Physical Security for Data Centers OWASP July 16, 2015

48
PHYSICAL SECURITY FOR YOUR DATA CENTER Michael E. Marotta, BS, MA. Intentional Privacy www.IntentionalPrivacy.com Austin, Texas

Transcript of Physical Security for Data Centers OWASP July 16, 2015

Page 1: Physical Security for Data Centers OWASP July 16, 2015

PHYSICAL SECURITY FOR YOUR DATA CENTER

Michael E. Marotta, BS, MA.

Intentional Privacywww.IntentionalPrivacy.com

Austin, Texas

Page 2: Physical Security for Data Centers OWASP July 16, 2015

Twelve years of experience in private security. Client sites included corporate settings, and campus safety.

Page 3: Physical Security for Data Centers OWASP July 16, 2015

WebEOC virtual emergency operations center standard across many agencies

Page 4: Physical Security for Data Centers OWASP July 16, 2015

TMAR annual training Camp Swift

April 11, 2015

Evaluated the dive team against national standards for incident response management.

Page 5: Physical Security for Data Centers OWASP July 16, 2015

BSides Austin 2013Jayson Street red hat pen tester takes on information security.

Page 6: Physical Security for Data Centers OWASP July 16, 2015

Your InfoSec Team

Page 7: Physical Security for Data Centers OWASP July 16, 2015

How InfoSec Sees Themselves

Page 8: Physical Security for Data Centers OWASP July 16, 2015

How InfoSec Sees Themselves

Page 9: Physical Security for Data Centers OWASP July 16, 2015

Your Front Desk Facilities Patrols

Page 10: Physical Security for Data Centers OWASP July 16, 2015

How We See Ourselves

Page 11: Physical Security for Data Centers OWASP July 16, 2015

ASIS International is the brand formerly known as the

American Society for Industrial Security

Page 12: Physical Security for Data Centers OWASP July 16, 2015

CERTIFICATIONS• Certified Protection Professional (CPP)®-

demonstrated knowledge and experience in all areas of security management

• Professional Certified Investigator (PCI)®- demonstrated education and/or experience in the fields of case management, evidence collection, and case presentation

• Physical Security Professional (PSP)®- demonstrated experience in physical security assessment, the application, design and integration of physical security systems, and implementation of physical security measures

Page 13: Physical Security for Data Centers OWASP July 16, 2015

CISO ≠ CSO

Page 14: Physical Security for Data Centers OWASP July 16, 2015
Page 15: Physical Security for Data Centers OWASP July 16, 2015

Carl begins his distraction.

Page 16: Physical Security for Data Centers OWASP July 16, 2015
Page 17: Physical Security for Data Centers OWASP July 16, 2015

Lose the balloons. Open the box and take out the briefcase.

Page 18: Physical Security for Data Centers OWASP July 16, 2015

“Martin, don’t even kid me. Those things are impossible!”

Page 19: Physical Security for Data Centers OWASP July 16, 2015

“This might work.”

Page 20: Physical Security for Data Centers OWASP July 16, 2015
Page 21: Physical Security for Data Centers OWASP July 16, 2015
Page 22: Physical Security for Data Centers OWASP July 16, 2015

ISO 27002

• Human Resources

• Asset Management

• Access

PHYSICAL SAFETY

Page 23: Physical Security for Data Centers OWASP July 16, 2015

Developing your own guidelines

VISITORS• Do they have an appointment?

• Are they expected?• Does their contact know that they are

here?• Where do they wait?• Is that area secure?

• Is that area open, closed, on camera?• Who issues the badge?

• Who ensures that the badge is returned?

Page 24: Physical Security for Data Centers OWASP July 16, 2015

Domestic Violence in the Workplace

• Research indicates that about 50 percent of battered women who are employed are harassed at work by their abusive partner.

• Over three-quarters of offenders used workplace resources at least once.

• 74% had easy access to their intimate partner's workplace

• 21% of offenders reporting that they contacted her at the workplace in violation of a no contact order.

Page 25: Physical Security for Data Centers OWASP July 16, 2015

Site Assessments

Page 26: Physical Security for Data Centers OWASP July 16, 2015

Site AssessmentsThreats, Risks and Exposures

PreventionsMitigationsResponsesRecoveries

Page 27: Physical Security for Data Centers OWASP July 16, 2015

Access Control

•Curbs•Berms•Hedges•Gates•Doors•Lights

•Locks•Motion Detectors•Alarms•Cameras•Badge Readers

Page 28: Physical Security for Data Centers OWASP July 16, 2015

Guards on Patrol Inspect Infrastructure

Page 29: Physical Security for Data Centers OWASP July 16, 2015

Guards on Patrol Inspect Infrastructure

Page 30: Physical Security for Data Centers OWASP July 16, 2015
Page 31: Physical Security for Data Centers OWASP July 16, 2015

$50 billion annually

2 million personnel

$ 100 billion annually

1.1 million personnel760,000 sworn

1960 1970 1980 1985 1990 1993 1998 2000 2003 2007 2010 2015

Private Security

Public Policing

9/11

Recession

Numbers from COPS US DOJ http://www.cops.usdoj.gov/Default.asp?Item=2034

Page 32: Physical Security for Data Centers OWASP July 16, 2015

Zero Point 27 Percentof RevenueSpent on PHYSICAL Security

Page 33: Physical Security for Data Centers OWASP July 16, 2015

How much is it worth to protect her …

Page 34: Physical Security for Data Centers OWASP July 16, 2015

… from them?

Page 35: Physical Security for Data Centers OWASP July 16, 2015

Disaster

Page 36: Physical Security for Data Centers OWASP July 16, 2015

Enemies are Everywhere

Page 37: Physical Security for Data Centers OWASP July 16, 2015

They have powerful friends

Page 38: Physical Security for Data Centers OWASP July 16, 2015

The best defense …

Page 39: Physical Security for Data Centers OWASP July 16, 2015

… is merely a defense

The firewall cannot always withstand a denial of service attack.

Page 40: Physical Security for Data Centers OWASP July 16, 2015

How do you know that I don’t have next year’s designs on this?

Page 41: Physical Security for Data Centers OWASP July 16, 2015
Page 42: Physical Security for Data Centers OWASP July 16, 2015

Dad, I got sick at school.Can you come pick me up?

Every desk can have one. No one should be out of touch

Page 43: Physical Security for Data Centers OWASP July 16, 2015

You probably do not need to go this far in cutting off smart phone access to your most sensitive departments

Page 44: Physical Security for Data Centers OWASP July 16, 2015
Page 45: Physical Security for Data Centers OWASP July 16, 2015
Page 46: Physical Security for Data Centers OWASP July 16, 2015

Independence and Autonomy

C-Level Representation

Recognition of Profession

Page 47: Physical Security for Data Centers OWASP July 16, 2015

You got any questions?

Page 48: Physical Security for Data Centers OWASP July 16, 2015

THANK YOU