
Mission Impossible? Integrating physical security and IT![]() Steve Hunt, President of 4A International, discusses some of the challenges associated with integrating physical security and IT and offers some practical solutions. A chief financial officer recently told 4A International that in one month he received two purchase order requests that he could not approve. One came from the security department for an €1 million upgrade to the access control infrastructure to manage people and their privileges to corporate assets. Then he received a request for a €1 million “identity management” solution from the IT department. It too was designed to manage people and their privileges to corporate assets. One system managed physical privileges and the other data, but that subtle difference was lost on the CFO who declared the expense redundant, demanding that the two groups work together to save costs. Bringing two very distinct security solutions together into one is complex, but achievable. 4A International suggests making changes in technology, attitude, processes, and how you “sell” the project.
Technology 4A research has found that in 5 years, the systems on which most access and event management deployments will rely will be software written by IT companies. Physical security dealers and integrators need to adopt, to a certain extent, some “IT awareness” or sensitivity. Here are other issues, which, if ignored, could get you knocked off the ladder by an angry IT techie. Recommendations
IT professionals are very possessive of “their” network and servers. Similarly, physical security professionals have been doing security for a long, long time and feel they’ve earned the right to decide what’s best for their clients. 4A research shows that corporate security personnel are by-and-large inexperienced with computers and networking technology, and are not inclined to learn computing skills independently. Conversely, IT personnel are highly inclined to learn new technology skills. The best approach for convergence work is to highlight the capabilities and expertise of all members of a project team. Recommendations
Processes & Policies Most IT managers are rigorous about policies and processes. You’ll go far by conforming your systems to the policies of your customer’s IT department. Recommendations
Selling the project
Take a cue from the IT guys who over the years have become adept at gaining support for their projects directly from business unit managers. Getting the buy-in for security products and services today means understanding what drives your customer’s security purchase decisions. Fear, uncertainty and doubt are not the cleverest tools to use anymore. No one cares about security. Outside of the security profession, everyone in the company thinks security is an annoying layer of cost and inconvenience. Couch all project descriptions in terms of value, and enabling the business. Value wins every time. Conclusion The security profession’s growing use of software, computers, and network connectivity will drive a steady increase in interactions between physical security and IT groups. Done well, these projects will yield millions of pounds of value in improved efficiency, reduced costs, elevated security and increased ability to respond to new needs. After all, it’s not our job to secure the building. It’s our job to secure the business. |