Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, November 9, 2011

Biometric Techniques - Enhancing Security Standards In High Performance Enterprise

INTRODUCTION:

In today's digital economy, where many important activities are carried out with the help of computer, the need for reliable, simple, flexible and secure system is a great concern and a challenging issue for the organisation. Day by day security breaches and transaction fraud increases, the need for secure identification and personal verification technologies is becoming a great concern to the organisation. By measuring something unique about an individual and using that to identify, an organisation can dramatically improve their security measures. Awareness of security issues is rapidly increasing among company how they want to protect the information which is a greatest asset that the company possesses. The organisation wants to protect this information from either internal or external threat. Security plays a very important role in the organization and to make computer system secure, various biometric techniques have been developed. Today biometric techniques are a reliable method of recognising the identity of a person based on physiological or behavioral characteristics. Biometrics techniques exploit human's unique physical or behavioral traits in order to authenticate people. The features measured are face, fingerprints, hand geometry, iris, retinal, voice etc. Biometric authentication is increasingly being used in areas like banking, retailing, defense, manufacturing, health industry, stock exchange, public sector, airport security, internet security etc. Biometric technologies are providing a highly-secure identification and personal verification solutions. Biometric techniques are an attempt in providing a robust solution to many challenging problems in security. Biometrics focuses on the analysis of physical or behavioral traits that determine individual identity. Biometrics can he used to verify the identity of an individual based on the measurement and analysis of unique physical and behavioral data. Indeed, biometrics techniques increasingly are being viewed as the preferred means to confirm an individual's identity accurately.

DISNEY ENTERPRISE

The history of biometric techniques is not new, it trace its origin from the past. The ancient biometric technique which was practiced was a form of finger printing being used in China in the 14th century, as reported by the Portuguese historian Joao de Barros. The Chinese merchants were stamping children's palm and footprints on paper with ink to distinguish the babies from one another. Biometrics the ancient Greek word is the combination of two words -bio means life, metric means measurement.It is the study of methods for uniquely recognizing humans based upon physical or behavioral characterstics. The physiological characterstics are fingerprint, face, hand geometry, DNA and iris recognition. Behavioral are related to the behavior of a person like signature, study of keystroke, voice etc. Thus a biometric system is essentially a pattern recognition system which makes a personal identification by determining the authenticity of a specific physiological or behavioral characteristic possessed by the user. Biometric characteristics are collected using a device called a sensor. These sensors are used to acquire the data needed for verification or identification and to convert the data to a digital code. The quality of the device chosen to capture data has a significant impact on the recognition results. The devices could be digital cameras for face recognition, ear recognition etc or a telephone for voice recognition etc. A biometric system operates in verification mode or identification mode. In verification mode the system validates a person identity by comparing the captured biometric data with the biometric template stored in the database and is mainly used for positive recognition. In the identification mode the system captures the biometric data of an individual and searches the biometric template of all users in the database till a match is not found.

DIFFERENT TYPES OF BIOMETRIC TECHNIQUES

o Face Recognition

The biometric system can automatically recognize a person by the face. This technology works by analyzing specific features in the face like - the distance between the eyes, width of the nose, position of cheekbones, jaw line, chin ,unique shape, pattern etc. These systems involve measurement of the eyes, nose, mouth, and other facial features for identification. To increase accuracy these systems also may measure mouth and lip movement.Face recognition captures characteristics of a face either from video or still image and translates unique characteristics of a face into a set of numbers. These data collected from the face are combined in a single unit that uniquely identifies each person. Sometime the features of the face are analyzed like the ongoing changes in the face while smiling or crying or reacting to different situation etc.The entire face of the person is taken into consideration or the different part of the face is taken into consideration for the identity of a person. It is highly complex technology. The data capture by using video or thermal imaging. The user identity is confirmed by looking at the screen. The primary benefit to using facial recognition as a biometric authenticator is that people are accustomed to presenting their faces for identification and instead of ID card or photo identity card this technique will be beneficial in identifying a person. As the person faces changes by the age or person goes for plastic surgery, in this case the facial recognition algorithm should measure the relative position of ears, noses, eyes and other facial features.

o Hand Geometry:

Hand geometry is techniques that capture the physical characteristics of a user's hand and fingers. It analyses finger image ridge endings, bifurcations or branches made by ridges. These systems measure and record the length, width, thickness, and surface area of an individual's hand. It is used in applications like access control and time and attendance etc. It is easy to use, relatively inexpensive and widely accepted. A camera captures a 3 dimensional image of the hand. A verification template is created and stored in the database and is compared to the template at the time of verification of a person. Fingerprint identification.Currently fingerprint readers are being built into computer memory cards for use with laptops or PCs and also in cellular telephones, and personal digital assistants. It is successfully implemented in the area of physical access control.

o Eye Recognition:

This technique involves scanning of retina and iris in eye. Retina scan technology maps the capillary pattern of the retina, a thin nerve on the back of the eye. A retina scan measures patterns at over 400 points. It analyses the iris of the eye, which is the colored ring of tissue that surrounds the pupil of the eye. This is a highly mature technology with a proven track record in a number of application areas. Retina scanning captures unique pattern of blood vessels where the iris scanning captures the iris. The user must focus on a point and when it is in that position the system uses a beam of light to capture the unique retina characterstics.It is extremely secure and accurate and used heavily in controlled environment. However, it is expensive, secure and requires perfect alignment and usually the user must look in to the device with proper concentration. Iris recognition is one of the most reliable biometric identification and verification methods. It is used in airports for travellers.Retina scan is used in military and government organization. Organizations use retina scans primarily for authentication in high-end security applications to control access, for example, in government buildings, military operations or other restricted quarters, to authorized personnel only. The unique pattern and characteristics in the human iris remain unchanged throughout one's lifetime and no two persons in the world can have the same iris pattern.

o Voice Biometrics

Voice biometrics, uses the person's voice to verify or identify the person. It verifies as well as identifies the speaker. A microphone on a standard PC with software is required to analyze the unique characteristics of the person. Mostly used in telephone-based applications. Voice verification is easy to use and does not require a great deal of user education. To enroll, the user speaks a given pass phrase into a microphone or telephone handset. The system then creates a template based on numerous characteristics, including pitch, tone, and shape of larynx. Typically, the enrollment process takes less than a minute for the user to complete. Voice verification is one of the least intrusive of all biometric methods. Furthermore, voice verification is easy to use and does not require a great deal of user education.

o Signature Verification

Signature verification technology is the analysis of an individual's written signature, including the speed, acceleration rate, stroke length and pressure applied during the signature. There are different ways to capture data for analysis i.e. a special pen can be used to recognize and analyze different movements when writing a signature, the data will then be captured within the pen. Information can also be captured within a special tablet that measures time, pressure, acceleration and the duration the pen touches it .As the user writes on the tablet, the movement of the pen generates sound against paper an is used for verification. An individual's signature can change over time, however, which can result in the system not recognizing authorized users. Signature systems rely on the device like special tablet, a special pen etc. When the user signs his name on an electronic pad, rather than merely comparing signatures, the device instead compares the direction, speed and pressure of the writing instrument as it moves across the pad.

o Keystroke

This method relies on the fact that every person has her/his own keyboard-melody, which is analysed when the user types. It measures the time taken by a user in pressing a particular key or searching for a particular key.

OTHER BIOMETRIC TECHNIQUES ARE
o Vein/vascular patterns: Analyses the

veins in, for example, the hand and the face.

o Nail identification: Analyses the tracks in the nails.

o DNA patterns: it is a very expensive technique and it takes a long time for verification/identification of a person

o Sweat pore analysis: Analyses the way pores on a finger are located.

o Ear recognition: Shape and size of an ear are unique for every person.

o Odour detection: Person is verified or identified by their smell.

o Walking recognition: It analyses the way the person walks.

METHODS OF BIOMETRIC AUTHENTICATION:

o VERIFICATION : is the process of verifying the user is who they claim to be.

o IDENTIFICATION : is the process of identifying the user from a set of known users.

WORKING OF BIOMETRICS:

All biometric systems works in a four-stage process that consists of the following steps.

o Capture: A biometric system captures the sample of biometric characteristics like fingerprint, voice etc of the person who wants to login to the system.

o Extraction: Unique data are extracted from the sample and a template is created. Unique features are then extracted by the system and converted into a digital biometric code. This sample is then stored as the biometric template for that individual.

o Comparison: The template is then compared with a new sample. The biometric data are then stored as the biometric template or template or reference template for that person.

o Match/non-match: The system then decides whether the features extracted from the new sample are a match or a non-match with the template. When identity needs checking, the person interacts with the biometric system, a new biometric sample is taken and compared with the template. If the template and the new sample match, the person's identity is confirmed else a non-match is confirmed.

[Biometric Authentication System and its functional components]

The Biometric authentication system includes three layered architecture:

o Enroll: A sample is captured from a device, processed into a usable form from which a template is constructed, and returned to the application.

o Verify: One or more samples are captured, processed into a usable form, and then matched against an input template. The results of the comparison are returned.

o Identify: One or more samples are captured, processed into a usable form, and matched against a set of templates. A list is generated to show how close the samples compare against the top candidates in the set.

A biometric template is an individual's sample, a reference data, which is first captured from the selected biometric device. Later, the individual's identity is verified by comparing the subsequent collected data against the individual's biometric template stored in the system. Typically, during the enrollment process, three to four samples may be captured to arrive at a representative template. The resultant biometric templates, as well as the overall enrollment process, are key for the overall success of the biometric application. If the quality of the template is poor, the user will need to go through re-enrollment again. The template may be stored, within the biometric device, remotely in a central repository or on a portable card.

Storing the template on the biometric device has the advantage of fast access to the data. There is no dependency on the network or another system to access the template. This method applies well in situations when there are few users of the application. Storing the template in a central repository is a good option in a high-performance, secure environment. Keep in mind that the size of the biometric template varies from one vendor product to the next and is typically between 9 bytes and 1.5k. For example, as a fingerprint is scanned, up to 100 minutia points are captured and run against an algorithm to create a 256-byte binary template. An ideal configuration could be one in which copies of templates related to users are stored locally for fast access, while others are downloaded from the system if the template cannot be found locally.

Storing the template on a card or a token has the advantage that the user carries his or her template with them and can use it at any authorized reader position. Users might prefer this method because they maintain control and ownership of their template. However, if the token is lost or damaged, the user would need to re-enroll. If the user base does not object to storage of the templates on the network, then an ideal solution would be to store the template on the token as well as the network. If the token is lost or damaged, the user can provide acceptable identity information to access the information based on the template that can be accessed on the network. The enrollment time is the time it takes to enroll or register a user to the biometric system. The enrollment time depends on a number of variables such as: users' experience with the device or use of custom software or type of information collected at the time of enrollment

Biometric Performance Measures:

o False acceptance rate (FAR) or False match rate (FMR): the probability that the system incorrectly declares a successful match between the input pattern and a non-matching pattern in the database. It measures the percent of invalid matches. These systems are critical since they are commonly used to forbid certain actions by disallowed people.

o False reject rate (FRR) or False non-match rate (FNMR): the probability that the system incorrectly declares failure of match between the input pattern and the matching template in the database. It measures the percent of valid inputs being rejected.

o Receiver (or relative) operating characteristic (ROC): In general, the matching algorithm performs a decision using some parameters (e.g. a threshold). In biometric systems the FAR and FRR can typically be traded off against each other by changing those parameters. The ROC plot is obtained by graphing the values of FAR and FRR, changing the variables implicitly. A common variation is the Detection error trade-off (DET), which is obtained using normal deviate scales on both axes.

o Equal error rate (EER): The rates at which both accept and reject errors are equal. ROC or DET plotting is used because how FAR and FRR can be changed, is shown clearly. When quick comparison of two systems is required, the ERR is commonly used. Obtained from the ROC plot by taking the point where FAR and FRR have the same value. The lower the EER, the more accurate the system is considered to be.

o Failure to enroll rate (FTE or FER): the percentage of data input is considered invalid and fails to input into the system. Failure to enroll happens when the data obtained by the sensor are considered invalid or of poor quality.

o Failure to capture rate (FTC): Within automatic systems, the probability that the system fails to detect a biometric characteristic when presented correctly.

o Template capacity: the maximum number of sets of data which can be input in to the system.

For example, performance parameters associated with the fingerprint reader may be:

o a false acceptance rate of less than or equal to 0.01 percent

o a false rejection rate of less than 1.4 percent

o the image capture area is 26×14 mm.

Obviously, these two measures should be as low as possible to avoid authorized user rejection but keep out unauthorized users. In applications with medium security level a 10% False Rejection Error will be unacceptable, where false acceptance rate error of 5% is acceptable.

False Acceptance When a biometric system incorrectly identifies an individual or incorrectly verifies an impostor against a claimed identity. Also known as a Type II error. False Acceptance Rate/FAR

The probability that a biometric system will incorrectly identify an individual or will fail to reject an impostor. Also known as the Type II error rate.

It is stated as follows:

FAR = NFA / NIIA or FAR = NFA / NIVA

where FAR is the false acceptance rate

NFA is the number of false acceptances

NIIA is the number of impostor identification attempts

NIVA is the number of impostor verification attempts

False Rejection Rate/FRR The probability that a biometric system will fail to identify an enrollee, or verify the legitimate claimed identity of an enrollee. Also known as a Type I error rate.

It is stated as follows:

FRR = NFR / NEIA or FRR = NFR / NEVA

where FRR is the false rejection rate

NFR is the number of false rejections

NEIA is the number of enrollee identification attempts

NEVA is the number of enrollee verification attempts

Crossover Error Rate (CER)

Represents the point at which the false reject rate = the false acceptance rate.

Stated in percentage

Good for comparing different biometrics systems

A system with a CER of 3 will be more accurate than a system with a CER of 4

BIOMETRICS USE IN INDUSTRY

Punjab National Bank (PNB) installed its first biometric ATM at a village in Gautam Budh Nagar (UP) to spread financial inclusion. "The move would help illiterate and semi-literate customers to do banking transaction any time.

Union Bank of India biometric smart cards launched. Hawkers and small traders could avail loan from the bank using the card.

In Coca-Cola Co., hand-scanning machines are used to replace the time card monitoring for the workers. In New Jersey and six other states, fingerprint scanners are now used to crack down on people claiming welfare benefits under two different names.

In Cook County, Illinois, a sophisticated camera that analyzes the iris patterns of an individual's eyeball is helping ensure that the right people are released from jail. At Purdue University in Indiana, the campus credit union is installing automated teller machines with a finger scanner that will eliminate the need for plastic bankcards and personal identification numbers.

MasterCard International Inc. and Visa USA Inc., the world's two largest credit card companies, have begun to study the feasibility of using finger-scanning devices at the point of sale to verify that the card user is really the card holder. The scanners would compare fingerprints with biometric information stored on a microchip embedded in the credit card.
Walt Disney World in Orlando has started taking hand scans of people who purchase yearly passes. These visitors now must pass through a scanner when entering the park preventing them from lending their passes to other people.

The technology also received widespread attention at summer's Olympic Games Atlanta, where 65,000 athletes, coaches and officials used a hand-scanning system to enter the Olympic Village.

Selection of Biometric Techniques:

There are a lot of decision factors for selecting a particular biometric technology for a specific application.

1. Economic Feasibility or Cost:-The cost of biometric system implementation has decreased recently; it is still a major barrier for many companies. Traditional authentication systems, such as passwords and PIN, require relatively little training, but this is not the case with the most commonly used biometric systems. Smooth operation of those systems requires training for both systems administrators and users.

2. Risk Analysis:-Error rates and the types of errors vary with the biometrics deployed and the circumstances of deployment. Certain types of errors, such as false matches, may pose fundamental risks to business security, while other types of errors may reduce productivity and increase costs. Businesses planning biometrics implementation will need to consider the acceptable error threshold.

3. Perception of Users:-Users generally view behavior-based biometrics such as voice recognition and signature verification as less intrusive and less privacy-threatening than physiology-based biometrics.

4. TechnoSocio Feasibility:-Organizations should focus on the user-technology interface and the conditions in the organizational environment that may influence the technology's performance. The organization should create awareness among the users how to use the techniques and should overcome the psychological factors as user fears about the technology. Organization has to also consider the privacy rights of users while implementing the biometric techniques.

5. Security: Biometric techniques should have high security standards if they will be implemented in high secure environment. The biometric techniques should be evaluated on the basis of their features, potential risk and area of application, and subjected to a comprehensive risk analysis.

6. User friendly and social acceptability -Biometric techniques should be robust and user friendly to use and they should function reliably for a long period of time. The techniques should not divide the society into two group i.e. digital and non digital society.

7. Legal Feasibility-Government has to form a regulatory statutory framework for the use of biometric techniques in various commercial applications. It should form a standard regulatory framework for use of these techniques in commercial applications or transactions. If required the framework has to be regulated and changed time to time.

8. Privacy-As biometric techniques rely on personal physical characteristics, an act has to be made to protect the individual's privacy data not to be used by other. A data protection law has to be created in order to protect the person's privacy data.
Criteria for evaluating biometric technologies.

The reliability and acceptance of a system depends on the effectiveness of the system, how the system is protected against unauthorized modification, knowledge or use, how the systems provide solutions to the threats and its ability and effectiveness to identify system's abuses.

These biometric methods use data compression algorithms, protocols and codes. These algorithms can be classified in three categories:

o Statistical modeling methods,

o Dynamic programming,

o Neural networks.

The mathematical tools used in biometric procedure need to be evaluated. Mathematical analysis and proofs of the algorithms need to be evaluated by experts on the particular fields. If algorithms implement "wrong" mathematics then the algorithms are wrong and the systems based on these algorithms are vulnerable. If the algorithms used in the biometric methods have "leaks", or if efficient decoding algorithms can be found then the biometric methods themselves are vulnerable and thus the systems based on these methods become unsafe.

Different algorithms offer different degrees of security, it depends on how hard they are to break. If the cost required to break an algorithm is greater than the value of the data then we are probably safe. In our case where biometric methods are used in financial transactions where a lot of money is involved it makes it worth it for an intruder to spend the money for cryptanalysis.

The cryptographic algorithms or techniques used to implement the algorithms and protocols can be vulnerable to attacks. Attacks can also be conceived against the protocols themselves or aged standard algorithms. Thus criteria should be set for the proper evaluation of the biometric methods addressing these theoretical concerns.

The evaluation of the biometric systems is based on their implementation. There are four basic steps in the implementation of the biometric systems which impose the formation of evaluative criteria.

o Capture of the users attribute.

o Template generation of the users attribute.

o Comparison of the input with the stored template for the authorized user.

o Decision on access acceptance or rejection.

Applications of biometric techniques

Biometrics is an emerging technology which has been widely used in different organization for the security purpose. Biometrics can be used to prevent unauthorized access to ATMs, cellular phones, smart cards, desktop PCs, workstations, and computer networks. It can be used during transactions conducted via telephone and Internet (electronic commerce and electronic banking). Due to increased security threats, many countries have started using biometrics for border control and national ID cards. The use of biometric identification or verification systems are widely used in different companies as well as the government agencies. The applications where biometric technique has its presence are

o Identity cards and passports.

o Banking, using ATMs, Accessing Network Resource

o Physical access control of buildings, areas, doors and cars.

o Personal identification

o Equipment access control

o Electronic access to services (e-banking, e-commerce)

o Travel and Transportation, Sporting Event

o Border control

o Banking and finance, Shopping Mall

o Airport security

o Cyber security

o Time Management in Organization

o Voice Recognition(Telebanking)

o Prison visitor monitoring system.

o Voting System

Prospects of Biometric Techniques:

The biometric industry is at an infancy stage in India, but is growing fast to capture the entire market. This technique is expanding both into private and public areas of application. Biometric applications need to interconnect to multiple devices and legacy applications. The industry market and consumer markets are adopting biometric technologies for increased security and convenience. With the decreasing price of biometric solutions and improved technology, more organization is coming forward to implement this technology. The lack of a standard regulatory framework is a major drawback in implementing biometrics in organisation.It is not widely accepted by the users because some organization and society have the opinion that this technology is inappropriate and the privacy data of the users are lost. If proper regulatory framework is not established it will not be accepted by the organization as well as by the user. The devices manufactured for biometric techniques has to comply with standards Increased IT spending in the government and financial sector offers better opportunities for such deployments. Even though there are no global mandated or regulatory frame works as of now, they are expected to arrive very soon.
Standarad law and regulation will open a wide market for biometrics in electronic legal and commercial transactions.

The anti-terrorism act has introduced has a wide scope for the biometric techniques to be implemented.

Consumer privacy data has to be protected in order to be widely accepted by the user.
Integration of biometric with different legacy application and hardware.

Biometric technique has a great demand in the telecommunication domain.

The notebook and laptop manufacturer has already implemented the biometric techniques like finger printing for the enhancement of the security.

The biometric industry must address major challenges related to performance, real-world utility, and potential privacy impact in order for biometrics to reach their full potential
Many companies are also implementing biometric technologies to secure areas, maintain time records, and enhance user convenience.

An interesting biometric application is linking biometrics to credit cards.

Other financial transactions could benefit from biometrics, e.g., voice verification when banking by phone, fingerprint validation for e-commerce, etc. The market is huge, and covers a very wide range of hardware, applications and services.

Conclusion:

The future of this technology is booming. With the rapid increase of fraud and theft in commercial transaction; it is a great concern for the organization to use biometric as key instrument in eliminating the fraud and flaws in the traditional security approach. Both businesses and consumers are anxious for greater security in commercial transactions. The technology is increasingly reliable and affordable, and the question of the legal enforceability of electronic contracts is settled. While consumers recognize the benefits of biometric authentication, they are reluctant to fully accept the technology without adequate assurances that companies will keep their biometric information confidential and subject to various safeguards and the existing law provides a limited measure of protection for biometric information so greater protection should be offered to consumers so that their personal information is not misused. Biometrics will play vital roles in the next generation of automatic identification system. Biometric identifiers must be considered when implementing a biometric-based identification system. The applicability of specific biometric techniques depends heavily on the application domain. Biometrics must be implemented properly to be effective and the consequences considered. Biometrics will become increasingly prevalent in day-to-day activities where proper identification is required. The real future of the technology lies in creating a biometric trust infrastructure that allows private sector and the public sector to handle security needs. Ultimately, such an infrastructure would allow people to move to various locations worldwide while maintaining their security clearance as defined by their physiological and behavioral identities.

Biometric Techniques - Enhancing Security Standards In High Performance Enterprise

DISNEY ENTERPRISE

Monday, October 3, 2011

The Need for Physical and IT Security Convergence

Business security professionals make it a point to study their craft and learn ways to counter evolving threat. Business intelligence methods need to continue to keep up with technology to analyze and prevent the internal and external influences that can ruin the enterprise. The threats corporations face include: theft, vandalism, workplace violence, fraud, and computer attacks. Through a system of identification, analysis, risk assessment operation security and prevention, astute managers can mitigate risks.

Theft affects all. On average the median loss of theft of cash and non-cash assets is 3,000 (ACFE). The costs of theft are passed on to consumers to bear the cost of the loss. A simple way for companies in retail to get back from a bottom line loss is to pass the costs on by increasing the top line. Raising prices is a symptom of theft, but not a cure. It does nothing by itself to stop the activity other than punish the innocent.

ENTERPRISE PORTAL

Many companies have invested in security staff. This staff focuses efforts to identify and prevent theft. Many businesses have created "loss prevention" jobs. The whole career is oriented on identifying risky behavior, observing others, investigating theft, and finding methods of reducing risk. In retail, they may be secret shoppers; in transportation they may be monitoring cameras and patrolling as guards, or dressed in business suits advising in board rooms.

Information technology (IT) and lessons from business intelligence (BI) can be applied to detecting and preventing theft. For the internal threat, access can be controlled by badge or biometrics. Capabilities of these can limit access by employee, time of day, and certain days of the week. For example, employees that work in the warehouse can access their warehouse doors, but cannot gain entry to the supply department. Those who have janitorial privileges with their access cards can only do so during work hours and not when the business is closed.

Other IT help includes closed circuit television (CCTV). This is a great deterrent and detection device for both the internal and external threat. Current technologies allow the use of tilt/pan/zoom cameras that can record digital data for months. This data can be reviewed to see the habits and patterns of suspect customers and employees. All of this leaves a data trail that can be put into a data warehouse. Besides employee protection and assistance roles, this data can be mined to see patterns and recognize traits of potential perpetrators. For example, a supply bin in a warehouse may suffer shortage at each inventory. The installation of a CCTV device would provide digital feedback of whether or not supplies are being stolen and who is doing the stealing.

Sabotage and vandalism is a constant threat and can be categorized with workplace violence, criminal trespass activities, and industrial espionage or in conjunction with a theft. Though it is a rare, its costs are heavy and depending where in the supply chain the product is, the expense may fall on the company or the customer. Here supply chain is a generic term, but is used to identify an IT tool that provides and automated tracking of inventory and information along business practices. These practices can include campuses, apartments, retail, transportation, factories and other industries.

Security solutions to detect and prevent include monitoring the workplace and removing the internal threat, building security in depth to prevent the external threat, training employees on operation security, and employing loss prevention techniques. Other effective measures against vandalism and sabotage include volunteer forces, employee incentive programs and other organizations such as neighborhood watch programs. Industry, churches, community activity centers and schools have learned the value of relying on volunteers. Volunteers serve as force multiplies that report criminal activities like vandalism to the proper authorities.

Employee workplace violence makes huge headlines for a very good reason. It is shocking behavior with the most serious events resulting in multiple deaths. These incidents lead to law suits, low morale, a bad reputation for the company and leaves families and victims devastated. In 2003, workplace violence led to 631 deaths, the third leading cause of job related injury deaths (BLS).

This is acts of abuse physical or verbal that is taken out on employees, customers or other individuals at a place of business. For the purpose of this paper, the workplace is identified as a corporate building, warehouse, gas station, restaurant, school, taxi cab or other place where people engage in business.

Not all violence in the workplace end in death. They range from simple assault to much worse. What ever the level of crime, innocent people are attacked at the work place. In the corporate world this may be shocking. In other industries like law enforcement, retail sales and health care systems it is much different. These three have the most incidents. The US department of Justice conducted a study on workplace violence from 1993 to 1999. In this study they found that 1.7 million workers fell victim to many types of non-fatal crime. These crimes include, rape, assault, robbery, and sexual assault. These studies don't always mean employee on employee violence, but include outsider on employee violence and vice versa (DETIS).

Concerning homicides at the workplace, it is very expensive. For the risk of sounding cold, the average mean cost of a work related homicide from 1992 to 2001 was a round 0,000. The total cost of homicides during those years was almost .5 billion (ASIS). These cold hard facts derived from the National Institute for Occupational Safety and Health (NIOSH) are what industry must deal with in creating their risk management plan. It is a tough but necessary evil that must be calculated.

When dealing with these facts and creating a mitigation plan, industry has to make choices to protect the workplace. The company has two obligations. The first includes the legal responsibility of the employer to protect and safeguard against preventable harm. This includes all those who work in or visit the workplace. The second responsibility is to handle incidents and investigations, discipline and other processes appropriately (ASIS). It is as important to respect the rights of all persons involved throughout the prevention and investigation processes.

All departments in the enterprise are involved in the prevention and detection. All can contribute to the design, construction, and use of the data warehouse necessary for executing this type of prevention and detection. Each part could maintain a data mart with senior managers mining from the entire warehouse. In this scenario, all team members would build the data base with discriminating features. Alone, these features would probably not mean much, but any behaviors or habits when combined, may identify an abuser.

The more serious discriminators would be identified and "non-hire" criteria. For example, one discriminator that would prevent a person from getting a job would be a history of violence. This would be identified in during the employee pre-employment screening phase. Another would be specific questions about performance during the interview that might indicate propensity for violence or not being able to work well with others.

By building these rules, all sources could contribute to the database to identify high risk people throughout the employment. Rules could be input that when breached, could help management make a determination of who might be a threat to harmony in the workplace. For example, HR can input results of pre-employment background checks, job interview records and disciplinary actions within the company. Managers could provide information from performance reviews about questionable comments. Employees could make anonymous tips about other employees concerning their behavior.

Employees' may not be the threat. Nature of customers, friends and family members could provide risk to the work place. These criteria could be identified as well. Employees who have abusive partners or spouses and employees who perform in risky environments such as retail must be considered in the risk analysis and data warehouse input.

Some additional mitigating factors for employee workplace violence include traditional security methods. Additional lighting in darker areas, an armed guard, security cameras and panic alarms do wonders to give employees a peace of mind as well as help prevent violent behavior. Knowing security is in place deters the criminal element. These security measures could be linked in a network to provide feedback and evidence for use in analyzing and determining actions to prevent this behavior.

Occupational fraud describes the use of "one's occupation for personal enrichment through the deliberate misuse of resources or assets" (ACFE). Whether an employee feels entitled to his fair share, is disgruntled or other reasons, this crime is costly. The median cost to business for this scheme is 9,000. Some reported fraud cases have cost upward of billion (ACFE). Fraud accounts for approximately five percent of losses of their annual revenues or 2 billion in fraud losses.

This crime can be broken down into three categories: Asset misappropriation, corruption, and fraudulent statement. Examples of asset misappropriation include fraudulent invoicing, payroll fraud, and skimming revenue. Corruption can involve bribery and conduction business laced with undisclosed conflict of interest. Fraudulent statement covers booking fictitious sales and recording expenses in the wrong period (ACFE).

Fraud losses affect small business the greatest. For example, compared to the median loss of all businesses, small businesses suffer median losses of 0,000. Losses like these can devastate an unwitting company and fraud can continue for 18 months before being detected (ACFE). Whenever possible, business should focus on reducing both the mean cost of a fraud incident as well as the time it takes to reduce the fraud discovery timeline.

Out of all industries, fraud causes the highest median losses per scheme in whole sale trade, construction and manufacturing. Government and retail has the lowest losses per scheme (ACFE). These industries have a huge impact on costs of finished product. Wholesale trade, construction and manufacturing all wrap up the costs in the final product. Of course the costs aren't recovered immediately. In construction and some manufacturing, the jobs are bid on and regardless of losses; the project must be completed at or below cost of bid. However, later bids may be higher as a result to gain back costs.

Believe it or not, the position of who commit fraud is directly related to the cost of the fraud. For example, the losses caused by owners or executives in a business are 13% higher than the losses caused by employees (ACFE). Managers may not be sticking product in their pockets and sneaking out the door. People in higher positions can be found falsifying travel reports, creating false accounts, diverting payment and other crimes. Some of this is evident as we continue to prosecute chief officers involved in huge schemes.

Fraud is difficult to detect and many schemes can continue for long periods of time before they are detected. Detection can be accidental, the result of a tip, an audit (internal, external or surprise), hotline or as referred to by law enforcement. Focus and discipline could be perceived as the best means to detect fraud. Paying attention to patterns, verifying paperwork and checking records is time consuming, but must be performed.

The most successful but less used method to detect fraud involves the input of employees. Training employees on fraud and awareness cuts down on the time span of a fraud as well as the overall cost. Training increases morale in many ways and creates a team like atmosphere. Business can gain from the proper training. Employees are a great resource in fraud prevention. There has been great success with using hotlines and anonymous reporting to detect and deter fraud (ACFE).

Information technology (IT) and lessons from business intelligence (BI) can be applied to detecting and preventing fraud. We have already mentioned that employee and hotline tips are most effective but business doesn't take advantage of this. Computer links could be set up on corporate sites to allow employees to report fraud. Some methods could include survey, direct question and answer, or just a space for reporting.

The audit, hotlines and tips are effective after or during the commission of the lengthy fraud period. These are all reactionary events. What about being proactive? Many companies have the capability to automate almost everything. Time sheets, accounting, billing, production and supply chain records are often on a server. Most require supervisor approval or at the very least have the capability of real time monitoring. This information can be integrated into a company version of a data warehouse and be manipulated according to the input rules. Specific habits of employees can be pulled to look for and address financial inconsistencies.

As mentioned earlier, businesses have employed access control measures such as card scanners, code readers and biometrics. They leave a trail of employee activity and regardless of position all are required to enter information to gain entry. Computer keyboard activity can be limited by password protection and all media should go through the security department before introduction or removal. All of this leaves a data trail that can be put into a data warehouse. Besides employee protection and assistance roles, this data can be mined to see patterns and recognize traits of potential perpetrators.

Finally, computer attacks are a huge risk to all businesses. The threat of hackers, malicious viruses, and those who hijack websites and hold financial transactions for ransom are just a few serious events of which the security manager must the aware. Data can be destroyed, reputations can be ruined, and lives can be stolen. These attacks can cripple an enterprise and could take months or years to recover. Businesses need to have IT tools to detect and combat this type of threat as soon as possible. Identity protection and other computer related incidents requires the same type of protection afforded to an employee as in the section about employee workplace violence.

Worms and viruses are quickly destroying years of input. These threats appear innocently enough in the beginning and when the right time comes, they activate. They recreate themselves, and spread through out networks and stand alone systems. Hackers continually knock at the internet portal trying to learn passwords and the inner most secrets of protect to exploit for espionage, theft or horrible fun. Hijackers enter a system and threaten to cripple financial transactions until payment is made; extortion in high-tech form.

Unprotected systems perpetuate all the above threats. Businesses that get involved either innocently as naive contributors or as the hapless victims suffer greatly financially and productively. There is another cost that could take longer to recover from. This is the of their valuable reputations with their customers. A technically illiterate or unprotected business has no excuse when dealing with customers or partners. Embarrassing things happen when a virus or cyber trail leads to a witless company. Industry cannot take the risk.

There are many existing security methods available to help companies take the offense against such attack. As the in the above examples, this effort takes the coordination, input and involvement of all business units and departments in the organization. This cannot be given to the security department alone to handle, however such actions should be accountable to one department.

There are new positions created called Chief Security Officer (CSO) and Chief Information Officer (CIO). The hot new topic for these positions is convergence. Convergence is the alignment of physical and information security under the same department. According to CSO Magazine, this should be run by one point of contact being the CSO. This can align physical security, information security, compliance and privacy under one function. This enables the security executive to address Insurance Portability and Accountability Act and Sarbanes-Oxley with focus and intent (CSO Online).

Other aggressive measures that can be taken are password protection, rules on internet use, firewalls and internet access blocking. These can be regulated with the convergence concept. Software already exists to help generate and protect passwords on network and stand alone systems. These help ensure not only that authorized users are accessing the systems, but they also provide a basis for auditing systems. This is vital to protect a company from the threat of social engineering. Information technology can track who used which system to access which information. The user leaves an automatic automated electronic trail.

Companies need a firewall to protect information from both leaving and entering the enterprise system. These firewalls help prevent hacking, high jacking and malicious viruses. The firewall needs to be updated regularly with updates. Most importantly, the CSO or CIO should be checking and running analysis identifying the threat. This analysis of threat and defenses can be conducted the same way as military strategy.

This identification should track where the threat is coming from, how often the defenses are probed, what the threat using to probe the defenses is, and what times of day are the threats the strongest. For operations security, the chief should look at what makes their business so tempting to the threat.

When a chief information or security officer analyses his own operation, they should be trying to identify strengths and weaknesses that the adversary is trying to exploit. When is the IT asset most vulnerable? Are our passwords easy to break? How much intrusion would it take to stop our operations? Are just a few questions that must be analyzed along with external threat analysis.

Internet discipline is also vital. An enemy doesn't have to break down your defenses to wreak havoc. Just like old vampire lore, all you have to do is invite them in. When employees visit unauthorized websites, download unauthorized software, transfer data from a home computer or forward corrupted email, they can cause just as much harm. Blocking websites, allowing only IT personnel to upload software, and screening all mobile media or preventing all media such as CDs and other portable storage devices is crucial to protecting the enterprise.

As mentioned in other paragraphs, protecting your company with security in depth will solve many problems. This security in depth includes previously mentioned biometric or card reader access devices, alarms and CCTV cameras. These are available IT devices that are popular and effective at monitoring employee movement and activity. The chief can also store vital risk assessment detail in a data warehouse to better analyze events and proactively mitigate risks before damage occurs.

As mentioned throughout this paper, somebody needs to take charge of organizing a multiple business unit task force to protect the company. Traditional methods of segmenting units and having them work in a vacuum do not produce effective results. When the IT department handles all internet activity, human resources execute the laying off offenders, finance department handle all payroll discrepancies and accounting performs all audits, the result is a broken chain of incomplete activity.

The willing participation and information sharing is better handled in the form of a committee. Each respective department can do their day to day activities, but results can be presented to the entire group to help detect and determine any one of the threats addressed in this paper.

We began with the news reports of businesses needing to protect their personnel and the assets. We showed examples from the headlines of people coming to places of business to conduct senseless acts of terrorism and violence and the need for having a corporate culture or environment to address the different types of threats. This culture involves quickly evolving the role of security to become the protector of personnel, facilities and product. This evolution will enable them to use IT as a tool to help detect and deter risks to the enterprise.

Having said that, we can conclude that security professionals need to continue to make it a point to study their craft and learn ways to counter evolving threat. Business intelligence methods need to continue to keep up with technology to analyze and prevent the internal and external influences that can ruin the enterprise. The threats corporations face include: theft, vandalism, workplace violence, fraud, and computer attacks. We have reviewed the roles of security to converge traditional physical protection with the capabilities of IT systems. The IT can provide a great tool to enterprise as a system of identification, analysis, risk assessment operation security and prevention, astute managers can mitigate risks.

Works Cited:

ACFE. 2006 ACFE Report To The Nation On Occupational Fraud & Abuse, Association of Certified Fraud Examiners, Austin, TX, 2006

American Society of Industrial Security, Workplace Violence Prevention and Response, ASIS International, 2005

Detis. Violence in the workplace, 1993-1999. NCJ 190076. December 2001

Berinato, Scott; Carr, Kathleen; Datz, Todd; Kaplan, Simone and Scalet, Sarah. CSO Fundamentals: ABCs of Physical and IT Security Convergence. CSO Magazine. [http://www.csoonline.com/fundamentals/abc_convergence.html]

Cummings, Maeve; Haag, Stephen; Phillips, Amy, Management Information Systems for the Information Age. McGraw-Hill. New York, NY 2007

The Need for Physical and IT Security Convergence

Jeffrey W. Bennett is a corporate security officer and holds the Industrial Security Professional (ISP)certification. Jeff is also the founder of LayMentor Ministries. This organization teaches volunteers how to lead with concepts similar to those taught in most MBA programs. Additionally, Jeff writes and teaches on the ISP certification. For more information on this article, practice test questions and the upcoming book, visit: http://www.ispcert.com

Jeff is also the author of the Adventure novel Under the Lontar Palm available on line at http://www.jeffreywbennett.com or in major and online bookstores

ENTERPRISE PORTAL