SIA Calls for Greater Collaboration To Improve HSPD-12 Implementation

In recent testimony before the U.S. House Subcommittee on Government Management, Organization and Procurement, Rob Zivney, vice president of Marketing for Hirsch Electronics and member of the Security Industry Association Board of Directors, called implementation of HSPD-12 a pioneering effort which will require both a financial investment and development of new infrastructure.

“The opportunity to testify on behalf of our industry is a testament to the legislative inroads and successes SIA has realized in recent years,” said Richard Chace, executive director and CEO, The Security Industry Association. “We look forward to working closely with committee members to implement our recommendations.”

At the hearing, Zivney urged the subcommittee to direct the Office of Management and Budget’s (OMB) Office of E-Government and Information Technology to establish a dedicated “physical security team” composed of professionals with substantial knowledge of physical security technologies and physical security infrastructure within federal agencies. As part of its responsibilities, this physical security team would support the ongoing efforts of the Interagency Security Committee charged with developing physical security policies, standards, and strategies at non-military government facilities.

He also recommended OMB establish a policy for implementation of physical security similar to OMB Memorandum M-05-24. Currently, PIV-I and PIV-II are “unfunded mandates.” However, physical access control systems are outside of that scope and have neither funding nor a mandate. This requested policy must recognize that the PIV card is not compatible with most installed PACS currently in use and that the PACS will have to be, at a minimum, upgraded or most likely, replaced.

Finally, Zivney called on the committee to use SIA as a resource for the effective utilization of the PIV credential with physical access control systems. He noted that SIA not only has the skills and knowledge for deployment and use, but as an ANSI standards development organization, is able to produce standards for physical security systems.

Additional highlights of Zivney’s testimony include:

  • HSPD-12 and the associated standards developed by the National Institute of Standards and Technology (NIST), specifically the identity vetting processes, form a far stronger foundation for our federal government agencies’ security than we have ever witnessed in the past.
  • The scope of the investment and time required for HSPD-12 implementation were underestimated by the government when it set goals for the deployment of HSPD-12 through the OMB Memorandum M-05-24.
  • Traditionally the functions of authentication and authorization have resided locally with the administrator of the physical access control system (PACS). The HSPD-12 and Federal Information Processing Standard (FIPS) 201 model have changed this: the credential issuer to a large degree now handles authentication while authorization remains a function of the PACS. This has created a unique challenge facing federal agencies, the development of a substantial shared infrastructure to accommodate the increased functionality and security features of the PIV II credential.
  • HSPD-12 requires information technology departments, human resources, and security departments interface and cooperate on an unprecedented level. These three disciplines traditionally are different in cultures and basic objectives. This creates challenges for all parties involved.
  • In the absence of clear guidance and specifications for the systems that will use the PIV card, some manufacturers have stepped up to the challenge and assumed substantial research and development costs to produce next generation equipment capable of utilizing the features of a PIV II credential. This work has been conducted without the benefit of having operational PIV II credentials available to manufacturers to develop and test associated product.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3