How Does Physical Security Affect Networks?

TL;DR
Network-connected access control and surveillance systems can create vulnerabilities when they share infrastructure with business applications but remain operationally siloed from IT security. Organizations can reduce these risks by authenticating every connected device, protecting transmitted and stored data, coordinating physical and IT security, using common credentials, and linking building-presence records to network access policies.
Transcript
Hi, I'm Bob Belisle, and today, along with my co-presenter, Ray Coulombe, we're going to discuss does physical security on the network create new vulnerabilities? I'm gonna go ahead and lead the discussion, and I'm gonna come at this from a top-down perspective in terms of how physical security and network security can work together and what those ... Read More
Key Insights
- Physical security systems have historically been siloed and frequently operated on analog or manufacturer-specific technologies, but access control and video surveillance products increasingly connect to the same IP infrastructure used by business applications and supported by IT security.
- Shared network infrastructure does not automatically produce coordinated security because physical and IT systems may still exchange little or no information. Without integration, organizations lack a holistic view of breaches and compliance issues that cross the boundary between facility access and network activity.
- Separate provisioning creates avoidable security gaps because physical facility permissions, network privileges, and HR records may be maintained in different systems. Deprovisioning a departing or reassigned user can therefore require removal from two or potentially three independent systems.
- Combined activity reporting can reveal suspicious behavioral changes by connecting physical and digital events. Entering rooms or buildings that a person does not normally visit, followed by access to unfamiliar network resources without a role change, can indicate a potential security problem.
- Executive concern about convergence is substantial because 73 percent of the surveyed CIOs, CSOs, and CISOs believed that a vulnerability in either physical or IT security could cause a breach in the system that was not originally vulnerable.
- Trusted network participation requires content, applications, infrastructure, people, and devices to receive appropriate security treatment. Connected physical security devices should be authenticated, assigned suitable rights and privileges, and prevented from exposing stored or transmitted information.
- Common smart-card credentials can strengthen authentication because their microprocessors can perform cryptographic functions, securely store biometric templates, and participate in certificate checking. The presentation reports that a Department of Defense study found a significant fraud reduction after adopting a credential for building, computer, and network access.
- Physical presence can become a network access requirement by sending badge events from the physical security server through a metadata server to a network access control appliance. Access is granted only when presence, username and password, device health, and applicable policies all match.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How can physical security systems create network vulnerabilities?
Physical security systems can create network vulnerabilities when access control and video surveillance devices move from isolated or analog environments onto the IP infrastructure used by business applications. If these devices lack suitable authentication, trust, data protection, monitoring, or secure behavior, a weakness in physical security can affect other systems sharing the network, while network threats can also reach the physical security environment.
Q: Why should physical security and IT security share information?
Physical security and IT security should share information because breaches and compliance issues can involve both facility access and network activity. A combined view can associate a person's movements with digital behavior, such as entering unusual rooms and then accessing unfamiliar network resources. Without shared information, each security team may see only part of a suspicious sequence and fail to recognize the broader pattern.
Q: How does separate user provisioning increase security risk?
Separate user provisioning increases risk because facility access rights, network privileges, and HR information may reside in different systems. When someone leaves or changes roles, administrators may need to update two or potentially three independent records. If one system is overlooked, the person could retain physical or digital access that is no longer appropriate, leaving an avoidable gap in the organization's controls.
Q: What security capabilities can smart-card credentials provide?
Smart-card credentials can provide stronger authentication through embedded microprocessors that perform cryptographic functions. They can securely store biometric templates and participate in certificate checking, helping systems establish identity, trust, responsibilities, and associated access rights. A common credential can also support access to buildings, computers, and the network, reducing the separation between physical and digital identity processes.
Q: How can badge records control access to a network?
Badge records can control network access by communicating a person's building-presence status from the physical security server to a metadata server and then to a network access control appliance. The appliance applies a policy requiring the user to be recorded inside the building. If the person has not badged in, internal network access is denied even when the submitted username and password are correct.
Q: Why does linking network access to badge entry discourage tailgating?
Linking network access to badge entry discourages tailgating because an employee who follows another person through a door without presenting a credential is not recorded as present. The network consequently treats that employee as outside the building and denies access. To connect, the employee must return to the entrance, badge in properly, and create the physical access event required by policy.
Q: Can physical presence checks reduce stolen-password risk?
Physical presence checks can reduce stolen-password risk because correct credentials alone may not satisfy the network access policy. If an authorized employee is recorded as outside the building, another person inside cannot use that employee's written username and password to gain network access. The attempt is denied because the physical security record and the claimed digital identity do not correspond.
Q: What must be verified before an employee receives network access?
Under the converged example, the network access control server verifies that the employee is recorded inside the building, that the username and password match, and that the device meets its health requirements. When these conditions and the applicable policy agree, the server admits the user to the network and grants the rights and privileges associated with that user's established policies.
Summary & Key Takeaways
-
Physical security systems historically operated as isolated, often analog environments using manufacturer-specific communications. As video surveillance and card-based access control migrate to shared IP networks, they become part of the same infrastructure as business applications. This creates a need to evaluate their security, trust, authentication, and effects on other connected devices.
-
Keeping physical and IT security separate produces fragmented provisioning, deprovisioning, monitoring, and compliance processes. Combining physical access events with network activity can expose suspicious behavior that either system might miss alone, such as an employee entering unusual rooms and accessing unfamiliar resources without a corresponding change in organizational responsibilities.
-
Converged security can make physical presence a condition of network admission. If an employee enters without badging, the physical security system records no presence, and the network access control appliance denies access. After proper badge entry, valid credentials and acceptable device health allow the employee to receive authorized network privileges.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator