Case study answers

Possible Responses (Case Study - U.S. Department of Homeland Security)

1 slides · 2 min read · Domain 5

Possible Responses (Case Study: U.S. Department of Homeland Security)

1. Name the logical or physical systems described in the PACS application.

  • - PACS is a collection of physical AC processes and technologies that are applied to U.S. government buildings, although this approach can be applied within any organization. It describes the controls that can and need to be applied to any entity (e.g., users, shipping manifests, devices, vehicles) entering or moving through a controlled space. Consider people as a specific example: who might these individuals be (e.g., employees, contractors, temporary visitors who are U.S. citizens, and temporary visitors who are not U.S. citizens)? In all these examples, some form of pre-screening is required before admission to the site is granted.

2. What assumptions can be made about the nature of the information related to identification in the PACS application?

  • - PAC systems initially include an identification and authorization process, such as a turnstile, mantrap, or vehicular access control like a barrier or rising curb. These devices present both a physical and logical barrier to anyone seeking to gain access. Next, physical and logical sensors are deployed. Physical sensors, such as closed-circuit television (CCTV), motion sensors, and acoustic sensors, provide continuous monitoring of both the whole space and individual areas. Logical sensors, such as IDS and IPS, monitor activity within a network or critical hosts. Given the degree of prescreening required before physical access is granted, there can be reasonable assurance that nothing poses a threat to the safety of either the occupants or data within the secure location.

3. DHS seems to view the controlling of access to physical facilities as a separate set of problems requiring separate policies than access control to information systems. Why might they have this view?

  • - PACS are correct to see physical security as a separate and distinct set of problems. Organizations go to extreme lengths to protect networks, data, and systems from external attacks. Often this involves the acquisition of expensive and complicated technologies, but the existence of these solutions can sometimes create a false sense of security. If a malicious actor can gain physical access to a site, and the occupants assume their site is secure, they may lower their guard. Physical access allows an attacker to bypass many of these expensive security solutions.
Test this domain