
Security Basics mailing list archives
Re: Biometric Access logs
From: Shailesh Rangari <shailesh.sf () gmail com>
Date: Mon, 2 Mar 2009 14:17:16 -0500
Dear John,I understand that the infrastructure @ your organization maybe different than we had @ my former workplace. But I will still go ahead and mention how we tackled this problem @ my former workplace.
All the Data Centers had a Dual Factor Authentication, Layer 1 Access Card & Layer 2 Biometrics Access.
The Layer 2 Access was Monitored and Recorded 24/7 by Camera's.This ensured that even though our Biometrics Access Control Logs had an Access Granted/Denied reference we had the Layer 1 Swipe Card Logs (with card unique no.) to Cross Verify with. In a case where we couldn't verify the two logs, the Camera Recording always came handy.
Regards, Shailesh On Mar 2, 2009, at 7:24 AM, John wrote:
Hi All, Request you to give your views on the following issue.We have Biometric access controlled server room door for better security. There is no doubt that Biometric proovides enhanced protection. But theissue with this access control mechanism is that it is not possible to review and analyze denied attempt logs since the logs only shows thataccess was denied, but to whom and other details are obvisouly not shown because only few users from IT department only have the access to the serverroom.It is not like Swipe cards based Access control where all the employees areregistered with the access control system.In that it becomes easily possible to trace who tried to access what andwhen.We faced issue in the audit because of this and auditor insisted that the review and analysis of the logs for the Biometric controlled area needs tobe done.What can be done in this scenario like this? Please give in your comments.Thanks.
Current thread:
- Biometric Access logs John (Mar 02)
- Re: Biometric Access logs Shailesh Rangari (Mar 03)
- Re: Biometric Access logs Thor Norse God of Thunder (Mar 03)
- RE: Biometric Access logs Murda Mcloud (Mar 03)
- RE: Biometric Access logs Christian Campbell (Mar 03)
- Re: Biometric Access logs Kurt Buff (Mar 03)
- Re: Biometric Access logs Stephen Mullins (Mar 03)
- Re: Biometric Access logs Rogerio Carvalho (Mar 03)
- <Possible follow-ups>
- RE: Re: Biometric Access logs fac51 (Mar 05)