Thinking Beyond the Product

Protecting information assets in the digital age

Technology plays a dichotomous role in the security of an organization's information assets. While it enables us to protect assets in ways we never imagined, it also can enable the very threats that leave those assets vulnerable.

Regardless of the organization or the type of assets being protected, one thing is true: technology—the security products and solutions on which we rely— can no longer stand alone.

Today's sophisticated business environment calls for an equally sophisticated, holistic approach that incorporates not only technology but also the people and processes that will ensure technology achieves our objectives for the protection of information.

Understanding Threats

During the last decade, threats have certainly changed in character. Gone are the days when the most dangerous risks to an organization were physical in nature. Logical threats, such as hacking, viruses and digital sabotage, have become more prevalent as technology has proliferated. And those dangers are coming from both internal and external sources.

That's why information security—the protection of sensitive data and the infrastructure on which it resides—has become one of the most topof- mind concerns for security professionals. Unlike many physical threats, the impact of logical security breaches is typically far-reaching and long-lasting. Organizations, with help from their security partners and suppliers, must examine their current security structures and develop robust, integrated programs that effectively protect their networks, systems and data. Such an approach can complement an organization's business objectives, while enabling it to identify vulnerabilities, assess and prioritize threats, deploy efficient mitigation strategies and manage the information security program.

Assessing the Situation

To adequately safeguard systems, an organization's security professionals need to identify and understand where it is most vulnerable. Only then can the appropriate technologies, people and processes be implemented to protect data assets.

A risk assessment can deliver insight about existing opportunities for information technology systems to be compromised. It can help determine how well critical systems are protected, providing a detailed analysis of both external and internal threats. Ongoing assessments should be conducted to confirm systems are protected, as well as to ensure strategies and technologies remain effective.

Developing a Holistic Strategy

Once vulnerabilities have been identified, the ultimate goal of any information security initiative should be the development of a holistic strategy to protect consumers, employees and the organization.

The implementation of a proactive, positive information security model should be the first step in the development of such a strategy. In tandem with antivirus software, which proactively prevents intrusion, defies hackers and identifies suspicious activity, a positive model provides protection by allowing only limited privileges to system users, applications and data. Positive model programs do not rely on detection of an intrusion before raising a red fl ag. Rather, they create rules that define allowable activities and restrict all else. This embraces a philosophy that fewer allowed permissions yield the least opportunity for threats. With this architecture in place, the system's connectivity can be shut down if an action falls outside the normal scope of operation.

A holistic information security strategy also should incorporate technologies that are interoperable with an organization's physical systems, such as physical access control systems and personnel databases. Integrating these systems with the logical access control system can provide organizations with complete reporting of employee activity, including information about who is entering facilities and rooms, as well as physically accessing computers and other devices, and at what times.

This level of system integration also allows for the creation of an automated workfl ow process that executes automatically based on the business policies and compliance requirements mandated by the organization. For example, if an employee hasn't swiped into the building, his or her account could be automatically locked to prevent unauthorized computer access. Furthermore, once an employee is removed from the personnel database, the automatic removal of that user from both physical and logical access control systems can be triggered.

Engaging the People, Defining the Processes

The efficacy of information security relies, in large part, on people. Each person should be aware of security, understand his or her role in mitigating risk and be committed to providing protection. Processes— and training programs to ensure the understanding and adoption of those processes—must be in place to enable all employees to understand rules, roles and responsibilities.

Staffing is critical to the successful deployment of information security technologies. Before selecting and deploying technologies, organizations should understand the staffing that's needed to effectively and efficiently implement and manage technology. Even the most proactive, sophisticated security technologies can be rendered useless without the people and processes needed to support them.

As the industry continues its focus on the protection of critical systems and data, we must all go beyond the product. We must place equal emphasis on the people and processes that will ensure we maximize the technologies that were designed to protect our information assets.

Featured

  • TSA Introduces New $45 Fee Option for Travelers Without REAL ID Starting February 1

    The Transportation Security Administration (TSA) announced today that it will refer all passengers who do not present an acceptable form of ID and still want to fly an option to pay a $45 fee to use a modernized alternative identity verification system, TSA Confirm.ID, to establish identity at security checkpoints beginning on February 1, 2026. Read Now

  • The Evolution of IP Camera Intelligence

    As the 30th anniversary of the IP camera approaches in 2026, it is worth reflecting on how far we have come. The first network camera, launched in 1996, delivered one frame every 17 seconds—not impressive by today’s standards, but groundbreaking at the time. It did something that no analog system could: transmit video over a standard IP network. Read Now

  • From Surveillance to Intelligence

    Years ago, it would have been significantly more expensive to run an analytic like that — requiring a custom-built solution with burdensome infrastructure demands — but modern edge devices have made it accessible to everyone. It also saves time, which is a critical factor if a missing child is involved. Video compression technology has played a critical role as well. Over the years, significant advancements have been made in video coding standards — including H.263, MPEG formats, and H.264—alongside compression optimization technologies developed by IP video manufacturers to improve efficiency without sacrificing quality. The open-source AV1 codec developed by the Alliance for Open Media—a consortium including Google, Netflix, Microsoft, Amazon and others — is already the preferred decoder for cloud-based applications, and is quickly becoming the standard for video compression of all types. Read Now

  • Cost: Reactive vs. Proactive Security

    Security breaches often happen despite the availability of tools to prevent them. To combat this problem, the industry is shifting from reactive correction to proactive protection. This article will examine why so many security leaders have realized they must “lead before the breach” – not after. Read Now

  • Achieving Clear Audio

    In today’s ever-changing world of security and risk management, effective communication via an intercom and door entry communication system is a critical communication tool to keep a facility’s staff, visitors and vendors safe. Read Now

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.