Balance, expertise, documentation

February 2015 Integrated Solutions

While few people would deny the need to secure people, assets and operations in any enterprise, there is a tendency for many to think that a security implementation is a once-off job that renders your system secure. This is, of course, a fallacy.

Any security implementation, whether it is made up of physical measures, logical security or combination of both, will have vulnerabilities. The trick in designing and running a security operation is therefore to find a balance between security, vulnerabilities and the need for legitimate access to the various aspects of the operations.

Balance

The cabling infrastructure of the Gautrain project is a good example of this. Cable theft is a constant problem for every company that relies on communications, whether via Telkom lines or its own network. Electricity is also supplied via cables, which puts this necessary resource at risk too.

Photo by flowcomm via Flickr Creative Commons (<a href="http://www.flickr.com/photos/flowcomm/" target="_blank">www.flickr.com/photos/flowcomm/</a>).
Photo by flowcomm via Flickr Creative Commons (www.flickr.com/photos/flowcomm/).

The Gautrain relies on electricity, signalling and digital communications to function. The Gautrain’s Operator’s headquarters is the main power distribution centre, managing the flow of some 80 kW. There are four additional substations managing the electricity to other areas within the rail network. The power supply must serve the 10 stations along the 80 km system as well as provide energy for the train sets to run as per the schedule, creating an effective, efficient and reliable system.

The second critical infrastructure is the signalling cable. This is the most critical asset providing the governance of safety for the system and passengers, allowing the Gautrain to run at speeds of 160 km per hour. If this asset is damaged, the trains are not permitted to go faster than 30 km per hour, making the Gautrain a very slow crawling system, much slower than the traffic on the very congested Ben Schoeman highway. Naturally, communications is a critical part of the Gautrain to provide radio communication for the train drivers, conductors, security, station personnel and maintenance personnel as well data between the stations. Where the physical communication is of utmost importance for the operations of the system, data is the platinum of the system. This supplies business intelligence, passenger flow statistics, parking facilities utilisation etc., to be used for the operational deployment of resources. This is all supplied through kilometres of various strands of copper, signalling, earth and fibre optic cables linking the whole system together and allowing for effective performance and management.

It is therefore logical that protecting this communications network would be a high priority. However, if the solution was to build high walls with regular guard posts and to seal the cabling into the conduits with concrete, for example, the cost of securing the 65 km perimeter – on both sides – would be prohibitive and any maintenance required would be extremely difficult.

As it is, the perimeter security solution was limited by budget constraints and, more importantly, the need to allow maintenance technicians and security personnel to gain access to all areas of the system. The result Snyman and his team came up with was a layered approach to security.

The perimeter is protected on both sides by two palisade fences with barbed wire in some areas, which has the benefit of keeping the site visible at all times and limiting hiding spaces. There are also 108 gates for authorised access. The cabling conduit is accessible via numerous steel plates located next to the tracks, secured by two bolts that require a specific key to unlock – this prevents the plates from being lifted with a crowbar. The cables are buried underground in cable ducts to prevent easy access.

Snyman admits that this is not the most secure option that could have been chosen, but was the best solution given the prerequisites and the available budget. The need for security was balanced with the need for access. (It’s worth noting that multiple parties, from the Gauteng legislature and national government, the police and the National Security Agency were involved in approving the security for the whole project.)

Despite this, Snyman says there are still vulnerabilities in this area due to the human effect. As an example, technicians want quick access and there are times when bolts are not secured after maintenance is done, or only one bolt is secured as the workers hurry to the next job. Training and quality control of work done will assist in preventing this type of vulnerability, but it is something the Gautrain operator has to deal with as it is has to allow maintenance and repair access.

Expertise

As noted, many people were involved in the approval of the security measures for the Gautrain project. Snyman believes that one person or company cannot have all the answers to a complete security solution and the project managers therefore need to make use of experts in various fields if they want the best solution.

The final solution will be made up of the input of various experts, who will (hopefully) have ensured a skills transfer process to ensure that the operators onsite would be able to maintain the security solution independently into the future. The training of employees in the various aspects of security is also crucial, from the guards through to management.

At its most basic level, this will ensure that all staff are aware of what is happening and what should be happening, as well as what the correct reaction is to various events. Engaging with partners who try to keep their expertise to themselves or will not provide explanations of the ‘why and how’ is a dangerous practice.

In addition, since there will be staff turnover at all levels of the project, documenting these processes from day one is also a crucial aspect of a security operation. These historical legacy records are the lessons learned from the past to be used for any future project. This results in a standards and compliance checklist from challenges, solutions and best practices, which Snyman kept meticulously during his tenure.

Documentation

In some areas of business, a new manager may be appointed and he/she will immediately try to develop a team that functions the way they want them to. This may or may not be a good idea, depending on the business and the environment. In the security world, however, a 'new broom sweeps clean' approach can cause serious problems. Of course, if the security operation was failing this would require significant changes, but if it was working well, change for the sake of change is a recipe for disaster.

Snyman therefore considers documenting the security processes in detail a critical process. The documentation should be done in a way that any new person coming onboard will be able to understand what was done and why, what the risk tolerance of the company is in various situations, and the company’s best practices in its security operations.

Detailed documentation will also allow for measured improvements and expansion of the security operation that builds on the existing solution. And as the solution expands to cater for new situations and risks, as well as resolving some previous vulnerabilities, the documentation should be updated and extended to detail the expansion. It is also advisable to ensure that the older documentation is available in order to provide a full history of the system for future reference.

Documenting the processes also provides a foundation to effectively measuring and auditing the operation, ensuring the goals and requirements of the company are met. Audits, whether it is ISO 9001:2008 or annual internal audits, should be Risk Based Audits (RBA) and the premise of departure must always be the latest comprehensive risk management plan for the specific environment.

A full security solution for a project the size of the Gautrain operation is a complex project that requires input from internal and external stakeholders, companies, people and experts. It is a lesson in risk assessments and identifying the most important risks to deal with and finding a balance between total security and workable security that permits the operation to function to its maximum capacity over the long term. It requires ongoing skills development and regular reassessments to ensure the security operation maintains the levels of performance required and improves over time.

Nico Snyman is the managing director of Crest Advisory Africa, specialising in risk management, corporate governance and advanced technologies. For more information, contact [email protected], +27 (0)11 534 8454 (office) or on his mobile +27 (0)76 403 4307.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Future trends for electronic safety and security in mining
Fang Fences & Guards Mining (Industry) Integrated Solutions AI & Data Analytics
The mining industry is ever evolving, driven by technological advancements and the growing need for enhanced safety and security measures, with significant innovation seen in turnkey electronic security for mining operations.

Read more...
Unlocking enhanced security for mining
Mining (Industry) Integrated Solutions
In the dynamic landscape of African mining, security remains of paramount concern as threats evolve and challenges persist, and mining companies seek innovative solutions to safeguard their operations, assets, and personnel.

Read more...
A constant armed struggle
Technews Publishing XtraVision Editor's Choice Integrated Solutions Mining (Industry) IoT & Automation
SMART Security Solutions asked a few people involved in servicing mines to join us for a virtual round table and give us their insights into mine security today. A podcast of the discussion will be released shortly-stay tuned.

Read more...
Access and identity in 2024
Technews Publishing Gallagher HID Global IDEMIA Ideco Biometrics Enkulu Technologies neaMetrics Editor's Choice Access Control & Identity Management Integrated Solutions
SMART Security Solutions hosted a round table discussion with various players in the access and identity market, to find out what they experienced in the last year, as well as their expectations for 2024.

Read more...
Advanced security solution for high-risk areas
Secutel Technologies Surveillance Integrated Solutions
The need for a sophisticated intrusion detection system is paramount when faced with persistent security challenges, particularly in isolated battery rooms or high-risk areas prone to vandalism, cable theft, and battery theft.

Read more...
Vumacam and NAVIC enhance SafeCity initiative
Integrated Solutions Security Services & Risk Management
Vumacam and NAVIC, two of South Africa's most respected surveillance technology and vehicle intelligence providers, are proud to announce an alliance that will greatly expand the coverage and impact of the SafeCity initiative across the country.

Read more...
Gallagher Security’s achieves SOC2 Type 2 recertification
Gallagher News & Events Integrated Solutions Infrastructure
Gallagher has achieved System and Organization Controls (SOC2 Type 2) recertification after a fresh audit of the cloud-hosted services of its integrated security solution, Command Centre. The recertification was achieved on 21 December 2023.

Read more...
Integrated transportation security
Guardian Eye AI & Data Analytics Integrated Solutions Logistics (Industry)
HG Travel installs an AI-powered camera system integrated across 115 vehicles throughout a fleet comprising 160 vehicles of different sizes, along with predictive and self-monitoring tools to track tyre condition, fuel consumption and theft, and overall vehicle maintenance.

Read more...
Embracing next-generation surveillance for safer cities
Surveillance Integrated Solutions AI & Data Analytics
With the South African government highlighting the importance of building smart cities by integrating advanced technologies to make them more resilient and liveable, the role of next-generation network video and surveillance technologies cannot be ignored.

Read more...
Gallagher Security releases Command Centre v9
Gallagher News & Events Access Control & Identity Management Integrated Solutions
Richer features, greater integrations, with the release of Gallagher Security’s Command Centre v9 security site management software designed to integrate seamlessly with various systems and hardware.

Read more...