Showing posts with label Egress Switch. Show all posts
Showing posts with label Egress Switch. Show all posts

Sunday, June 30, 2019

System Integrators tips to win Sales Proposals for New Access Control Systems

System Integrator tips to win Sales Proposals for New Access Control Systems

Access control provides the ability to control, monitor and restrict the movement of people, assets or vehicles, in, out and round a building or site. It is only a matter of time before you receive the highest compliment from one of your customers when they say: “We need a completely new access control system, and we want you to design and implement it.”

Any security systems integrator (Security Safety Automation Integrate - SSA Integrate) who has ever worked on an “enterprise-level” access control project will tell you it is not just standard access control, only larger. There are a host of requirements, challenges and issues that come with true enterprise access control.


Today’s enterprise-level projects are more complex than ever, with an emphasis on integration with not only other security systems such as video, but also Active Directory, building control and even beyond — in some cases going to PSIM-level integration. Technologies such as mobile credentialing, PoE and convergence have all to greatly impact this space in recent years, requiring more technical expertise than ever before on the part of the security systems integrator. I am always with you, in case of any designing issue / guide is required, just give me a mail – I work for smarter & safer future – Arindam Bhadra.

Now I share some Checklist to win sales proposal for New Access Control Systems. If you approach it methodically, you can reduce error and ensure that your customer gets the exact system they require.
Questions to ask include:
• What is the short-, mid- and long- range vision for the access control system? Is it based on open standards, like 802.11b/g or 802.3af, for the most affordable infrastructure? Is it scalable enough to support possible mergers and acquisitions?
• What type of Access Card / credential(s) will be used? How many are issued? What type of format will be used, and can it support a projected card-holder population? Is it controlled to ensure there are no duplicate IDs?
• What investment has already been made? Is the current system upgradeable? Or completely new.
• What assets does the end-user have, and what value do these assets have in relation to the operation or business? These range from physical assets like computers to patient records, employee records and client data.

Observe the End-User
Essentially, the integrator should be trying to find out about the culture at the end-user’s location. It can range from an open, accommodating environment, to one with strict and limiting access controls. There will always be a conflict between convenience and security — the challenge is to create procedures and rules that balance these disparate goals.
Did you observe the employees holding doors open for each other? If so, how are they able to verify their current employment status? Did they open the door for persons carrying large packages?

If so, did they check their IDs? Did visitors sign in at the reception desk? Did they wear ID badges? Were they escorted by staff members? Did students have a habit of leaving their rooms unsecure? If so, what sort of liabilities fall on school administration if a theft occurs and they knowingly allowed that practice to continue?
Conduct a Site Survey and Security Audit
Walking through a customer’s facilities can be invaluable when developing a comprehensive access control plan. Here are a few things to look for:
• Mechanical Security: If the openings are not mechanically secure, any additional funds spent on electronic access control are wasted. The following must be addressed before moving forward on an advanced access control system: Are the doors, frames, and hinges in good condition? Are they rugged enough for the application and durable enough for the traffic? Are the frames mortar-filled?
> What key system is in use? Is it a patented, high-security type? How often are locks re-cored? How many master keys have been issued? Have any been lost? How easy is it to reproduce the keys?
> Is there accommodation for the handicapped to ensure compliance with the Local Act?
> Are cross-corridor fire doors in place? Do they have magnetic door holders tied to the fire system?
• Identify the Threat: Consider the enduser’s surroundings: Have you noticed any evidence of gang activity? Have you noticed an increase in shuttered businesses?
If so, perhaps an increase in perimeter security is in order, potentially including increased lighting, cameras and gated access.
• Evaluate the Facility(s): This will help you identify product options. How old is the building? Does it have architectural or historical significance? How thick are the walls? Was asbestos used as an insulating material? If so, it may be difficult and costly to install conventional, wired access control devices. Perhaps a WiFi solution will be a good alternative.
• Identify Assets and Value: Many consider assets to be tangible items that can be sold for quick cash. But assets include anything that someone might want to steal or destroy, and vary among end-users. The important thing is to put a price tag on the loss of the asset, plus the cost of lost productivity and potential liability that could result.

Get the Technical Details
For each opening requiring access control, you’ll need the following details to ensure you order the right product for the given application:
• Does the door swing in or out? Is it leftor right-handed?
• What’s the finish of the existing hardware? What’s the lever style? Would the end-user prefer a more modern look?
• How is each door expected to operate? Ensure that an operational narrative is written for each opening that covers the following conditions, and have the customer sign off on it. This should include: normal state; authorized/unauthorized access and egress; monitoring and signaling; and power failure, fire alarm and mechanical operation.
• Determine where to place access control equipment. This could be an IT closets, server rooms, administrators’ offices or under BMS Room. Make sure your staff will have access for installation, and later for service and maintenance. Also, make sure there is enough space on the wall to mount access control panels, interface modules and power supplies.
• Determine network coverage. Are IP drops where you need them? Is there sufficient WiFi coverage where you need it should you opt for WiFi locksets?

Validate the Security Requirements
Different applications and clients have differing security requirements. Verify these needs with the end-user before starting the system design; otherwise, you could be in for a lot of extra work. The following considerations should be factored into an overall access control plan, as they have a direct impact on product selection and system configuration:
• Lockdown: Is lockdown capability needed in the interior or just the exterior — or at all?
• Real Time: Is real-time communications to the access control system a critical requirement? Perhaps it is for perimeter doors, but what about interior doors?
• Monitoring Requirements: How much monitoring does the end-user need? In most cases, a door position switch will suffice; however, some clients want to know that the door is both closed AND secured — these are not necessarily the same thing.
• Audit Trail Requirements: How important is it to know who and when someone
entered a building or room? For code compliance, this feature is always mandatory, such as accessing computer rooms, personnel records and patient records; however, some companies use audit trail reports to validate employee activity.
• High-Security and Classified Areas: For increased security, there are several options. Is multi-factor authentication a requirement, such as card and PIN or even a biometric verification? Should there be a two-man rule?
• Special Considerations: Some areas, require valid access credentials from both sides of the door — keeping the right people in and the wrong people out. This requirement takes different hardware than a typical free-egress lock or exit device.

Determine Business Requirements
Consider the final details that will allow you to complete your system design:
• Aesthetics: Many high-profile building owners use architectural design to make their facilities stand apart. This extends to the interior space as well. So, is a black wall reader the right choice? Or will an elegant lock with integrated card reader and designer lever be a better option?
• Infectious Disease Control: Some locks and doors are available with an anti-microbial finish designed to inhibit the growth of bacteria.
• Turnover: What kind of turnover does the facility experience? Heavy turnover would be difficult to manage with a PDA-programmable offline lock; however, one-card systems program access privileges onto the card, virtually eliminating the need to tour the doors to reprogram them. Of course, online solutions could address this as well.
• Applications: It is inevitable that a variety of applications will converge into a single system. That’s why it is important to select an access control system that can grow by providing application support for parking access, visitor badging, integrated video and other needs as required.
• System Management: It is important to determine who, how and where the enduser will manage the new access control system. For enterprise-class systems, it might mean multiple departments will manage their own people, while a system administrator will maintain and manage the main, centralized system.
• Budget: You ultimately need to know your customer’s budget; however, with all the upfront research, your findings might be beyond their initial scope. This is how long-term planning comes into play so you can develop a priority list over several phases to ensure the end user gets the access control system that fully meets their requirements

Ensure Code Compliance
Several agencies have issued codes and standards over the years to enhance life safety, improve privacy and reduce fraud. They need to be factored into an overall access control plan, and the Health Insurance Portability and Accountability Act (HIPAA). National Building Code of India 2016; Life-Safety (NFPA 101) — Means of Egress; Fire (NFPA 80) — Retro-fitting, Sprinkler Systems; Accessibility (ANSI A117.1) — Operators, Credentials; and Electrical (NEC NFPA 70) — Installation, Wiring, Products. Select products and services that meet the design requirements and comply with current standards, such as EN50133 European Access Control Standards and Electrical wiring regulations.

Suppose you need to design 2door, where both side card reader for 100nos Card holder. What is the MOQ.
Option 1:
Sl No
Short Description
Long Descriptions
Unit
Total Qty.
1
Door Controller
2 Door / 2 reader Door Controller
No.
2
2
Power Supply
Power Supply for controller
No.
2
3
Proximity Reader
Proximity Readers for Entry & Exit
No.
4
4
Proximity Card
Proximity Cards
No.
100
5
EM Lock
Singe leaf lock ( 600 lbs)
No.
2
6
EDR
Emergency Break glass switch
No.
2
7
MC
Magnatic Contuct
No.
2
8
Access Software
Access Control Software
Set
1
9
Patch Cord
Patch Cord 3 M
No.
2
10
Network Switch
4port Network Switcher
No.
1
11
Access Workstation
PC i5 with windows operating system, complete with keyboard, mouse
No.
1
12
4C Cable
Supply, Laying & Testing of  4cx1.5 sq.mm cable
RM
30
13
2C Cable
Supply, Laying & Testing of  2cx1.5 sq.mm cable
RM
40
14
25mm PVC Conduit
Supply, Laying & Testing of 25mm dia. PVC type conduit
RM
60
Option 2:
Sl No
Short Description
Long Descriptions
Unit
Total Qty.
1
Door Controller
Standalone Door Controller cum reader.
No.
2
2
Power Supply
Power Supply for controller
No.
2
3
Proximity Reader
Proximity Readers for Entry & Exit
No.
2
4
Proximity Card
Proximity Cards
No.
100
5
EM Lock
Singe leaf lock ( 600 lbs)
No.
2
6
EDR
Emergency Break glass switch
No.
2
7
MC
Magnatic Contuct
No.
2
8
Access Software
Access Control Software
Set
1
9
Patch Cord
Cat6a Cable
RM
30
10
Network Switch
4port Network Switcher
No.
1
11
Access Workstation
PC i5 with windows operating system, complete with keyboard, mouse
No.
1
12
4C Cable
Supply, Laying & Testing of  4cx1.5 sq.mm cable
RM
30
13
2C Cable
Supply, Laying & Testing of  2cx1.5 sq.mm cable
RM
40
14
25mm PVC Conduit
Supply, Laying & Testing of 25mm dia. PVC type conduit
RM
60


Ref:
Access & Identity Management Handbook.
https://ipvm.com/reports/video-surveillance--access-control-integration
BS EN 50133-2-1:2000 British Standards Institution 2018.


Saturday, September 22, 2018

Role of IT in Access Control System

Role of IT in Access Control System


It is a fact that IT is becoming more involved in the physical security world. In a small minority of companies, these two departments are actually merging, although this is a mammoth task fraught with problems, not only in terms of technology, but primarily in terms of culture.

In the access control world, one could say it’s normal for IT to be involved in networking (assuming the access systems make use of the corporate network and/or the IP protocol), but the scope of IT has slowly been creeping into more of the access control functions. In smaller companies, for example, it’s not unusual for the service provider responsible for the company’s IT to also take the responsibilities of physical security.
So how far has IT made inroads into the access control world in general? HID Global broadcast arrange a webinar in October 2018 in which it revealed some new research into the increasing role IT departments and personnel are playing in the physical access control world. The webinar was hosted by HID Global’s Brandon Arcement and Matt Winn. After discussing the findings of the research, they went on to advise physical security operators as to how they can embrace their IT colleagues further, with the goal of improving the holistic security posture of their organisations.

The survey was conducted by The 05 Group, sponsored by HID and was completed in March 2018. As the title of this article notes, the research found that IT departments are now more involved than ever in organisations’ physical access control decisions and implementation, and that trend is set to increase.

The 05 Group surveyed 1 576 individuals from more than a dozen industries, including education (19%), information (16%), government (11%), manufacturing (8%), health services (8%), and security, professional and business services (8%). Of the respondents, 35% were IT managers, 26% were IT directors, 13% were IT staff, 8% were CIO/CTO, and 3% were VPs of technology. The survey also spanned companies of different sizes, with 24% having less than 100 employees, 22% 101-500 employees, 11% have 501-1000 employees, 17% have 1001-5000, 6% have 5001-9999, and 6% have 10 000-24 999 employees. The results therefore cover a broad spectrum of companies and industries.
 The numbers tell a story
The research offers a significant amount of data about the role of IT in access control, however the webinar brought out a few pertinent facts (a link to the white paper written by HID from the research is at the end of this article). When asking the organisations being surveyed “Who is primarily responsible for physical access control in your organisation”, the responses were as follows:
• 29% said both IT and physical security.
• 26% said IT only.
• 25% said facility management handles the job.
• 12% said physical security only.
• 8% said the property management company was tasked with access control.
With a quarter of the respondents already saying IT is responsible for access control, and a further 29% saying it is shared between the two departments, it’s clear that the divide between IT and physical security is rapidly vanishing – and in some cases, altogether gone. And this is a trend that will continue; in organisations where IT is not involved in access control, 36% of the respondents said it will be within the next five years.

For those organisations where access control responsibilities are shared, 47% of the respondents report it had been shared within the past five years. Similarly, where IT owns the responsibility, 42% of the companies say they were given this task within the last five years. Once again we see that IT/physical security convergence in the access world is an expanding reality.

We mentioned IT’s influence in access control above in terms of the networking of access systems, however, this is an old function. The webinar showed that both IT professionals as well as physical security professionals see IT being involved in all areas of access control. When it comes to physical security professionals:
• 66% of physical security professionals see IT involved in influencing the decision-making process.
• 48% see IT’s involvement in integrating access and other systems.
• 37% see IT involved in implementation.
• 22% see IT involved in managing the systems.
From the other side of the table, IT professionals have a similar view:
• 76% expect to influence decision making.
• 72% will be involved in integration.
• 59% will be involved in implementation.
• 39% expect to be involved in managing systems.

Not all wine and roses
Of course, as these different cultures work together, there are bound to be some issues. It is in the field of integration where IT sees problems. Half of the IT people surveyed have issues with the lack of integration of access systems with other IT systems. This is an area in which the access control industry could make significant changes in the short-term to ensure their software and hardware can be more easily integrated with existing business management and security systems.

When it comes to new access control systems, the IT school has a few things it wants to see on the vendors’ to-do list. They want improved ease of use (71%), the ability to support or add new technologies (68%), mobile access (59%), and integration with existing security platforms (54%).

It’s also clear from the survey that IT is not all that comfortable with access control technology. Areas such as credential management, decision making with respect to access control systems, how system components work and also individual features within access systems can cause a bit of nervousness among the IT folk. These are areas in which physical security professionals can make their mark, as they are more skilled in dealing with these issues as well as others unique to their industry. 

Helping IT in access
The driver behind this convergence is not a technical issue, but is itself a convergence of a number of separate drivers. HID notes the primary drivers are:
• Converged threats that impact both physical and logical infrastructure. If you have a physical vulnerability it puts your logical systems at risk, and vice versa.
• Proliferation of networked devices in the age of IoT (the Internet of Things) which all require both physical and logical security. Interestingly, the webinar held its own real-time survey of the attendees and this topic was selected as having the biggest impact on access control’s shift to IT with half of the audience selecting it.
• Compliance to new regulations, which again rely on both sides of the table.
• Budget consolidation, which we are all suffering through.
• A shift in reporting structures as executives try to get a handle on the seemingly endless threats companies face on all fronts.

When it comes to the role of physical security professionals and how they can assist in the convergence between the two sides and help improve organisational security, 80% of the respondents said they play a role in establishing best practices, while 50% see physical security having a role in preventing unauthorised access in general, and 49% say they can help in achieving compliance. In order to streamline collaboration, the HID webinar suggests, among other issues, that both sides need to work on aligning project priorities and determining responsibilities, and balancing the technical acumen of IT when it comes to access products and management. 

A converged example
The webinar went on to provide an example of how the two divisions could work together in an access control installation. When it comes to the physical access control host, HID advises organisations to integrate physical access control systems (PACS) with an IT source of identity such as LDAP. Furthermore, administrators should ensure there is a set policy around regular software updates and patches, while they should also take advantage of IT’s experience (and equipment) to ensure high availability.


When it comes to the controller, HID advises organisations to settle some of the issues raised above by requiring an open controller platform that can be integrated with other technologies and other vendors’ products. Preventing vendor lock-in is a costly lesson IT departments have learned. It also suggests considering an ‘IP-at-the-door’ topology, keeping controller firmware updated to the latest versions, using strong passwords and encrypting communication between controllers and hosts (and using OSDP – Open Supervised Device Protocol – for encrypted reader communications).

Another strong warning was to take care when selecting access credentials as many of the card and fob technologies available are easy to replicate, making it simple for the wrong people to easily gain access. There are secure card technologies out there and these should be used as a standard. A business benefit of these more advanced credentials is that they can also be used for additional business functions, such as secure printing, vending machines and network logon.
The webinar presenters also touched on the benefits of using users’ mobile devices as credential holders. These can offer higher levels of authentication, easier administration and more user convenience that does not come at the expense of the company’s security.

Whether you are on the IT or physical security side, the most important part of the research (depending on your biases) can be seen in the answer to the question “Do you believe that increased collaboration between physical security and IT can improve the overall security of your organisation?” An overwhelming 95% of all the respondents said “yes”.

While the full convergence of physical and logical security is still some way off, people in the access control sector obviously understand that IT and physical security working together is critical to develop a successful security defence strategy for their organisations. In the access control industry this may be easier to achieve, but as noted in the introduction, it is often a question of culture (or ego, to be blunt) that prevents collaboration and results in organisations being vulnerable to the ever-increasing threats they face from well-organised criminal syndicates, as well as unhappy teenagers with too much time on their hands.

End of the article thanks to Mr. Andrew Seldon, for valuable time to us & security sa team.