There s a new concept in security. Think beyond IT convergence. Think Identity Analytics.

Size: px
Start display at page:

Download "There s a new concept in security. Think beyond IT convergence. Think Identity Analytics."

Transcription

1

2 PROACTIVE & PRE-EMPTIVE WORKFORCE MANAGEMENT AT THE DOOR There s a new concept in security. Think beyond IT convergence. Think Identity Analytics. Can you risk an employee entering a restricted area without appropriate training? Can you guarantee your contractors have the right licences, appropriate safety equipment and insurance? By harnessing the power of real, operational business convergence you can engage the myriad of systems within your organisation, delivering the most appropriate access control decisions possible based on dynamic variables. By leveraging your core investment in physical security infrastructure you can automate compliance with operational and regulatory policy, ensuring your people are competent, safe and accountable as they move around on site.

3 TRAINED COMPETENT ACCOUNTABLE ACCESS GRANTED PROACTIVE WORKFORCE Management Identity Analytics provides the ability to enforce business safety and security processes via distributed hardware at the door. Traditionally, if a person is denied access they have little or no understanding as to the reason. They are left with the frustration of having to report their situation to their manager or Security personnel. Identity Analytics delivers truly intelligent access control decisions which are communicated in a meaningful way on distributed hardware at the point of access. Staff are warned via a door reader screen of any upcoming expiry of their licences or competencies so that they can proactively prevent these from becoming an impediment to their access. If denied access, staff are also immediately informed of corrective action they should take in order to have their access to an area re-instated. For example, a employee may be denied access if he needs to complete certain training before accessing equipment, or a licence to access a vehicle before signing on for his shift. Pre-emptive Risk Management Bi-directional information flow between business systems overlayed with policy and its effect at the door delivers an ongoing impact throughout your organisation. As business rules are set, managers are assured that organisational and regulatory policy are automatically enforced. The effect on day-to-day business can be felt on the ground by every employee they have the assurance that their co-workers are fit for work, and that their working environment is safe. Activity can be monitored and measured through a real-time audit trail. This unprecedented transparency means business decisions and requirements can be adjusted and actioned quickly in response to their effect. This greatly mitigates the risk of accidents, partial or full site shutdown, and corporate liability. It can also have a very positive effect on insurance premiums. As well as enforcing compliance with business and regulatory policy under a normal operational situation, exceptions can be accommodated - for example, in emergency situations certain people need access to areas they otherwise couldn t access, others need to be kept out and a full audit trail of all access events is required. The ability to accommodate exceptions means personnel flow and safety are optimised, no matter what the situation.

4 PREMIER WORKFORCE MANAGEMENT SOLUTION Through our own Cardax FT platform for integration and integrated third party systems, Gallagher delivers the premier people & site management solution encompassing: cardax ft - the platform for integration 1 24/7 personnel flow and workforce management 1 customised door entry 2 visitor management 2 contractor management 2 beyond access control 3 perimeter security - powerfence trophy ft 4 vehicle/fleet management 5 combined vehicle & driver identification 5 vehicle process automation 5 training & inductions 6 testing (drug & alcohol) 6 fatigue & exposure management 6 access expiries management 7 emergency management site lockdown 7 evacuation & tag boards functionality 7 workflow management 7 securing lower security doors 8 protecting high security areas 8 KEY CONSIDERATIONS integration platform 9 scalability & flexibility 9 enterprise security management 10 it security: high data encryption 12 it compatibility 12 software licence and maintenance agreements 13 professional services 13 why gallagher? 14

5 A core system for security management and monitoring, the Cardax FT software provides a single graphical user interface. CARDAX FT - the platform for integration Designed by some of the world s most capable security engineers, the Cardax FT system is without peer in the field of large scale, high security, integrated systems. As the platform for integration, it assumes the central role in delivering Identity Analytics functionality. Cardax FT is a comprehensive Microsoft Windows based security system that provides high-level security management for global access control, intruder alarms, voice over IP, and alarms management requirements. At the face of the Cardax FT system are its comprehensive range of readers, Intelligent Door Terminals and Remote Arming Terminals. By badging a card or presenting a finger at an integrated third party biometric reader, a multitude of reactions can be programmed to happen. At the most basic level, access will be granted and the door will unlock providing the person is authorised to enter. Access decisions enriched by information from databases and other sources throughout your business ensure every access decision is unique and therefore, highly relevant. 24/7 PERSONNEL FLOW AND WORKFORCE MANAGEMENT Leveraging physical security hardware, Gallagher s solutions give you complete control of who can access specific areas, at specific times of day and night: Who Staff, HR, IT, Management, CEO to Contractors, Visitors & Consultants with What - Individuals competencies (induction, training, licenses, security clearances) Where Total site security from the perimeter fence line (single or multi-site) and remote buildings and equipment, through to accommodation and corporate offices When 24/7 Gallagher s Cardax FT platform for integration resides on your site s network providing a holistic view of access events and allowing you to govern personnel flow throughout your facilities from head office to manufacturing plant to port. Cardax FT enables you to track and determine who can go where and when throughout your site as all employees, contractors and visitors badge their programmable access cards at access control readers. Cardholder movement can be tracked and controlled at doors, boom gates, vehicles anywhere a reader is mounted. The Universal Card Format tool means Cardax readers can read a range of third party access control cards - a notable practicality and cost saving for sites with existing ID cards. Mifare Smartcards have multiple applications beyond access control, such as pre-paid vending. 1

6 CUSTOMIsED DOOR ENTRY Extended access time can be granted to specific cardholders and doors allowing mobility impaired employees or visitors longer entry and exit times to pass through a door. SEAMLEss VISITOR MANAGEMENT Fully integrated Visitor Management within Cardax FT means Visitor records are maintained within the system for re-use when required. Historical Visitor records provide an audit of all Visitor movements over time. Visitor Cards can be re-used over and over minimising the time required to enable Visitor site access and exit. Visitor Management is highly customisable to meet site specific requirements. It also enables implementation of effective evacuation processes for Visitors in the event of an emergency. Different types of visitors can be granted different access based on their access requirements and have different information stored against their records. CONTRACTOR MANAGEMENT Contractor access can be granted and controlled based on the time/date they are supposed to be on-site. Automatic revocation of cards prevents unauthorised access after their contract has expired. Time on-site can be tracked for billing purposes and can be used to audit if contractors are on-site for maintenance or repairs as scheduled. Cardholder information can be recorded in Cardax FT and shared bi-directionally with existing HR/people management systems for accurate, real-time use. Staff records provide a full audit trail to ensure compulsory training and testing are undertaken. This minimises corporate liability and enables organisations to meet their Duty of Care. 2

7 BEYOND ACCEss CONTROL Detecting Intruders Separate intruder alarm systems become superfluous. Core security both allowing access and eliminating intruders is streamlined into one system. Readers can also arm and disarm alarms. If there is a security breach, an immediate report will be sent to your monitoring company reporting exactly where the incident has occurred. DVR/CCTV Integration Integrated DVR or CCTV systems provide a visual and auditable record of system events. DVR feed can be viewed live by an operator or can be viewed in response to an event and can be relied upon to provide evidence if needed. Combining Cardax FT with Video Surveillance Cardax FT integrates with many brands of CCTV / DVR systems to work in conjunction with your core access and alarm system. Cameras can be viewed live at all times, or triggered to start recording in response to an event. Attractive Readers World class industrial design has been applied to readers, giving them the reputation of the most aesthetically pleasing readers available. Monitored Readers Cardax readers are monitored, so operators know they are all functioning. Incorporating Cardax FT Challenge Some readers require only card, others card plus PIN. Some doors require the cardholder to be visually verified by the operator, known as Challenge. Integrating with Intercom Systems The Jacques intercom system is supported enabling intercom functionality to be integrated into Cardax FT. Integrating Elevators Card readers can be installed in elevators, providing control and reporting of access to floors. 3

8 PERIMETER SECURITY - powerfence tm trophy ft For organisations with perimeter areas in often remote sites, perimeter security is vitally important both in terms of protecting and securing staff, resources and equipment and also fulfilling their Duty of Care to the public by ensuring they cannot access potentially hazardous areas. Gallagher s PowerFence Trophy systems actively deter would-be intruders and trespassers and detect attackers. The system consists of a grid of electrically pulsed, high tensile, wires that can be constructed inside a new or existing perimeter fence. PowerFence systems are non-lethal and, without a doubt, safe; they meet international safety standards. PowerFence Trophy systems are divided into zones which are individually monitored so that in the event of an attack, security staff or a monitoring company can pin-point which zone is affected and respond appropriately. Through high level integration with Cardax FT, a PowerFence perimeter security system can be configured, controlled and monitored within Cardax FT. All alarms from the perimeter are logged in Cardax FT and monitoring staff can respond accordingly. Integration with imaging systems means attacks on the fence can be viewed and recorded providing a comprehensive audit trail of events and seamless site security. Multiple remote sites can be monitored and protected at a central point using Cardax FT. Gallagher is the only manufacturer world wide to produce a fully integrated access control, intruder alarm and PowerFence TM perimeter security system. 4

9 OPERATIONAL CONTINUITY THROUGH INTEGRATED VEHICLE / FLEET MANAGEMENT Driver based automatic vehicle identification (AVI) offers fast, convenient and secure vehicle access for authorised drivers. The integration of Nedap AVI with Cardax FT ensures that a vehicle can never leave, or get access to a secured area unless occupied by an authorised driver. Vehicle and driver access traditionally requires the driver to stop and badge or present their access card. This can often result in traffic congestion around access points / gates. The Gallagher solution allows vehicles (both trucks and cars) to activate gates far enough in advance (up to 10m [33 ft], at speeds up to 200 km/h [125 mph]) which eliminates the need for vehicles to stop, ensuring an uninterrupted flow of traffic. This is a notable feature for industrial sites where it is disruptive to stop and start heavy machinery or in the hospital environment when instantaneous access is required in emergency situations e.g. for ambulances and on-call staff. COMBINED DRIVER & VEHICLE ID BASED ON EXISTING ACCEss CONTROL BADGES The option of combined driver & vehicle identification increases security as you know exactly who was driving which vehicle. Additionally you can also monitor fluid driver and vehicle situations. The integrated Nedap AVI system provides the ability to identify driver and vehicle simultaneously delivering totally hands-free access to you site. Safety is improved by eliminating the need for drivers to reach out a vehicle window to badge their access token at a stationary reader, which is typically required with card-only vehicle access. VEHICLE PROCEss AUTOMATION The vehicle identification system can also be applied to automate the process of managing vehicles on your premises. Contractors that come on site can be identified automatically and, when authorised, are granted access to your site. Their vehicle can then be guided to the designated area for loading/unloading. The vehicle can be identified at weighing bridges, and weighing information can be linked to the vehicle ID number. Information regarding vehicle activity on site can be automated and monitored via the central management system. 5

10 TRAINING AND INDUCTIONS Inductions, Licenses, Qualifications and Training can be facilitated and monitored within Cardax FT: Configure your training matrix and automate compliance: > > Inductions can be associated with an area, so that when a Cardholder is given access to the area the required Inductions are automatically applied. The Cardholder will not be able to access the area until the Inductions are completed > > When Inductions are completed the access that they enable can be automatically added to the Cardholder A site to also manage access based on parameters such as: > > Contracts and insurances ensure a Contracting Company has a contract with your company and has current insurances in place > > Through integration with a third party system, roles (such as Production Officer in SAP) could translate into access into all of the smelters within your company Multiple external training or other systems can be seamlessly integrated, thereby eliminating duplication of entries. > > For example, creation of a new employee in your Human Resources system along with their qualifications can automatically create a Cardholder in the Cardax FT system. Coupled with the Induction process in the Cardax FT system, access can be automatically granted, with no human interaction. DRUG AND ALCOHOL TESTING Through integration with third party systems, Gallagher enables organisations to comply with OH&S regulations by ensuring automatic, random drug and alcohol testing. The system is configurable to meet the testing and selection processes of your site: Can be utilised to test based on a range of parameters extending its functionality beyond drug and alcohol testing i.e. can randomly test on key induction questions to ensure core knowledge of staff is maintained Can be configured to integrate with Fatigue Management to ensure checks such as hydration or heat stress etc can be performed on the personnel that require it the most. 6 FATIGUE AND EXPOSURE MANAGEMENT Integration with third party systems automates fatigue and exposure management to ensure only anomalies are raised for attention: Check for events such as who has been on site for too long, who has not had sufficient break or who has accessed the site too many days in a row Actions such as disabling Cards, alerting Managers or alerting the Cardholder can be initiated based on breaches of pre-defined rules Ensures regulatory mandates are followed and that your people are safe and less likely to injure themselves or others.

11 ACCEss EXPIRIES MANAGEMENT Through integration with third party systems cardholder access management is completely automated for a proactive approach to dealing with pending access expiries: Set up checks for Cards, access or training that is going to expire Rules can be set up for expiries pending within a user-defined period, e.g. 30 days, with varying degrees of action in accordance with the level of urgency Send expiry alerts out via SMS or to the Cardholder affected and to anyone else who needs to be informed. EMERGENCY MANAGEMENT AND SITE LOCKDOWN In the event of an emergency, real-time Cardholder location data can be provided. As Cardholders move from an unsafe area to a muster point, their names move from one part of the Operators screen to the other. The screen can also be used as a Tag Board outside any areas that require visibility of who is or is not in an area. Partial or total site lockdown during threat or emergency situations allows only a selected group of staff (e.g. rescue or medical personnel) to enter and exit locked down zone/s. EVACUATION AND TAG BOARDS Third party system integration delivers Evacuation and Tag Board functionality providing the ability to find groups of people quickly across a large site: Any number of Areas can be configured for different site views e.g. to show all people in all mine shafts on site Cardholder movements are immediately reflected in the system site-wide providing all operators with a single, real-time view Delivers efficient staff and visitor evacuation in the event of an emergency Automated electronic Tag Boards allow operators to know who is in an Area. WORKFLOW MANAGEMENT Through integrated third party systems, inductions and access can be configured and managed to ensure no one person can allocate and enable access without a number of configurable checks being completed. Once established, access can be controlled by Cardax FT (no human action required) to ensure compliance with site processes. 7

12 SECURING LOWER SECURITY DOORS Every business has doors which typically don t justify the cost of installing fully monitored electronic access control. Day-to-day access through wireless door locks is an ideal replacement for the traditional key and lock method. Keys can be a logistical challenge to manage; they can easily be lost meaning locks and keys have to be replaced at high ongoing cost. Gallagher provides a cost effective electronic access control solution through a high level interface with Aperio wire free, online access control door readers and with Salto wire free, offline access control door readers. Employees are able to use their single Mifare ID access card to gain access to cupboards, lockers, and other lower security doors as well as other more highly secured areas business wide. PROTECTing HIGH SECURITY AREAS High security areas can require tighter security measures. High level integration of SAGEM fingerprint readers provides an ideal solution, delivering both identification and verification. Seamless fingerprint enrolment and template management is achieved from within the Cardax FT user interface. Only the relevant fingerprint templates are sent to each reader, saving reader database space and cost. The readers immediately reflect schedule and access group changes in Cardax FT. In addition, the integration allows the option for duress fingers to be enrolled for tighter security. If a duress finger is presented at a reader, access is granted as per normal access privileges, but an alarm is raised to alert the operator of a duress situation; this is a significant feature for increased staff and site security. 8

13 INTEGRATION PLATFORM Keeping up with day-to-day changes that occur within large organisation can present real challenges in security management. Utilising IT industry protocols, Cardax FT can integrate with most existing information systems, such as staff or student databases, payroll systems and resource scheduling systems. This means only one point of data entry is needed to maintain staff, visitor, contractor or student records. Imagine, for a university, the impact of using the student registry database to automatically generate access information at enrolment time. Lecture theatres can be unlocked at scheduled class times, with lighting and air-conditioning activated for the duration. Using industry standard OPC, Cardax FT interfaces to Building Management systems for energy management functionality, based on area occupancy. SCALABILITY & FLEXIBILITY The Cardax FT system makes use of existing IT networks, and features the most secure encryption technology available. It can utilise existing company databases, and provides the means for future expansion. Whether your business has a just a few monitored doors through to thousands at geographically distributed sites, Cardax FT can grow to meet your requirements without hardware redundancy or unreasonable costs. This means if you want to add new buildings, employees, or tenants in a multi-tenanted site, the expansion can be easily incorporated into your existing system even across time zones and international borders. Multi-Server functionality makes Cardax FT an exceptionally powerful system for enterprise security management. System division enables individual sites or tenants within a large network to manage the security of the property that is pertinent only to them, without viewing other divisions. The cost of the system can then be shared by tenants, or managed centrally by a property manager. The scope and inherent security of Cardax FT has proven the system a winner for market leaders in a diverse range of industries, from general commercial sites, to critical infrastructure, utilities, mining, ports, government, tertiary education, telecommunications, banking and finance to hospitals, aged care facilities and schools. Cardax FT has the ability to meet the security needs of any enterprise. 9

14 ROBUST enterprise SECURITY MANAGEMENT Large systems with distributed sites manage costs by bringing sites onto one centralised system. Using IT infrastructure, remote bases can be managed from the central Cardax FT system no matter how many buildings you have or where they are in the world. While each building might have a Cardax FT workstation, it will be linked to the main server allowing one central management system to monitor security right across the entire enterprise. A head office in New York might have control over who gains access to the Sydney office in Australia. Furthermore, it doesn t matter if an employee is working in the Tokyo plant or the Dublin office they are able to use the same Cardax access card or biometric fingerprint. Centralised access control and alarm monitoring can significantly reduce telecommunication and monitoring expenses. Multi-Server functionality supports peer-to-peer communications between multiple servers, which enables Cardax FT to operate effectively in a distributed environment. This distributed environment may include multiple sites separated by large geographical distances and connected via low bandwidth and/or intermittently available networks. These connections can be created in a hierarchical structure (where a head office may want operational visibility/control capability over subsidiary sites) and / or in a peerto-peer matrix structure. Peer-to-Peer Server Communications Security Multi-Server functionality utilises highly efficient communications protocol to transfer data between sites, by reducing data transferred over WAN when operating locally. The Cardax FT Multi-Server framework implements strong, open encryption algorithms, secure authentication techniques and long key lengths, such as RSA 2048 bit keys and AES 256 bit symmetric encryption. Cross-site Operational Cover Cardax FT remains fully operational in the event of network failure as Multi-Server functionality provides a high degree of redundancy. A suitably privileged Operator can view certain information from the Remote Server, and override items as if they were connected directly to the Remote Server. This allows organisations to provide cross-site operational cover to their sites worldwide. Global Access - Cardholders Cardholders can use their same cards/fingerprints/pins across all sites within a Multi-Server network (e.g. a manager with appropriate access rights can travel between sites controlled by separate Cardax FT Servers, using the one card for entry). Evacuation Reporting In the event of a disaster at one Server s site, Aggregation Server(s) can provide Evacuation Reports detailing the last known locations of Cardholders at the disaster affected site. Any server can keep an up-to-date status on the location of all Cardholders over a Multi-Server network. Disaster Recovery The Cardax FT Multi-Server feature can be used in conjunction with third party hot standby server options, to provide a comprehensive disaster recovery solution. Where a disaster event causes a Cardax FT Server to swap to its hot standby server, other Cardax FT Servers on the Multi-Server network are able to communicate directly with the hot standby server. This allows Operators at the other Cardax FT Servers to quickly gauge the severity of the disaster event on the affected site s physical security, and to temporarily provide operational cover (e.g. alarms monitoring and management, monitoring and overrides of site items and equipment etc.) for the disaster affected site. 10

15 UNINTERRUPTED OPERATIONAL CONTINUITY ACROss THE ENTIRE ORGANISATION WHEREVER IN THE WORLD THAT MAY BE. Cardax FT Multi-sERVER 11

16 IT SECURITY: HIGH DATA ENCRYPTION Data security achieved through encryption is critical in maintaining security integrity for your organisation. Leveraging your organisation s IT infrastructure to communicate with the remote security devices makes it practical to have integrated security right across your operation. Cardax FT has the ability to handle extensive processing to encrypt data to a very high standard. The default level of encryption for Cardax FT network communications is 128-bit AES symmetric encryption, with recently released equipment communicating at 256-bit. Cardax FT has options for encrypting communications from Controllers to peripheral equipment, achieving end-to-end data security and preventing system data transmission from being intercepted. IT COMPATIBLITY A core question to consider in the implementation of any system is How will it integrate with our existing company infrastructure? Cardax FT is designed to be compatible with IT systems. Cardax FT resides on your existing network, and follows industry standard rules for network connectivity. It uses minimal bandwidth, and will not interrupt normal IT communications. The processing power of Cardax FT is distributed throughout the system s components. Peer-to-peer communications between the field Controllers on the network ensure that valid and instantaneous access decisions are made even if communication links or the central Server fail. Cardholders will never know there is a network problem, because the Cardax FT Controllers will still be operational. In large distributed systems, peer-to-peer communications are essential for ensuring reliability for operations such as emergency evacuation, duress and panic alarms. Minimising network delays for critical communications is required for immediate capture of video data in response to a security related event.cardax FT also protects and monitors the IT infrastructure in other ways. With environment sensors, if the temperature or humidity in the server room gets above a certain level, Cardax FT can send a signal to your IT manager to assess the situation. 12

17 MAINTAINING YOUR CARDAX FT SOFTWARE A Software Licence and Maintenance Agreement (SLMA) will help your system keep pace with Microsoft upgrades and regular Cardax FT releases designed to enhance system performance and functionality. There may even be the opportunity to install new Cardax FT features onto your system. We recommend that an SLMA becomes the cornerstone of a total site security support plan. There may be up to four software releases a year depending up updates, but we commit to providing at least one release per calendar year. You appoint your Cardax FT Channel Partner to receive the software releases for you and provide the services for the implementation and ongoing support for your SLMA. POWER UP YOUR SECURITY SOLUTION WITH PROFEssIONAL SERVICES Gallagher provides a range of Professional Services and welcomes the opportunity to work with you and your Certified Channel Partner to add value to the implementation of our solutions. We know our systems inside out and based on our broad experience and through a sound understanding of your requirements we can deliver creative and imaginative solutions. Examples of services Gallagher can provide include: Project management - typically for large, global customers Strategic planning and migration paths planning for future requirements Requirements analysis and customisations changes required to Gallagher developed software to meet the customer s requirements Integration development of middleware to provide integration between two or more systems Database conversion and preparation Configuration and advanced system programming System audit Preparation and implementation of software upgrades Identifying potential efficiency gains in the use of your security management system. When you purchase a Cardax FT system you are recommended to invest in a Software Licence Maintenance Agreement (SLMA). The SLMA program provides a cost effective means of obtaining future upgrades. 13

18 WHY GALLAGHER? Worldwide, Gallagher Security Management Systems has a reputation for supplying state-of-the-art, reliable solutions to address the most significant issues facing organisations large and small: Security and risk management Personnel workflow Business continuity. GSMS is a division of Gallagher Group, a privately owned New Zealand based company. We design, manufacture and market Cardax FT and PowerFence security systems. Established in 1938, Gallagher Group is a global business with offices and distributors located in over 130 countries. Drawing on our competencies of security knowledge and expertise, secure data management and systems integration, our offering is expanding. We are moving towards a suite of systems that can be fully integrated and securely managed through allocated privileges to authorised users. We pride ourselves in our agility and dedication to delivering innovative and imaginative security solutions, based on real world thinking. Our goal is to deliver outstanding quality and deliver on customer expectations. 14

19 15

20 Gallagher Security Management Systems Kahikatea Drive, Hamilton 3206 Private Bag 3026, Hamilton 3240 New Zealand Phone: Fax: Offices and Representatives are located in: Asia Middle East Australia New Zealand Canada South Africa Central America South America China United Kingdom Europe United States of America Disclaimer In accordance with the Gallagher Group policy of continuing development, design and specifications are subject to change without notice. Gallagher Security Management Systems is a division of Gallagher Group Limited, an ISO 9001:2000 Certified Supplier. Cardax and PowerFence are registered trademarks of Gallagher Group Limited. All other product, brand or trade names are property of their respective trade mark owners. Copyright Gallagher Group Limited All rights reserved. 3E /10