SourceSecurity.com
  • Products
    CCTV
    • CCTV cameras
    • CCTV software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network video recorders (NVRs)
    • IP Dome cameras
    • CCTV camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Audio, video or keypad entry
    • Electronic locking devices
    • Access control cards/ tags/ fobs
    • Access control system accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    Topics
    • Artificial intelligence (AI)
    • Counter Terror
    • Cyber security
    • Robotics
    • Thermal imaging
    • Intrusion detection
    Climax unveils Hybrid Security System

    Climax unveils Hybrid Security System

    Dahua Panoramic PTZ WizMind Network Camera

    Dahua Panoramic PTZ WizMind Network Camera

    Hikvision DeepinView: The Dedicated Subseries

    Hikvision DeepinView: The Dedicated Subseries

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    Topics
    • Artificial intelligence (AI)
    • Counter Terror
    • Cyber security
    • Robotics
    • Thermal imaging
    • Intrusion detection
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Motorola provides VB400 body-worn video solutions to the frontline workers at London Ambulance Service to respond to threats
    • Matrix Telecom Solutions supports Domino's Pizza food chain with seamless and efficient communication systems
    • Anviz releases AI-based biometric facial recognition terminals to facilitate safe return to offices post COVID-19 lockdown
    • Armis and Viakoo announce a partnership to bring together IoT device discovery and remediation
    Topics
    • Artificial intelligence (AI)
    • Counter Terror
    • Cyber security
    • Robotics
    • Thermal imaging
    • Intrusion detection
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Security bytes
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2020
    • Year in Review 2019
    Featured
    • Remote Monitoring technology: Tackling South Africa’s cable theft problem
    • What are the positive and negative effects of COVID-19 to security?
    • Maximising supermarket safety with real-time surveillance solutions
    • The intrinsic role of lighting for video surveillance clarity and performance
    Topics
    • Artificial intelligence (AI)
    • Counter Terror
    • Cyber security
    • Robotics
    • Thermal imaging
    • Intrusion detection
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    Topics
    • Artificial intelligence (AI)
    • Counter Terror
    • Cyber security
    • Robotics
    • Thermal imaging
    • Intrusion detection
    Dahua Technology installs HD CCTV cameras with smart analytics using AI to secure iconic Battle of Britain Bunker

    Dahua Technology installs HD CCTV cameras with smart analytics using AI to secure iconic Battle of Britain Bunker

    Oliver Law Security installs Vanderbilt ACT365 security system to protect one of Doncaster’s largest gyms, The Fitness Village

    Oliver Law Security installs Vanderbilt ACT365 security system to protect one of Doncaster’s largest gyms, The Fitness Village

    Hikvision IP CCTV systems protect visitors and stores at Somerset Mall in South Africa

    Hikvision IP CCTV systems protect visitors and stores at Somerset Mall in South Africa

    CLIQ® access control solution from ASSA ABLOY helps secure museums, shopping and indoor leisure sites

    CLIQ® access control solution from ASSA ABLOY helps secure museums, shopping and indoor leisure sites

  • Virtual events
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Management Systems
    • Integrated Systems
    • Asset Management
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Topics
    • Artificial intelligence (AI)
    • Counter Terror
    • Cyber security
    • Robotics
    • Thermal imaging
    • Intrusion detection
    Shifting trends in operation centers and control rooms for 2021

    Shifting trends in operation centers and control rooms for 2021

    Capture new opportunities with computer vision and video analytics

    Capture new opportunities with computer vision and video analytics

    How Open Supervised Device Protocol (OSDP) is revolutionising access control systems

    How Open Supervised Device Protocol (OSDP) is revolutionising access control systems

    The World of Access Control Webinar - Part 2

    The World of Access Control Webinar - Part 2

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID Global
    • Nedap Security Management
    • ASSA ABLOY
    • Security & Safety Things
    • Hanwha Techwin America
    Other Resources
    • eMagazines
    • Videos
    Topics
    • Artificial intelligence (AI)
    • Counter Terror
    • Cyber security
    • Robotics
    • Thermal imaging
    • Intrusion detection
    Solve access control challenges in the healthcare sector

    Solve access control challenges in the healthcare sector

    The role of access control in a safe return to the workplace

    The role of access control in a safe return to the workplace

    10 step guide to staying ahead of emerging security threats

    10 step guide to staying ahead of emerging security threats

    2021 Trends in Video Surveillance

    2021 Trends in Video Surveillance

About us Advertise
  • Artificial intelligence (AI)
  • Counter Terror
  • Cyber security
  • Robotics
  • Thermal imaging
  • Intrusion detection
  • Body worn video cameras
  • ISC West
  • Video management software
  • Video analytics
  • COVID-19
  • View all
Cyber security
  • Home
  • About
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • White papers
  • Videos
Cyber security

How UL helps security manufacturers comply to cybersecurity standards

How UL helps security manufacturers comply to cybersecurity standards
Larry Anderson
Larry Anderson
Download PDF version
Share with LinkedIn Share with Twitter Share with Facebook Share with Facebook
Related Links
  • Growing data security trends: Internet of Things and cyber security
  • Cyber criminals are ready to attack your business: Are you ready to defend it?
  • Cyber security’s balancing act between utility and protection
  • ASIS 2017 hot topics: Digitising building systems, cybersecurity and cloud services

Cybersecurity is a growing concern for manufacturers of life safety and security products, and Underwriters Laboratories (UL) wants to help solve the problem. Specifically, UL seeks to work with manufacturers to up their game on cybersecurity and to certify compliance to a minimum level of cybersecurity “hygiene.”

UL cybersecurity certification

UL is a familiar brand in consumer goods and in the security and life safety markets. UL certification is sought by manufacturers in a range of product lines, from electrical goods and smoke alarms to access control and central monitoring stations. Approximately 22 billion UL marks appeared on products in 2016. In the physical security industry alone, products are certified to around 20 different standards covering access control, intrusion detection, locks, safes and vaults, software and other categories.

Now UL is working to increase the prominence of their brand in cybersecurity with the UL Cybersecurity Assurance Program (CAP). The UL 2900-1 standard, the standard that offers General Requirements for Software Cybersecurity for Network-Connectable Products, was published in 2016 and in July 2017 was published as an ANSI (American National Standards Institute) standard. The standard was developed with cooperation from end users such as the Department of Homeland Security (DHS), U.S. National Laboratories, and other industry stakeholders. UL 2900-2-3 – the standard that focuses on electronic physical security/Life Safety & Security industry, was published in September 2017.

Testing for cybersecurity weaknesses

The UL 2900 standard encompasses three main areas related to cybersecurity – software weaknesses, known vulnerabilities and risk control such as encryption, access control, passwords, remote communications, and software patches and updates. UL conducts structured penetration, fuzz testing and other tests to establish a reasonable level of confidence that a product or system has addressed cybersecurity concerns.

“Certification to the standard means that a product or system has been evaluated to a minimum level of cyber hygiene,” says Neil Lakomiak, Director of Business Development and Innovation, Building and Life Safety Technologies, for UL LLC. “It covers the ‘blocking and tackling’ that you would expect manufacturers to do. It doesn’t provide absolute assurance, but rather a level of confidence that a product has been vetted.” The certification is good for one year, and changes in products require recertification.

UL global network of scientific and advisory experts
UL has written more than 1,600 standards defining safety, security, quality and sustainability

Lakomiak says applying the standard will: “create an environment where companies are starting to incorporate cybersecurity into their development processes; creating security by design. It will elevate the industry to consider cybersecurity earlier in the development process.” An overall goal of UL is to “give people peace of mind around the products and systems they use.”

Underwriters Laboratories at ASIS 2017

Companies that achieve certification can promote it as a point of differentiation in the market, although not a guarantee that a product is cybersecure. UL’s independent evaluations carry weight in the market, as reflected by the ubiquity of the UL brand, and Lakomiak contends the industry can benefit from applying the same level of testing and certification to the area of cybersecurity. He sees UL’s cybersecurity initiative as complementary to other cybersecurity measures, such as “white hat” hacking. From a standards perspective, UL’s efforts seek to complement industry efforts such as SIA, ASIS International, PSA and ONVIF.

Lakomiak was at the ASIS 2017 show in Dallas, where he met with existing manufacturer customers and potential future clients – including large and small companies in the industry – to discuss cybersecurity and the road to certification. He says many manufacturers are not yet ready for certification, in which case UL provides consultancy and advisory services to help them get there.

“A lot of companies just need help understanding what their current processes and cybersecurity posture are,” says Lakomiak. “They want help to create a roadmap to get certification. A variety of manufacturers are on the path to certification.”

Underwriters Laboratories security mission

The cybersecurity element is an extension of UL’s mission to help companies demonstrate safety, confirm compliance, deliver quality and performance, and build excellence. Lakomiak says many people mistakenly perceive UL as a quasi-governmental organisation, perhaps because UL standards are sometimes incorporated into regulations.

However, the organisation is a business and wants to operate like one by serving the needs of its manufacturer customers. “We want to have the service we provide be market-driven. We understand the pain points of manufacturers, integrators and others as they interface with technology. We want to devise programmes to help them be successful in the market. Our focus is to make our customers succeed by providing objective certification.”

To the extent that cybersecurity is a growing pain point for the physical security industry, there is a large potential role to be played by UL and many others.

Share with LinkedIn Share with Twitter Share with Facebook Share with Facebook
Download PDF version Download PDF version
  • Network / IP
  • Security systems
  • Physical security
  • Security access systems
  • Intrusion detection
  • Security alarm
  • Security software
  • ONVIF
  • IP security solutions
  • Trade Show/Exhibition
  • Cyber security
  • Central Monitoring
  • Smoke Detection
  • Related categories
  • CCTV software
  • Intruder detectors
  • Access control software
  • Access control systems & kits
Related articles
Expert roundup: healthy buildings, blockchain, AI, skilled workers, and more

Expert roundup: healthy buildings, blockchain, AI, skilled workers, and more

What will be the biggest security trends in 2021?

What will be the biggest security trends in 2021?

What are the new trends and opportunities in video storage?

What are the new trends and opportunities in video storage?

Follow us

Sections CCTV Access Control Intruder Alarms Companies News Insights Case studies Markets Virtual events Events White papers Videos October 2017 news RSS
Topics Artificial intelligence (AI) Counter Terror Cyber security Robotics Thermal imaging Intrusion detection Body worn video cameras ISC West Video management software
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy
See this on SecurityInformed.com

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SourceSecurity.com - Making the world a safer place
Copyright © Notting Hill Media Limited 2000 - 2021, all rights reserved

Our other sites:
SecurityInformed.com | TheBigRedGuide.com | HVACInformed.com

Subscribe to our Newsletter


SourceSecurity.com
SecurityInformed.com

Browsing from the Americas? Looking for our US Edition?

View this content on SecurityInformed.com, our dedicated portal for our Americas audience.

US Edition International Edition
Sign up now for full access to SourceSecurity.com content
Download Datasheet
Download SourceSecurity.com product tech spec