly.

A surge is one of the most commonpower problems and is controlled with

surge protectors. These protectors use adevice called a metal oxide varistor,which moves the excess voltage toground when a surge occurs.

Page 20: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 20/40

Power Protection S urge ...

Its source can be from a strong lightning strike,a power plant going online or offline, a shift inthe commercial utility power grid, an electrical

equipment within a business starting andstopping. Most computers have a built-in surgeprotector in their power supplies, but these arebaby surge protectors and cannot provideprotection against the damage that larger

surges (as from storms) can cause. So, youneed to ensure that all devices are properlyplugged into larger surge protectors, whoseonly job is to absorb any extra current before itis passed to electrical devices.

Page 21: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 21/40

Power Protection

Blackout A blackout is when the voltage drops tozero. This can be caused by lightning, acar taking out a power line, storms, or failure to pay the power bill. It can lastfor seconds or days. This is when a

backup power source is required for business continuity.

Page 22: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 22/40

Power Protection

Brownout When power companies are experiencinghigh demand, they frequently reduce the

voltage in an electrical grid, which isreferred to as a brownout.Constant voltage transformers can be usedto regulate this fluctuation of power. Theycan use different ranges of voltage andonly release the expected 120 volts,alternating current, to devices.

Page 23: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 23/40

Page 24: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 24/40

Power Protection

NoiseNoise on power lines usually results from atransformer being hit by an automobile,

lightning, and fluorescent lighting.Frequency ranges overlap, which canaffect electrical device operations.

Lightning sometimes produces voltagespikes on communications and power lines, which can destroy equipment or alter data that is being transmitted.

Page 25: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 25/40

Page 26: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 26/40

Power Protection Noise ...

Because these and other occurrences are common,mechanisms should be in place to detect unwantedpower fluctuations, to protect the integrity of the dataprocessing environment.Voltage regulators and line conditioners can be used to ensure a clean and smooth distribution of power.The primary power runs through a regulator or conditioner.They have the capability to absorb extra current if

there is a spike, and to store energy to add current tothe line if there is a sag. The goal is to keep thecurrent flowing at a nice, steady level so that neither motherboard components nor employees get fried.

Page 27: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 27/40

Power Protection

Noise ...Offices usually have different types of devices connected and plugged into thesame outlets. Outlet strips are pluggedinto outlet strips, which are connected toextension cords. This causes more line

noise and reduction of voltage to eachdevice.

Page 28: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 28/40

Page 29: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 29/40

Power Protection Preventive Measures and Good PracticesWhen dealing with electric power issues, thefollowing items can help protect devices and theenvironment:

Plug in every device to a surge protector toprotect from excessive current.Shut down devices in an orderly fashion tohelp avoid data loss or damage to devices dueto voltage changes.Employ power line monitors to detectfrequency and voltage amplitude changes.Use regulators to keep voltage steady andpower clean.

Page 30: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 30/40

Power Protection Preventive Measures and Good Practices ...

Protect distribution panels, master circuitbreakers, and transformer cables with accesscontrols.

Provide protection from magnetic inductionthrough shielded lines.Use shielded cabling for long cable runs.Do not run data or power lines directly over fluorescent lights.Use three-prong connections and adapters if using two-prong cables.Do not plug outlet strips and extension cordsinto each other.

Page 31: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 31/40

Power Protection

Environmental IssuesImproper environmental controls cancause damage to services, hardware,and lives. Interruption of some servicescan cause unpredicted and unfortunateresults.

They all need to be operating properlyand be monitored regularly.

Page 32: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 32/40

Power Protection

Environmental Issues ...During facility construction, the physicalsecurity team needs to make certain that

water, steam, and gas lines have proper shutoff valves, and positive drains,which means their contents flow out instead of in.

If there is ever a break in a main water pipe, the valve to shut off water flowmust be readily accessible

Page 33: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 33/40

Page 34: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 34/40

Power Protection Environmental Issues ...

Similarly, in case of fire in a building, thevalve to shut off the gas lines must bereadily accessible.In case of a flood, a company wants toensure that material cannot travel upthrough the water pipes and into its water supply or facility.

Facility, operations, and security personnelshould know where these shutoff valvesare, and there should be strict proceduresto follow in these types of emergencies.

Page 35: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 35/40

Power Protection Environmental Issues ...

Most electronic equipment must operate in aclimate-controlled atmosphere.

Although it is important to keep the atmosphereat a proper working temperature, it is importantto understand that the components within theequipment can suffer from overheating even ina climate-controlled atmosphere if the internal

computer fans are not cleaned or are blocked.When devices are overheated, the componentscan expand and contract, which causescomponents to change their electroniccharacteristics, reducing their effectiveness or damaging the system overall.

Page 36: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 36/40

Power Protection

Environmental Issues ...Maintaining appropriate temperature andhumidity is important in any facility, especially

facilities with computer systems.Improper levels of either can cause damageto computers and electrical devices. Highhumidity can cause corrosion, and lowhumidity can cause excessive staticelectricity. This static electricity can short outdevices, cause the loss of information.

Page 37: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 37/40

Power Protection Environmental Issues ...

Maintaining appropriate temperature and humidity isimportant in any facility, especially facilities withcomputer systems. Improper levels of either can

cause damage to computers and electrical devices.High humidity can cause corrosion, and lowhumidity can cause excessive static electricity. Thisstatic electricity can short out devices, cause theloss of information.

Lower temperatures can cause mechanisms to slowor stop, and higher temperatures can cause devicesto use too much fan power and eventually shutdown.

Page 38: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 38/40

Power Protection Preventive Steps Against Static ElectricityThe following are some simple measures toprevent static electricity:

Use antistatic flooring in data processing areas.Ensure proper humidity.Have proper grounding for wiring and outlets.Don’t have carpeting in data centers, or havestatic-free carpets if necessary.Wear antistatic bands when working insidecomputer systems.

Page 39: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 39/40

Power Protection Ventilation

Air ventilation has several requirements that must be metto ensure a safe and comfortable environment.

A closed-loop recirculating air-conditioning system shouldbe installed to maintain air quality. “Closed -loop” meansthat the air within the building is reused after it has beenproperly filtered, instead of bringing outside air in.Positive pressurization and ventilation should also beimplemented to control contamination. Positive

pressurization means that when an employee opens a

door, the air goes out, and outside air does not come in. If a facility were on fire, you would want the smoke to go outthe doors instead of being pushed back in when people arefleeing.

Page 40: Security System 1 - 04

8/14/2019 Security System 1 - 04

http://slidepdf.com/reader/full/security-system-1-04 40/40

Power Protection Ventilation

Air ventilation has several requirements that must be metto ensure a safe and comfortable environment.

A closed-loop recirculating air-conditioning system shouldbe installed to maintain air quality. “Closed -loop” meansthat the air within the building is reused after it has beenproperly filtered, instead of bringing outside air in.Positive pressurization and ventilation should also beimplemented to control contamination. Positive

pressurization means that when an employee opens a

door, the air goes out, and outside air does not come in. If a facility were on fire, you would want the smoke to go outthe doors instead of being pushed back in when people arefleeing.