SlideShare una empresa de Scribd logo
1 de 11
Dr Liam Terblanche
CIO Accsys
Physical vs. Logical Access Control – The role of biometrics in securing your business
Introduction
Dr Liam Terblanche
Physical vs. Logical Access Control
Dr Liam Terblanche
Biometrics
Dr Liam Terblanche
Image acknowledgement:
http://www.identityone.net/BiometricTechnology.aspx
Biometrics - Risks
Dr Liam Terblanche
Less Secure
Permanence
Physical Spoof Attacks
Biometrics - Rewards
Dr Liam Terblanche
Single Sign-on • Across all IT systems
3-Factor
Authentication
• What you know (password)
• What you have (token)
• What you are (biometric)
Single
Identification
Token
• Logical & Physical access
• Time & Attendance
• Payroll
• HR (monitor truancy, absenteeism, etc.)
Reciprocity of Trust
Dr Liam Terblanche
Security Privacy
Legislative Framework
PROTECTION OF PERSONAL INFORMATION BILL (ISBN 978-1-77037-998-5)
Biometrics – Special Personal Information (Section 26)
• Prohibition on processing of special personal information*
Retention of Personal Information (Section 14)
• Only for as long as necessary to achieve agreed purpose.
Hosted solutions and multi-nationals
• Clause 72: Information will not be transferred to another country if
proper safeguards for the protection of the information have not
been adopted in that country
Dr Liam Terblanche
What if it gets hacked?
Dr Liam Terblanche
for i = 0 to length(CloudProviders) do
BEGIN
writeln(“Attention: “ +
CloudProviders[i] +
” has been hacked, reset your password!”);
END;
What’s the solution?
Dr Liam Terblanche
Identity
Management
Limited shelf-
life
Don’t
recycle, redo
Questions / Discussion
Dr Liam Terblanche

Más contenido relacionado

Destacado

Destacado (11)

Pharma Uptoday Monthly Magazine Volume 13, Issue Apr - 2015
Pharma Uptoday Monthly Magazine Volume 13, Issue Apr - 2015Pharma Uptoday Monthly Magazine Volume 13, Issue Apr - 2015
Pharma Uptoday Monthly Magazine Volume 13, Issue Apr - 2015
 
Contratado | UNESP - Sentando no Banco da Frente na sua Carreira
Contratado | UNESP - Sentando no Banco da Frente na sua CarreiraContratado | UNESP - Sentando no Banco da Frente na sua Carreira
Contratado | UNESP - Sentando no Banco da Frente na sua Carreira
 
Cerebelo correlacion clinica
Cerebelo correlacion clinicaCerebelo correlacion clinica
Cerebelo correlacion clinica
 
Copywriting
Copywriting Copywriting
Copywriting
 
Fisiología materna
Fisiología maternaFisiología materna
Fisiología materna
 
Silabo Lenguaje I - Upao 2016
Silabo Lenguaje I - Upao 2016Silabo Lenguaje I - Upao 2016
Silabo Lenguaje I - Upao 2016
 
Aprendizaje y servicio Solidario
Aprendizaje y servicio SolidarioAprendizaje y servicio Solidario
Aprendizaje y servicio Solidario
 
Insuficiencia Arterial periférica e insuficiencia venosa
Insuficiencia Arterial periférica e insuficiencia venosaInsuficiencia Arterial periférica e insuficiencia venosa
Insuficiencia Arterial periférica e insuficiencia venosa
 
الفصل الثاني - Charisma Code كاريزما كود
الفصل الثاني - Charisma Code كاريزما كود الفصل الثاني - Charisma Code كاريزما كود
الفصل الثاني - Charisma Code كاريزما كود
 
Wikispaces
WikispacesWikispaces
Wikispaces
 
Mcq 1060 questions
Mcq 1060 questionsMcq 1060 questions
Mcq 1060 questions
 

Más de Global Business Events

Más de Global Business Events (20)

Cio Event
Cio EventCio Event
Cio Event
 
Ludo Van den Kerckhove , Managing Partner at A-cross Health - The Network Alw...
Ludo Van den Kerckhove , Managing Partner at A-cross Health - The Network Alw...Ludo Van den Kerckhove , Managing Partner at A-cross Health - The Network Alw...
Ludo Van den Kerckhove , Managing Partner at A-cross Health - The Network Alw...
 
Tim Mann, CIO at NFU Mutual - Digital Transformation Case Studies: how NFUM i...
Tim Mann, CIO at NFU Mutual - Digital Transformation Case Studies: how NFUM i...Tim Mann, CIO at NFU Mutual - Digital Transformation Case Studies: how NFUM i...
Tim Mann, CIO at NFU Mutual - Digital Transformation Case Studies: how NFUM i...
 
Neil Ward-Dutton, Founder & Research Director at MWD Advisors - Innovating di...
Neil Ward-Dutton, Founder & Research Director at MWD Advisors - Innovating di...Neil Ward-Dutton, Founder & Research Director at MWD Advisors - Innovating di...
Neil Ward-Dutton, Founder & Research Director at MWD Advisors - Innovating di...
 
Mark Jacot, Assistant Director – IT Service Deliveryat The Open University - ...
Mark Jacot, Assistant Director – IT Service Deliveryat The Open University - ...Mark Jacot, Assistant Director – IT Service Deliveryat The Open University - ...
Mark Jacot, Assistant Director – IT Service Deliveryat The Open University - ...
 
Gerard O'Hara, Head of IT EMEA at Facebook - How the Facebook IT department i...
Gerard O'Hara, Head of IT EMEA at Facebook - How the Facebook IT department i...Gerard O'Hara, Head of IT EMEA at Facebook - How the Facebook IT department i...
Gerard O'Hara, Head of IT EMEA at Facebook - How the Facebook IT department i...
 
Hakan Yaren, Managing Director IT at FedEx Express EMEA - IT Modernisation
Hakan Yaren, Managing Director IT at FedEx Express EMEA - IT ModernisationHakan Yaren, Managing Director IT at FedEx Express EMEA - IT Modernisation
Hakan Yaren, Managing Director IT at FedEx Express EMEA - IT Modernisation
 
Sam De Silva, Partner - Head of IT and Outsourcing Group at Penningtons Manch...
Sam De Silva, Partner - Head of IT and Outsourcing Group at Penningtons Manch...Sam De Silva, Partner - Head of IT and Outsourcing Group at Penningtons Manch...
Sam De Silva, Partner - Head of IT and Outsourcing Group at Penningtons Manch...
 
Hugo Smith, CTO at Broadbandchoices - Improving the Agility of your Business ...
Hugo Smith, CTO at Broadbandchoices - Improving the Agility of your Business ...Hugo Smith, CTO at Broadbandchoices - Improving the Agility of your Business ...
Hugo Smith, CTO at Broadbandchoices - Improving the Agility of your Business ...
 
Mark Aikman, IT Director at The North Group - Leading a Complex Bespoke Syste...
Mark Aikman, IT Director at The North Group - Leading a Complex Bespoke Syste...Mark Aikman, IT Director at The North Group - Leading a Complex Bespoke Syste...
Mark Aikman, IT Director at The North Group - Leading a Complex Bespoke Syste...
 
David Clarke, CITSO at Digital Arena - Security Benchmarking, best practise a...
David Clarke, CITSO at Digital Arena - Security Benchmarking, best practise a...David Clarke, CITSO at Digital Arena - Security Benchmarking, best practise a...
David Clarke, CITSO at Digital Arena - Security Benchmarking, best practise a...
 
John Prowse, vCISO at BT - Security Anxiety
John Prowse, vCISO at BT - Security AnxietyJohn Prowse, vCISO at BT - Security Anxiety
John Prowse, vCISO at BT - Security Anxiety
 
Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...
Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...
Kevin Watkins, Enterprise Security Architect at BAT - BAT’s Managed Security ...
 
Keith Inight, CTO at Atos - Software Defined Everything
Keith Inight, CTO at Atos - Software Defined EverythingKeith Inight, CTO at Atos - Software Defined Everything
Keith Inight, CTO at Atos - Software Defined Everything
 
David Clarke, CITSO at Vciso - Security, Standards and Swiss Cheese
David Clarke, CITSO at Vciso - Security, Standards and Swiss CheeseDavid Clarke, CITSO at Vciso - Security, Standards and Swiss Cheese
David Clarke, CITSO at Vciso - Security, Standards and Swiss Cheese
 
Dave Jones, CIO at Cape Plc - Transition of Autonomous regional IT to Providi...
Dave Jones, CIO at Cape Plc - Transition of Autonomous regional IT to Providi...Dave Jones, CIO at Cape Plc - Transition of Autonomous regional IT to Providi...
Dave Jones, CIO at Cape Plc - Transition of Autonomous regional IT to Providi...
 
Wolfgang Kuhl, CIO at Pharmaserv - Data Centre Planning and Execution - A Sur...
Wolfgang Kuhl, CIO at Pharmaserv - Data Centre Planning and Execution - A Sur...Wolfgang Kuhl, CIO at Pharmaserv - Data Centre Planning and Execution - A Sur...
Wolfgang Kuhl, CIO at Pharmaserv - Data Centre Planning and Execution - A Sur...
 
Mark Aikman, CIO at The North Group - Leading a Complex Bespoke System Transf...
Mark Aikman, CIO at The North Group - Leading a Complex Bespoke System Transf...Mark Aikman, CIO at The North Group - Leading a Complex Bespoke System Transf...
Mark Aikman, CIO at The North Group - Leading a Complex Bespoke System Transf...
 
Neil Ward-Dutton, Co-founder and Research Director at MWD Advisors - Digital ...
Neil Ward-Dutton, Co-founder and Research Director at MWD Advisors - Digital ...Neil Ward-Dutton, Co-founder and Research Director at MWD Advisors - Digital ...
Neil Ward-Dutton, Co-founder and Research Director at MWD Advisors - Digital ...
 
Gordon Tredgold, SVP Global IT at Henkel - Fast Leadership - Accelerating Pro...
Gordon Tredgold, SVP Global IT at Henkel - Fast Leadership - Accelerating Pro...Gordon Tredgold, SVP Global IT at Henkel - Fast Leadership - Accelerating Pro...
Gordon Tredgold, SVP Global IT at Henkel - Fast Leadership - Accelerating Pro...
 

Último

Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
lizamodels9
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
amitlee9823
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
Abortion pills in Kuwait Cytotec pills in Kuwait
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
lizamodels9
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
dollysharma2066
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Sheetaleventcompany
 

Último (20)

Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 

Liam Terblanche, CIO at Accsys - Physical vs Logical Access Control

  • 1. Dr Liam Terblanche CIO Accsys Physical vs. Logical Access Control – The role of biometrics in securing your business
  • 3. Physical vs. Logical Access Control Dr Liam Terblanche
  • 4. Biometrics Dr Liam Terblanche Image acknowledgement: http://www.identityone.net/BiometricTechnology.aspx
  • 5. Biometrics - Risks Dr Liam Terblanche Less Secure Permanence Physical Spoof Attacks
  • 6. Biometrics - Rewards Dr Liam Terblanche Single Sign-on • Across all IT systems 3-Factor Authentication • What you know (password) • What you have (token) • What you are (biometric) Single Identification Token • Logical & Physical access • Time & Attendance • Payroll • HR (monitor truancy, absenteeism, etc.)
  • 7. Reciprocity of Trust Dr Liam Terblanche Security Privacy
  • 8. Legislative Framework PROTECTION OF PERSONAL INFORMATION BILL (ISBN 978-1-77037-998-5) Biometrics – Special Personal Information (Section 26) • Prohibition on processing of special personal information* Retention of Personal Information (Section 14) • Only for as long as necessary to achieve agreed purpose. Hosted solutions and multi-nationals • Clause 72: Information will not be transferred to another country if proper safeguards for the protection of the information have not been adopted in that country Dr Liam Terblanche
  • 9. What if it gets hacked? Dr Liam Terblanche for i = 0 to length(CloudProviders) do BEGIN writeln(“Attention: “ + CloudProviders[i] + ” has been hacked, reset your password!”); END;
  • 10. What’s the solution? Dr Liam Terblanche Identity Management Limited shelf- life Don’t recycle, redo
  • 11. Questions / Discussion Dr Liam Terblanche

Notas del editor

  1. Introduce SelfPhysical biometric access control is pervasive in the industry. But the adoption of logical biometric access control has been much slower than anticipated.What does biometric access control offer the CIO in terms of physical and logical security?What is the risk/reward ratio of using biologically identifiable features to grant/deny access to your physical and virtual assets?Where does the line between orporatesecuritty and personal privacy get drawn when storing personal biometric traits in a centralised database?And what does the law say about all this?Over the next 20 minutes, I will endeavour to open up this world to you and try to answer some of these questions in as concise possible way. Feel free to interject at any point if you want us to elaborate on any of these points.
  2. Less Secure:FAR of 1 in 5 000. A 128-bit encrypted password has a likelihood of 1 in 10^38 to be decryptedPermanence:When a password has been lost/stolen/breached, resetWhen a fingerprint template has been lost/stolen/breached, …Physical Spoof AttacksDuplicate fingerprint characteristics (lift it from a glass) and use that to generate a template.(Like finding someone's password in his drawer on a stick-it note)
  3. When an employee leaves a company, his access card gets returned, and reused for another person.But what guarantee does an employee have that his biometric data will be completely removed from the system?A password means nothing. It’s encrypted, salted, hashed, and even if it gets breached, one can change it.There is a global trend to standardise biometric templates across manufacturers. Your template used in this company, will be interpretable by Dept. of Home Affairs.
  4. The POPI bill (soon to be enacted)Is Biometrics encompassed?Biometric data classifies as Personal Information‘‘personal information’’ means information relating to an identifiable, living,natural person, and where it is applicable, an identifiable, existing juristic person,including, but not limited to—the blood type or any other biometric information of the person;What qualifies as biometrics?‘‘biometrics’’ means a technique of personal identification that is based on physical, physiological or behavioural characterisation including blood typing, fingerprinting, DNA analysis, retinal scanning and voice recognitionSection 14 – Retention of Personal InformationRetention and restriction of records14.(1) Records of personal information must not be retained any longer than is necessary for achieving the purpose for which theinformation was collected or subsequently processed.14.(5) The destruction or deletion of a record of personal information must be done in a manner that prevents its reconstruction in an intelligible form. Section 26 - Prohibition on processing of special personal information26. A responsible party may not process personal information concerning—(a) the religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life or biometric informationof a data subject unless explicitly being granted consent by the data subject
  5. Antivirus firm Symantec estimated the 2011 global price tag of direct financial loss and the cost of remediating attacks at $338 billion, excluding the theft of intellectual property and damage from data breaches. When theft of intellectual property is factored in, the figure soars past $1 trillion, according to former head of the NSA, General Michael Hayden.
  6. Identity is contextual. People have different identities that they may wish to keep entirely separate. An identity attribute that is relevant in one context [...] perhaps should not be mentioned in another context [...]. Information could be harmful in the wrong context, or it could simply be irrelevant.All of us have different sides of ourselves that we share with different people. The side we show our families is different to the side we show our work colleagues, and this is different again to the side we show our doctor.Privacy means managing those different sides of our identity in a way that allows us to feel comfortable. When personal information is linked or compiled into profiles, we limit an individual's ability to operate under nuanced and multi-faceted identities. Identities are flattened into a single homogenous entity.The problems with this have been well demonstrated recently by some individuals' experiences with social networking sites, where people have posted photos or information about their social lives, only to have that information make an untimely reappearance when applying for jobs. Identities are not meant to be the same for all of our public interactions, and this is why we need to take care to cultivate an environment conducive to good identity management.Biometric technology should, and indeed must, play a role in this. We must take care to ensure that a biometric identifier does not become an excuse to ''flatten' people's identities and curtail their ability to maintain and present separate and different sides to themselves.Identities are sophisticated and so biometric technologies must be the same.