effective prep for active shooter scenarios
know how to recognize mental health issues
municipal group shares best practices
Page 5
Page 8
Page 18
Canadian
January/February 2016
The publication for professional security management
Can you trust
the cloud? Prepare yourself for a mixed report when it comes to data safety PM# 40065710
CS Jan 2016.indd 1
www.canadiansecuritymag.com
2016-01-27 2:42 PM
we stop what can happen •
Security Guards
At Commissionaires, security is more than guarding.
•
Mobile Patrol
•
Non-core Police Services
•
Process Serving
•
Parking and Bylaw Enforcement
From risk assessment to non-core policing, Commissionaires offers a comprehensive range of security services. We are 20,000 strong with a high proportion of ex-military and RCMP in our ranks. The competition can’t match our training, discipline, sense of duty and front-line experience.
CS_JanFeb_Commissionaires.indd CS Jan 2016.indd 2 Ad: Security - We Stop
1
WhEN SEcurit y iS a Priorit y ca ll c o M M i S S i o N a i r E S | 877 322 6777 commissionaires.ca/cdnsecurity
Publication: Canadian Security
2016-01-20 2:42 2016-01-27 1:34 PM PM
20 1:34 PM
CONTENTS 3
Canadian The publication for professional security management
Columns
Volume 38 Number 1
Get your head in the cloud
8 focus on health Care Valuing mental health
The sky’s the limit, but understand the technology, and more importantly, your data security requirements first
10 risk perspective Treat the worst first
By Linda Johnson
12 safe data Clarity in the Cloud
15
13 THE big picture Increasing resilience 14 municipal matters The facts of city life
Council is in session A group of municipal security leaders are sharing their victories (and defeats) to improve success rates across the board
Departments 4 editor’s notebook The data game
By Neil Sutton
5 trending 9 ASIS update Toronto goals for 2016
18
21 book review Writing the wrongs 22 product focus Access Control
visit www.CanadianSecuritymag.com Security leaders will be dropping by our studio in 2016, so be sure to check out the video section of our website for new content.
Security Pages
Canada’s Only Security Industry Buyers Guide
Go Shopping at
SecurityPages.ca
canada’s Only Security industry Buyers guide
Security
Pages 2016
Brought to you by
Canadian The publicaTion for professional
securiTy managemenT
www.SecuritypageS .ca Security_pages 2016.indd
1 2015-11-16 10:31 AM
@SecurityEd • January/February 2016
CS Jan 2016.indd 3
2016-01-27 2:42 PM
Canadian
4 editor’s notebook By Neil Sutton
The publication for professional security management
The data game The Cloud’s payoffs are big, but learn the rules first
W
hen you start to think about concepts like the Cloud, it can be a bit of a mental puzzle. The nomenclature suggests something distant, almost ethereal. Clouds are remote, intangible — fairy tale stuff. “The Cloud” as a concept isn’t all that different, in some ways. It offers freedom from infrastructure and freedom of access. It allows data to be more useful because it’s that much more fluid. It creates possibilities. But there has to be acceptance that there are consequences to allowing data to exist in such a realm. There must be safeguards and restrictions, because data has value. It is “There is no such about something, and quite often about someone. It represents a person’s income, or their health thing as a 100 per cent status or their personal communications. It has value in the aggregate, but more importantly, guarantee.” value to the stakeholder who has entrusted it to a service provider, whether it’s their bank, insurance company, government, email host or any number of agencies. I think sometimes this notion can get lost in big picture discussions of the Cloud, which is partly why I wanted to have one of those discussions in the pages of this magazine. Our front cover asks a bold question: Can you trust the Cloud? This is more than just an attention grabber (thought hopefully it works on that level too). The answer is complex, since there are so many variables to take into consideration. What are you storing, where are you storing it, who are you partnering with, what have you communicated to your stakeholders? What are the consequences if that data is compromised, however unlikely that may be? Because as all security professionals know, there can be endless and conscientious preparation, but there is no such thing as a 100 per cent guarantee. As we continue to move through the era of physical and logical data becoming more relatable and in some ways more interdependent, a working knowledge of the Cloud becomes increasingly valuable. And it cuts both ways. IT systems do not exist in a vacuum. Whether data is stored on premises or in the Cloud (and whatever it is, the Cloud is not a vacuum), it must be surrounded by physical precautions, including access control and permission policies. We’ve all heard stories about data being compromised by a determined social engineer with a USB key. All it takes is the wrong person to tailgate into an office or slip past the front desk, or sweet talk his or her way into an enterprise with a convincing or seemingly benign story. I don’t think there can be enough reminders out there that information, stored in the Cloud or otherwise, is about people. Even if it’s stripped of its personal signifiers, its value is no less, and it should be accorded a measure of respect. The Cloud represents a tremendous asset and I firmly believe it’s the future of our data. We owe it to ourselves to keep our minds open to the possibilities and the precautions in equal measure.
Group Publisher Paul Grossinger pgrossinger@annexweb.com
Art Director Graham Jeffrey gjeffrey@annexweb.com
Publisher Peter Young pyoung@annexweb.com
Account Coordinator Trish Ramsay tramsay@annexweb.com
Editor Neil Sutton nsutton@annexweb.com
Director of Soul/COO Sue Fredericks
Online Editor Cindy Macdonald cmacdonald@annexweb.com
Editorial and Sales Office 222 Edward Street, Aurora, Ontario L4G 1W6 (905) 727-0077 • Fax (905) 727-0017 Web Site: www.canadiansecuritymag.com Canadian Security is the key publication for professional security management in Canada, providing balanced editorial on issues relevant to end users across all industry sectors. Editorial content may, at times, be viewed as controversial but at all times serves to inform and educate readers on topics relevant to their individual and collective growth and interests. Canadian Security is published six times per year by Annex Business Media. Publication Mail Agreement #40065710 Printed in Canada I.S.S.N. 0709-3403 Subscription Rates Canada: 1 Year $40.95 + HST; U.S.A. (payable in US dollars): 1 Year $70.00; International (payable in US dollars): 1 Year $80.00 Circulation Tel: (416) 510-5189 Fax: (416) 510-5170 asingh@annexbizmedia.com 80 Valleybrook Drive, Toronto, ON M3B 2S9 The contents of Canadian Security are copyright by ©2016 Annex Publishing & Printing Inc. and may not be reproduced in whole or part without written consent. Annex Business Media disclaims any warranty as to the accuracy, completeness or currency of the contents of this publication and disclaims all liability in respect of the results of any action taken or not taken in reliance upon information in this publication.
Editorial Advisory Board Jason Caissie Profile Group
Tracy Ann Kosa Microsoft
Carol Osler TD Bank
Ken Close Trillium Health Partners
Bill McQuade Final Image
Theresa Rowsell Kit and Ace
Ashley Cooper Paladin Security
Clark Northcott
Tim Saunders G4S
David Hyde Hyde & Assoc.
Malcolm Smeaton Whitehorse Group
@SecurityEd January/February 2016 • www.canadiansecuritymag.com
CS Jan 2016.indd 4
2016-01-27 2:42 PM
m
m
trending 5 Calendar Next Generation Security Leader February 29 - March 1, 2016 Atlanta, Ga. www.securityexecutivecouncil.com/ atlanta2016 Security Career Expo March 9, 2016 Toronto, Ont. www.securitycareerexpo.ca Focus On Cyber Security March 30, 2016 Toronto, Ont. www.focusonseries.ca ISC West April 6-8, 2016 Las Vegas, Nev. www.iscwest.com Border Security Expo April 13-14, 2016 San Antonio, Tex. www.bordersecurityexpo.com Security Canada East April 20, 2016 Laval, Que. www.securitycanadaexpo.com Canadian Technical Security Conference April 26-28, 2016 Cornwall, Ont. www.ctsc-canada.com Security Canada Alberta May 11, 2016 Edmonton, Alta. www.securitycanadaexpo.com IAHSS Annual Conference & Exhibition May 22-25, 2016 Charlotte, NC www.iahss.org Security Canada Ottawa June 1, 2016 Ottawa, Ont. www.securitycanadaexpo.com Focus On Drones June 7, 2016 Toronto, Ont. www.focusonseries.ca Security Canada West June 15, 2016 Richmond, B.C. www.securitycanadaexpo.com
ASIS and NFPA address active shooter dilemma
T
he National Fire Protection Association (NFPA) and ASIS International have come together to update best practices on how to prepare for and deal with the outcomes of active shooter events. The partnership began in earnest on Jan. 19 in Arlington, Va., where the groups jointly held a stakeholders’ meeting, inviting interested parties to attend and discuss issues around the active shooter phenomenon. At press time, those expected to attend included law enforcement, academics, standards developers and other industry groups. According to the organizers, one of the main focal points of the day is to address the shear number of approaches to dealing with the terrible outcomes that are part of active shooter events — some of which may be in direct conflict with one another. About a year ago, the NFPA hosted a two-day workshop at the University of Maryland where a discussion topic was the degree to which fire codes and security best practices are not synchronized, particularly in school environments. School boards may decide, for example, that locking doors in the event of a potential security situation would be an appropriate response, but there may be unseen ramifications to such Robert Solomon, NFPA decisions. “They’re all well meaning and well intentioned but they inadvertently start violating building codes, fire codes and life safety code provisions,” explains Robert Solomon, division manager, Building Fire Protection, NFPA, who spoke to Canadian Security prior to the event. “All of a sudden, these things that seem really disconnected, from fire codes and life safety codes are kind of in the forefront.
What we wanted to do was start this dialogue last year with security people and first responders and law enforcement to say, ‘OK, we’ve got to figure out how to marry these two.’ On our end, we’ve certainly concerned about fire safety but we’re obviously concerned about the everyday welfare of the students,” he says. Marc Siegel, ASIS “It puts schools and hospitals and other organizations in a bit of a quandary,” adds Dr. Marc H. Siegel, commissioner, ASIS Global Standards Initiative. There is a plethora of advice, best practices, papers and reports already out there to help guide not only school administrators but multiple businesses and institutions on how to best deal with potential active shooter events. The unfortunate consequence of this, notes Siegel, is it may result in confusion on the part of the decision-makers. “A school principal can’t wade through a 300-page document then figure out what they’re supposed to do,” he says. The aim of the January 19 event is to stave off this potential confusion and ensure stakeholders are moving towards a common purpose, says Siegel. The outcome of the meeting should be to provide effective guidance on how to minimize, recognize the likelihood of, prepare for, and deal with the aftermath of an active shooter event. Siegel notes that standards and recommendations that arise from the meeting will be as broadly applicable as possible, i.e., not just targeted towards U.S. stakeholders. He suggests that interested parties can find out more about the best practices that arise from the meeting by contacting ASIS International at standards@asisonline.org. — Neil Sutton @SecurityEd • January/February 2016
CS Jan 2016.indd 5
2016-01-27 2:42 PM
PALADIN RECOGNIZES ITS EXTRAORDINARY PEOPLE PAMELA SHARIF | Healthcare Security Officer
Extraordinary Moment
What Our Client Said
A
“Pamela’s poised response to our patient exemplified our commitment to patient care; ensuring our patient was taken care of while awaiting clinical support. Pam is a true ambassador of our Integrated Protection Services program. Well done Pam, and congratulations on your award.”
n unexpected delivery outside the Lions Gate Hospital (LGH) in Vancouver, BC earned Paladin Security Officer, Pamela Sharif the 2015 ASIS Pacific Chapter Security Officer of the Year award. Pamela assisted an expectant mother who arrived outside the hospital in active labour. As clinicians rushed to the scene, Pamela realized there wasn’t enough time. She quickly attended to the patient and almost instantaneously, held a baby boy in her arms. Amazingly, as the clinical staff took over the scene, Pamela rushed off to another call to help the security team manage a “code white” — aggressive incident! When asked about the event, Pamela stated; “It’s all in a day’s work at my hospital! I love my job and being able to support the patients and staff.”
Jeff Young, CPP, CHPA Executive Director Lower Mainland Integrated Protection Services Pamela’s impact on the industry reaches far beyond one incident. She’s been a core member of the security team at LGH for over a decade. She has mentored many officers over the years and is held in high regard by her co-workers and hospital staff alike. Pamela Sharif represents the talent and dedication of Paladin Security Officers nationwide.
Paladin is Canada’s undisputed leading provider of healthcare security services, serving more than 230 healthcare facilities from coast to coast. It is crucial that quality services are designed specifically to support the safe delivery of care in a secure, accessible environment. The healthcare environment is a unique setting committed to the delivery of quality care to patients. Pamela’s work that day is a tremendous example of how a patient-centric approach to security contributes to quality care.
Read More: paladinsecurity.com/extraordinary
In photo (left to right): Jeff Young, Executive Director Lower Mainland Integrated Protection Services; Pamela Sharif, Paladin Security Officer; Jonathan Acorn, Director of Operations, Lower Mainland Integrated Protection Services.
Extraordinary People, Extraordinary Service. Since 1976. • SECURITY OFFICERS • MOBILE PATROLS & EMERGENCY RESPONSE • OPERATIONS CENTRES
CS Jan 2016.indd 6 1 CS_Feb_Paladin.indd
• ALARM, FIRE & VIDEO MONITORING • ACCESS CONTROL SYSTEMS
• INVESTIGATIONS • SECURITY AUDITS & CONSULTATIONS • MANAGED SERVICES
• EMERGENCY MANAGEMENT & BUSINESS CONTINUITY PLANNING • CAMERAS & VIDEO MANAGEMENT SYSTEMS
2016-01-27 2:42 PM
rs ers nt
Extraordinary happens everyday. PALADINSECURITY.COM
“The woman was outside the hospital in active labour and, as clinicians rushed to the scene, I almost instantaneously, held a baby boy in my arms...” PAMELA SHARIF ASIS Pacific Chapter Security Officer of the Year
EXTRAORDINARY MOMENT Delivering a baby
#extraordinary
S
CS Jan 2016.indd 7
2016-01-27 2016-01-22 2:42 3:26PM PM
8 focus on health care By Uppala Chandrasekera
Valuing mental health
S Security providers face unique challenges and need supportive workplaces
ecurity providers face a number of A recent survey of the well-being of Canadian unique stressors in their workplaces that police officers found that 50 per cent reported make it that much more important to their perceived level of stress as being high, prioritize mental health well-being. with 30 per cent reporting a depressed mood. While any negative or unpleasant event A survey of staff at Correctional Service can be stressful, exposure to crime, violence Canada found that 30 per cent of correctional and other dangerous officers had been diagnosed situations common in with depression, and that the security field can be the incidence of depression “There is a lack of particularly stressful and among staff increased the information that seriously impact one’s longer they were employed mental health. in corrections. A study captures the real extent Exposure to these of American corrections situations can be traumatic found that of these experiences and professionals — they can be frightening, a third self-identified as overwhelming or cause having moderate to severe their effects.” a significant amount of depression, with 34 per cent distress. Everyone can experiencing PTSD. experience these types of Given the challenges situations and people can that security providers face react differently to them: they might feel it’s important that employees, employers, nervous, have trouble sleeping or revisit them managers and supervisors work together to in their mind. Such reactions are normal better support their mental health. There and tend to decrease over time, allowing are a number of resources available in the people to get back to their daily lives. When community to help. For example, Mental these reactions are more intense, last for Health Works, a social enterprise of the an extended period of time and severely Canadian Mental Health Association, disrupt one’s life and mental health, then provides capacity-building workshops for Post-Traumatic Stress Disorder or PTSD workplaces on mental health. But the first may be present. When these reactions are a steps to fostering better workplace mental result of experiences in the workplace, PTSD health involve employers and staff members can be classified as a type of Occupational coming together to create a space that Stress Injury or OSI. An OSI is any persistent supports health and safety, allows people to psychological difficulty that results from feel heard and respected and engages people operational duties such as law enforcement, in positive, lasting solutions. Mental health combat or any other service-related duties. affects us all — workplaces that recognize While we know that security providers and support this make better environments are often exposed to potentially traumatic for employees and the people they serve. situations, there is a lack of information that captures the real Uppala Chandrasekera is the Director, Public Policy at extent of these the Canadian Mental Health Association Ontario (www. experiences and ontario.cmha.ca). Chandrasekera spoke about mental their effects on health in the work place at Focus On Health Care Security the mental health in December 2015. 1. Duxbury, L. & Higgins, C. (2012) Caring for and about those of people working who serve: Work-life conflict and employees well being within in the sector. We can Canada’s Police Departments. 2. Union of Canadian Correctional Officers. (2003) Correctional however gain some insights Officers of CSC and their working conditions: by looking at information about a questionnaire-based study. 3. Denhof, M & Spinaris, C. (2013) Depression, PTSD, and professionals working in similar sectors such Comorbidity in United States Corrections Professionals: as law enforcement and corrections officers. Prevalence and Impact on Health and Function. 1
2
3
January/February 2016 • www.canadiansecuritymag.com
CS Jan 2016.indd 8
2016-01-27 2:42 PM
By Jason Caissie
asis update 9
Toronto goals for 2016
T
website to make multiple upcoming he ASIS Toronto Chapter starts events easier to find. the year in great shape thanks to • Increase the number of chapter the efforts of the outgoing executive volunteers to ensure the committee, led by Mike Soberal. workload is balanced and fair. Starting in 2016, a new • Host at least eight educational executive committee is taking sessions providing opportunities over, consisting of myself for CPEs for members. as Chairperson, Michael • Proactively issue proof of Brzozowski as Vice Chairperson, attendance at chapter events to Vivian Chiu as Treasurer and all certified members for their Joey Bourgoin as Secretary. Our own CPE records. goals for 2016 include: Jason Caissie • Continue to promote • Increase member awareness standalone events for the Women of events. We will do this by: Setting in Security and Young Professionals a complete 2016 schedule of dates committees, with an emphasis on before Christmas 2015; changing networking opportunities. chapter e-mail communication tactics; As you read this, we’ll be celebrating continuing to move events around the success of our first event of the year the GTA, at varying times of day, and on Jan. 21, featuring Joe Roberts from the with varying topics; and refreshing the
Push for Change (www.thepushforchange. com). Joe shared his inspirational firsthand experience as a homeless person and his road to recovery, along with some discussion about how we in the security industry can respond to homelessness in Toronto. We’re pleased to have the Push for Change as our 2016 charity partner, with a goal to donate at least $7,500 before the end of the year. Upcoming events include our Colleges Event in February, an evening chapter meeting in March and our 23rd Annual Best Practices Seminar & Exhibits on April 21. More event details, as well as registration for each event, can be found at www.asistoronto.org. Jason Caissie is the Chair of ASIS International Toronto Chapter 193.
Our focus is to make darkness totally visible
Maximize performance in low light Wouldn’t it be helpful if you could rely on clear and relevant images regardless of the lighting conditions? With the DINION IP starlight 8000 MP camera, Bosch offers a new quality standard in round-the-clock video surveillance. Regardless of lighting conditions, time-of-day or object movement, the camera delivers relevant IP video 24/7. With its impressive technical specifications, this is the ultimate 24/7 camera. Learn more at www.boschsecurity.com/hdsecurity
@SecurityEd • January/February 2016 CS_Feb_Bosch.indd 1
CS Jan 2016.indd 9
2016-01-19 1:31 PM
2016-01-27 2:42 PM
10 RISK Perspective
By Tim McCreight
Treat the worst first
T
A triage approach to security problems can help you make the best use of your resources
here are a plethora of articles written previous positions, we developed a repeatable about the risks we’ll face in 2016. triage process for risk assessments, focusing The potential for political change on those initiatives that appeared to pose the after the U.S. presidential election is real, as greatest risk to the organization. We targeted are the possible consequences of lower oil the majority of our efforts on larger or more prices and a Chinese economy struggling risky initiatives, and less time assessing to maintain its growth. Physical attacks we smaller or less risky engagements. witnessed in 2015 were horrific, and cyber To do this, we incorporated the “two breaches continued to man rule” for the triage shake our confidence process. When a request in companies that were came into the team for “I haven’t heard a supposed to keep our assistance, at least two team personal information members would review security director yet tell secure. the initial request and try me they have more than to quickly determine if the Security professionals need to adapt to these risks posed by the project enough staff.” ever-changing risks with (in were potentially low or many cases) smaller budgets high to our environment. and headcounts than in This approach wasn’t previous years. I haven’t perfect, and it took a bit heard a security director yet tell me they have of healthy debate to work through that first more than enough staff to deal with their meeting. The end result was a documented projects, initiatives, and day-to-day concerns. process we could adapt for most situations, As well, the shortage of new entrants into the and allowed us to be more nimble in our cyber security profession continues to impact response to the requests that kept coming companies across the globe. from the organization. Some assessments With all the change, how can we were completed quickly, and offered the continue to efficiently identify risks to project team remediation suggestions in a our organizations? How can we assess day. Other assessments took more time and those risks that are most impactful to our resources, but the triage process created companies, and work on recommendations the flexibility to spend more time on larger to remediate or at least lower the affect a projects because the smaller or less risky risk may have on our organization? With the engagements were identified and assessed limitations we’re facing in 2016, are there sooner in our review process. opportunities for us to change? Developing a nimble response to client One approach I’ve previously taken is requests will serve your security team well. developing a risk triage process. It’s similar If the predictions for 2016 are accurate, to the approach physicians take with patients we must react quickly to threats facing our entering an emergency room. I borrowed the organizations. The threat landscape in 2016 practice from a good friend of mine who was appears more dynamic than 2015 with becoming a doctor, and spent long hours at a significant changes predicted for the global busy Toronto ER. The goal of a medical triage economy, increased violence from terrorist process is to assess patients based on the organizations, and new cyber threats targeting urgency of care, and treat those whose need both private and public sector information is most urgent first. If a patient enters the ER networks. A risk triage process may help you with a heart attack, they’ll receive treatment become that reliable business partner in what faster than a patient who is concerned they is shaping up to be a challenging year. may have a cold. We can borrow this approach for Tim McCreight is director, enterprise information security assessing risks facing our organization. In at Suncor (www.suncor.com).
January/February 2016 • www.canadiansecuritymag.com
CS Jan 2016.indd 10
2016-01-27 2:42 PM
CS_JanF
Today’s G4S. More ways than ever to protect you. G4S Secure Integration brings your systems together. We design, install and maintain stand-alone and integrated security systems and technologies. A trusted partner to customers and suppliers, G4S Secure Integration takes great pride in delivering outstanding expertise and superior service. Our knowledge of a wide range of technologies, products and systems provide cost-effective, reliable and scalable solutions.
Secure Integration
Corporate Risk Services
Security Personnel
To learn more about G4S, contact us today: www.g4s.ca • 1-888-717-4447 • solutions@ca.g4s.com
CS_JanFeb_G4S.indd CS Jan 2016.indd 11 1
2016-01-19 AM 2016-01-27 11:31 2:42 PM
12 SAFE DATA
By Cory Freed
Clarity in the Cloud
C Ownership of your information should be a paramount concern
loud technology has made possible opportunities that can be truly transformative for businesses. The adoption of Cloud services worldwide has continued to accelerate at an incredible pace, for many reasons. For almost all industries, the Cloud changes how people work, where people work, and the ways people do business. However, like any tool, technology can be abused and when that happens, trust is undermined. In June 2013, Edward Snowden, a then 29-year-old contractor hired out to the U.S. National Security Agency (“NSA”), revealed to the world that it’s not always clear what governments are doing with our personal information. Snowden’s disclosures around a U.S. government surveillance program called “PRISM” undermined the public’s trust in technology and called into question the role that technology companies may have played in facilitating the bulk collection of data — outside of established legal process –— to support the NSA’s widespread surveillance program. It is not uncommon for Canadian enterprises considering a move to the Cloud to cite PRISM, or the USA PATRIOT Act (the “Patriot Act”), as an obstacle. Many of these concerns stem from media reports that these programs broaden and expand the U.S. government’s ability to access data held by U.S.-based Cloud service providers (“CSPs”). Regardless of the accuracy of these reports, customers justifiably want clear commitments from their Cloud service provider on how their data will be handled. CSPs who wish to be successful must recognize the concerns their customers have around government access to data and must share the responsibility for protecting their customers’ data. Customers need clarity around where data is stored and what happens when a local or foreign government requests access to that data. Customers should look for a CSP that takes this issue seriously, is transparent, and shares its customers’ concerns around government access.
When evaluating CSPs, ask yourself the following questions when it comes to the issue of foreign government demands: • Will the CSP redirect orders seeking customer information to the customer? • Will the CSP commit to not granting direct or unfettered access to customer data and does it commit to only releasing specific data mandated by a valid legal demand? • When law enforcement agencies or governments from any jurisdiction request that the CSP provide customer data, will the CSP insist that they do so in accordance with the applicable legal process? Usually that means serving some form of court order on the CSP. • Will the CSP invest in legal resources to ensure that legal process has been followed? In those very rare instances where a CSP must comply with an order to produce enterprise customer data, it is critical that the CSP does so only in accordance with the request and promptly notifies the customer, unless legally prohibited from doing so. Every enterprise customer of Cloud services should be looking for this contractual commitment. Snowden’s disclosures shed light on one of the most controversial provisions of the Patriot Act concerning the “bulk collection” of communications originating, terminating or transiting the United States. The bulk collection provisions have since been removed by the passing of the USA Freedom Act of 2015. Once in effect, orders for disclosure of data must be targeted to individuals suspected of involvement in or the planning of an offence. Bulk collection will soon no longer be permitted, so any request made by the U.S. government would amount to data about an individual or group of individuals, not an entire population. Nevertheless, you have a right to know how your data will be handled. At the end of the day, you own your data, not the CSP, and you should retain control of it. Cory Freed is senior corporate counsel with Microsoft Canada (www.microsoft.ca).
January/February 2016 • www.canadiansecuritymag.com
CS Jan 2016.indd 12
2016-01-27 2:42 PM
By Yves Duguay
big picture 13
Increasing resilience
A
As terror incidents multiply, security planners should act accordingly
s we look back on 2015 and reflect to share and communicate information, to on recent media headlines, we can optimize our response and the allocation of appreciate the level of uncertainty limited resources. that is affecting our society, along with the So to become more resilient, we unpredictability of the threats we are facing, must become more collaborative. This from weather hazards to terrorist attacks. can be accomplished partly by providing Terrorist organizations are determined stakeholders with a common communication to exploit our weaknesses, either physically and information sharing platform. Ideally or virtually, to create this platform must also chaos and terror, which facilitate the monitoring of are usually accompanied our actions by the leaders “How far do we by a significant impact on of the various organizations our national economies. involved in the emergency, want to go and how This is their raison d’être, contingency or business and in order to remain continuity plan. So it’s much do we want to relevant and to attract all about accurate and spend?” more followers, they will secure information being continue their attacks. communicated and shared in This in turn real time, between everyone has resulted in an involved at different levels in asymmetrical conflict: simple and minimal our governance model. resources on the part of the terrorists are As these unforeseen events increase in inflicting major damages, whereas the means numbers and frequency, our performance to prevent and protect against those attacks will be assessed by the effectiveness and the are both complex and costly. So the question efficiency of our response, how rapidly we is, how far do we want to go and how much engage our plans, how we dispatch resources do we want to spend to reduce the risk of and how we resume operations, once the such attacks? threat has been eliminated. To become more During the recent turmoil of events in resilient, we must also learn from these events, Europe, the United States and Africa, some what we did well, where we could do better, of our leaders were courageous enough to what we would do in the future and how we explain that even with the best of security will train and test ourselves, to ascertain and plans, there is no such thing as 100 per cent validate our new capacity. security or 100 per cent protection. Even with Thankfully, a number of companies the increased level of security since 2001, have recently developed innovative tools terrorists are still able to penetrate our layers that enable professional security and safety of physical and IT security. specialists to manage a crisis. I, for one, believe that it’s in our capacity Having plans and strategies in place to show our determination to respond to along with the means to communicate with terrorist attacks, by effectively and efficiently response teams is certainly a very important utilising the resources at our disposal. As part part of increasing an organization’s resilience. of this response, we have to become more These plans can become even more effective, resilient, to limit and restrain the impact of when allowed to cross organizational those hazards, and to resume our activities, as barriers, to integrate everyone’s contribution quickly as possible. to the resolution of a crisis, with accurate real The strength of our response to time information and monitoring capacity. weather hazards, terrorist attacks and other unforeseen events lie in our ability to Yves Duguay, EMBA, CSSP, is the President of HCiWorld collaborate across boundaries, agencies and (www.hciworld.ca) and strategic advisor to Cobalt companies. We must find innovative ways (www.e-cobalt.com). @SecurityEd • January/February 2016
CS Jan 2016.indd 13
2016-01-27 2:43 PM
14 MUNICIPAL MATTERS By Mel Gedruj
The facts of city life
A Expect municipal security to continue to evolve as our understanding improves
s the level of government closest models that would enable the governance to citizens, the municipal sector is level, in municipalities that is Council unique. (Board of directors in corporations) and the In fact in ancient times people lived in senior management level to decide on the city states and aside from Sparta, Greek city level of risk to mitigate and what residual states, for instance, had no standing army. risk to “own.” At times, the lack of clarity In other words, citizens were taking care in this area may have given the impression of their own security. that as long as the risks are not uncovered Nowadays, Canadians there is little consequence, cities offer a myriad of but this approach, if ever services that are very contemplated, does not take “There are no different from one into account all the fiduciary another. Water supply, aspects, whether explicit all-encompassing wastewater and waste or not and the presence of collection, public transit, critical infrastructure in standards for municipal libraries, recreation, municipal portfolios. security.” public health and police/ Let’s start with two emergency are some of the conceptual models that well-known services. In would place security in single-tier municipalities, relation with emergency and all services will be supplied from the one business continuity. level government, while two-tier regional First, if we accept that all these functions municipalities have their services divided flow from one to the other, in the following between the two levels. Customarily, water sequence — prevention, preparedness, and police would be from the upper tier while response, recovery and continuity of transit can be provided by either tier. operations — then we could call it a Security management is one of the most continuum. challenging aspects for the municipal sector. Secondly, the Bow-Tie risk model The number of different “businesses” making developed in the ’70s by the Royal Dutch up the services listed above have different Shell Corporation places the event as risk profiles and security needs. In an open the defining line between prevention, democratic environment, security has to be preparedness response, recovery and deployed in a manner that would not abuse continuity. It allows us to assign a prevention or restrict individual rights such as privacy. and mitigation leadership role to security Adding to that the fact that there are no prior to an undesirable event and a support all-encompassing standards for municipal role afterwards. Therefore, it would be security, the result is a sector faced with a advisable to have these three functions in dilemma. How and what can we develop the same municipal division along with risk in terms of security management planning management. The reasoning behind this is to and execution that would be repeatable, can achieve team cohesion and interoperability. be taught, learned from, and shared while Considering that federally, an all hazard serving the specific needs of municipalities? approach is recommended, the combining of This series of articles aims to provide all these areas dealing with risk, would lead a reasoned process and assist municipal to an integrated management process, when practitioners and decision makers in tackling faced either by a natural disaster or a security security matters like any other management event. area. In other words, strategic considerations should govern in establishing a framework Mel Gedruj, OAA, CSPM is an Ontario Licensed Architect from which tactical and operational solutions and Certified Security project manager specializing in can be planned. To make it tangible, we need municipal security management planning.
January/February 2016 • www.canadiansecuritymag.com
CS Jan 2016.indd 14
2016-01-27 2:43 PM
technology & policy 15
Get your head in the
cloud The sky’s the limit, but understand the technology, and more importantly, your data security requirements first By Linda Johnson
C
loud computing may be too new a technology to know yet how secure it is compared with traditional systems. But a few recent, well publicized attacks involving celebrities have highlighted the risks of Cloud storage. In addition to data breaches caused by hacking, information security officers have many risks to consider, including issues raised by trans-border data flow. For some, the business advantages clearly outweigh the security concerns. For others, a bit more wary, the choice is more difficult. “I believe companies have to invest in the Cloud,” says Suzie Smibert, director, information systems security and CISO, at Vancouver-based Finning International, a distributor of Caterpillar equipment that employs more than 14,000 people globally. “This is our direction.” For businesses that are local and have a limited geographical footprint, she says, it may make sense to have gear on premises: they don’t need to consider purchasing equipment
in various countries. For multinational organizations, however, such as Finning, going Cloud-based offers significant advantages. “It’s reducing the headache of having, for example, to ship gear to South America. Embracing Cloud allows us to be innovating and service our customers much faster because we don’t have to deal with the commodity of maintaining servers and hardware in the various data centres. It becomes costly if you have multiple locations and you need to put things on premises,” she says. Gordie Mah, CISO at the University of Alberta in Edmonton, says, while the Cloud presents security risks, he believes it does provide definite business benefits. In addition to lowering costs, the technology offers ease of management, administration, initiation and deployment. “For the university, for example, there are very reliable, stable and effective solutions that are essentially turn-key in the Cloud. And it precludes the need to attain that expertise in house and to have to expend resources to develop that @SecurityEd • January/February 2016
CS Jan 2016.indd 15
2016-01-27 2:43 PM
16 technology & policy
infrastructure and maintain, manage and upkeep it.” Owen Key, CSO and CISO for the City of Calgary, says the benefits of the Cloud depend on the organization and maturity level of the information technology platform of that organization. Small organizations will adopt Cloud technology much more easily and seamlessly than larger, already mature organizations, such as the City of Calgary. While the city has a robust IT department, there are pressures to move to Cloud solutions to take advantage of their ease of adoption and to meet business needs more quickly. “I think for larger organizations such as ours, there is a hybrid model to be had. Certainly, we have pressures from business units who want to look at Cloud solutions, and there is a push from large vendors to the City of Calgary to push our services onto the Cloud. But we have challenges in terms of personal information, intellectual property and critical systems,” he says. “So, am I anti-Cloud? No, certainly not. I am a realist and think it inevitable that we will have that large hybrid solution between on-premises and offpremises solutions.” A recent study by Microsoft reflects a reluctance of Canadian companies to move their systems to the Cloud. It found that 85 per cent of Canadian businesses have not moved “beyond very early incremental adoption” of Cloudbased technologies. The study also concluded that security concerns were a
central reason for this reluctance: 52 per cent of executives surveyed had concerns about data security in the Cloud. Reliability and security, Mah says, depend on the service provider. The larger, more experienced and well known Cloud-service providers have proven to be extremely reliable in regards to availability, failover, backup management and to resistance against cyber threats and attacks. “There’s a wide range of providers and various scales and levels. And there are more and more that are rising to the top and becoming known; it shows in their large list of customers and the growth of their organization.” Smibert agrees that reliability depends largely on the service provider the organization selects. Cloud providers can be very reliable, but organizations must do their due diligence, evaluating service reports and using SOC (Service Organization Control) report and the SSAE 16 (Statement on Standards for Attestation Engagements) to assess the provider. They should also make sure they have good contractual agreements with the provider. “Putting your data in the Cloud doesn’t eliminate your accountability in ensuring security. But you have to increase your vendor management practice and include an information security component when you select your Cloud vendor,” she says. Tom Jolly, VP, managed IT and Cloud services at Vancouver-based Telus, says Cloud technology is as, or even more, reliable than on-premises
data management. However, it’s a mistake for customers to think that, once they’ve subscribed to a Cloud service, their provider will handle all their security concerns. There are many different service models, and security responsibilities often fall to the customer. It’s essential to draw a very clear demarcation with the service provider about who’s managing what. “It’s about understanding what you’re subscribing to and making sure that potential areas of risks — like making sure your operating system is patched on a regular basis with the latest patches — is actually occurring and you’re not just thinking the service provider is doing it when in fact they think you’re doing it.” Jolly says businesses should also distinguish between their data that must remain secret and other kinds of data that could become public. For the former, it will be worth investing in the highest level of security, while the business may not want to spend a lot securing the latter type. “Make sure you understand the choice that’s in the Cloud, whether it’s private/public, whether it’s on shared infrastructure and whether, in some cases, the data may need to be on dedicated infrastructure. Understand how you and the service provider are managing the risk,” he says. Mah, who agrees with the study that Canadian companies are reluctant to invest in the Cloud, says it is largely because many of the data centres where data is hosted are located in the U.S., not in Canada. “One of the key critical showstoppers is still the legislative and compliance aspect,” he says. “The current legislative climate is still very adverse to trans-border data flow, where data in another jurisdiction may be subject to unauthorized and inappropriate disclosure and access to their government and law enforcement bodies.” Reluctance to adopt the Cloud comes more from security professionals and IT departments, Key says, than from
January/February 2016 • www.canadiansecuritymag.com
CS Jan 2016.indd 16
2016-01-27 2:43 PM
business units within organizations. For IT departments, the technology represents an erosion of their kingdoms. From a security perspective, he says, while concerns are partially mitigated by measures such as proper indemnification and insurance (which transfer risk from the organization to the service provider), other risks remain. “There is a reputational risk to mitigate if we lose data because our clients — in our case, our citizens — don’t care whether we’ve subcontracted to an outside party. It’s going to be the city that lost their data,” he says. Smibert, too, believes much of the reluctance to move to the Cloud can be attributed to IT departments. Internal business stakeholders want to procure a Cloud-service offering, and, often, they bypass IT and buy it directly. “And your business might already be in the Cloud, and you don’t “There are not too know it,” she says. many businesses out “I believe Canada is behind. The Canadian there that can operate IT are behind. We’ve been too scared of effectively having their embracing the Cloud.” There is also feardata locked in a vault.” mongering about the — Tom Jolly, Telus Patriot Act, she adds, a product in part of lack of education. IT personnel often don’t understand privacy law or are not working closely enough with their internal privacy office to understand measures they can take to protect their data, like having proper contractual agreements or leveraging data centres in different geographical locations. “If the privacy and security officers don’t work together to understand the regulatory landscape, they might be absolutely risk averse to embracing Cloud,” she says. One way for companies to safeguard against disclosure risks, and thus reduce the reluctance to move to the Cloud, Mah says, is through the encryption of data stored by the service provider. This control requires that encryption is adequate and strong and that the organization retains sole control of the decryption key. This solution, however, he adds, is often cost prohibitive and may involve too many extra steps for an organization or employees to make it practical. “It’s one thing to say on paper the solution lies in Cloud encryption and management of the decryption key. It’s another thing to find transparent solutions, to actually achieve it,” he says, adding there are today many vendors working to try to develop those solutions. “They know that it’s definitely a niche that can be profitable, and there’s certainly a need.”
INSIGHT PRESTIGE CONSOLES IMPROVE YOUR VIEW Winsted provides ergonomic console solutions for your demanding control room operations. We offer stock, customised and bespoke console options with exible monitor mounting solutions to optimise sight lines and improve viewing angles. Our experts create inspiring, feature-rich consoles that work with your operators to enhance comfort, functionality and productivity.
Download your free copy of WELS4 at: winsted.com/wels
Linda Johnson is a freelance writer based in Toronto. @SecurityEd • January/February 2016 Winsted_CS_March.indd 1
CS Jan 2016.indd 17
2015-03-18 12:07 PM
2016-01-27 2:43 PM
18 best Practices
Council is in session A group of municipal security leaders are sharing their victories (and defeats) to improve success rates across the board Municipal Security. But “the only one who calls it that is me,” says Cathie Evans, security manager at the City of Mississauga. Evans, who has worked at the city for 30 years, is the convener ecurity professionals will often acknowledge that their and organizer of the group’s annual meeting, which for the last best resources are each other. two years has been held in Mississauga. The group meets every Through sharing information and experiences, October, during the Canadian Security Association’s they can arrive at solutions faster and (CANASA) Security Canada Central, since many make decisions with some reassurance that municipal security managers are in town for that someone else in their position has already done conference anyway. this, and done it well. Less important than the name is the purpose. That, in essence, is the credo behind a group Meetings are well attended, drawing participants of municipal security managers and directors, from Ottawa and Toronto as well as nearby smaller mostly Ontario-based, who meet annually and municipalities like Waterloo, Guelph, Sudbury, communicate year-round for their mutual benefit. Niagara, and so on. Unlike other security organizations, it doesn’t The name of the game is networking, learning have a board or a charter. No one is 100 per cent and sharing failures and successes, both of which are sure when it really got started. It doesn’t even have Toronto’s Dwaine Nichol was an official name. one of the speakers at the most hugely instructive. “I think one of the super important things about a group like this, is it’s not only sharing: Nominally, for now, it’s Managers of recent municipal meeting.
By Neil Sutton
S
January/February 2016 • www.canadiansecuritymag.com
CS Jan 2016.indd 18
2016-01-27 2:43 PM
19 “As the morning progressed, we started talking about what do you have in place now, but what are you doing in the how, as public buildings and public institutions, we really are future, and what mistakes have you made? [Those are] two opening up our doors. Can you ever really prepare yourself for really critical pieces,” says Dwaine Nichol, director of corporate something like this?” says Evans. “It was a good meeting. It was security at the City of Toronto, who spoke at the most recent an awesome meeting.” meeting. “What is it, where did you get it, how has it worked The level of candour at meetings, and in emails that out so far, why did you replace what you had before?” continue throughout the year, is what has sustained the group While security managers everywhere may be bucking for and helped it to grow, says Evans. larger budgets or at least trying to justify why their existing “Informality, I believe, seems to be attractive to these folks,” funding is so important, the accountability structure is she says. “I don’t know how we did it without this type of somewhat different for government, argues Nichol, since the networking in the past.” ultimate boss is the tax payer. Given that informality, the group’s history Nichol employs a very simple equation can be difficult to map out, but “this has when deciding how funds should be spent been wanting to happen for 15 or 20 years at on security equipment. “Is this worth what If you’re the jack of least,” says Evans. “There was a need for us somebody would pay in property taxes?” to do this. We were all inundated with work he says. “Are you willing to explain to that all trades, you are the and issues and challenges. It was just a time person that you spent their property taxes security group.” factor for most of us. We just couldn’t get on this.” For that reason, “cost effectiveness ourselves together to do this. You’d get the and learning from each other is so incredibly — Dwaine Nichol, City of Toronto occasional phone call from somebody saying, important.” “I understand Mississauga does this… Tell It’s this kind of insight that drew Peter me a little bit about it.” Mercado, supervisor in charge of security at Evans credits Bob Gauvreau, former manager of corporate the Region of Waterloo, Ont., to the group. security in Ottawa, for the initial impetus to bring managers “I didn’t find out about it until two years ago. And when together as a group. I did find out about it, obviously I was very, very interested “I think it was Bob’s idea to start this up,” she says. and signed up. For me, it’s critical. It’s critical to have these “Whenever I had concerns or issues, the first phone call I would information-sharing meetings,” he says. “To be able to sit there make would be to Bob.” and talk one on one with the other security managers, that’s Gauvreau started working for regional government in worth its weight in gold.” Ottawa in 1991 and was offered a new security position after The range of discussion at a meeting can be huge, as befits The City of Ottawa Act set the city’s amalgamation in motion a municipal security manager who may have a vast number in 1999. “We got it going and I came up with a strategic plan: of responsibilities on his or her plate. Some topics might seem creating an integrated security management system,” says unusual, or even odd to outsiders, but challenges that befall Gauvreau. municipal security departments may not be the same as those “I had suggested way back, we should form an organization experienced by the private sector. just for municipal leaders, directors, managers — forget the “Standards, when it comes to legislative standards, are very titles,” he says. “Nothing ever happened with it. I got so busy few and far between,” says Nichol. “These best practices end with the city and I didn’t push it that much. The problem was, up being very important, applicable standards for us to use. with new cities, we were taking on something new that had That takes knowing, what are they doing at other similarlynever been done before.” sized municipalities? What are they doing at other specific But even in the absence of an organization, Gauvreau says infrastructure that a city has, like a water plant or recreation he shared what he had learned with other municipalities from centre or an outdoor pool? In a lot of cases, there’s not a Vancouver to Halifax. “Word got out and I got invited to speak related private sector comparison for those. There’s not a lot of at CANASA (conferences) and different places.” private sector outdoor pools, for instance. It ends up being very Evans says that Ottawa has continued to be a cornerstone important.” of the group, now that it has coalesced into an entity with It’s all the more important to smaller municipalities, regular meetings. Shannon Kenney, Ottawa’s program manager, continues Nichol, where one person may be charge of a broad corporate security, emergency and protective services, is integral variety of activities. “If you’re the jack of all trades at your city, to its efforts. you are the security group,” he says. Where the group goes from here is a matter of conjecture. And while some topics may seem arcane to casual Evans fears that something would be lost if the organization onlookers, there are others that are the most grave imaginable. formalizes and establishes not only a real name but a charter and By happenstance, the 2014 municipal managers meeting was more official structure. Some members appreciate its informality, convened the day after the terror attacks in Ottawa on Oct. 22. suggesting that such an atmosphere is more conducive to Naturally, those events dominated the meeting’s agenda. @SecurityEd • January/February 2016
CS Jan 2016.indd 19
2016-01-27 2:43 PM
20 best Practices Nichol acknowledges that the cliquish, informal atmosphere sharing. “There’s no whamming gavels,” as she puts it. is preferred by some members. But, he says, taking the group to “It seems to work for us,” she says. “Is it going to work the next plateau is almost a necessity. five years from now, 10 years from now? “The vision in this group in the future Maybe we need to have other representation is absolutely that it is more solidified, from municipalities … greater numbers.” “We can celebrate those that there is continued growth,” he says. Municipalities from out of province “Inevitably, we do need to formalize; we do has been involved in the group’s activities things that we do well.” need to be able to hold a seminar in a more to an extent, but usually more through — Cathie Evans, City of formal nature.” email correspondence than physical Mississauga Whatever may be next for the group, meeting attendance. Mercado would like to there is consensus that it is doing good work; participation increase. the insights of its members invaluable. It “I hope they do [expand],” he says. serves as a platform to bring people together and encourages “Basically, it’s a think tank. If you look at the leaders of our them to share ideas, whether it’s during a meeting or more world, they have the G20 and the G8 summits. And what do likely through the multiple emails that serve as the connective they do? They address certain issues. We’re kind of like the tissue holding the group together year round. same thing.” “We can celebrate those things that we do well and talk Nichol agrees. “My view is, I want to open it up as much about the ones that we maybe need to do better,” says Evans. as we can. The more people we have on board, the more “People are coming to our community centres, they’ve stories, the more benchmarks, the more good best practices — coming to our libraries, our arenas. We have to protect their all those things that we can learn and we can give others.” interests as well as our own. These people are essentially Such a structure could see the formation of a conference, our charges when they’re in our buildings. It’s a huge which would open up the group to greater levels of responsibility.” participation from municipalities across Canada.
WHY YOU SHOULD ATTEND: • Cyber security insight from both IT security and physical security professionals • Practical advice on the Cloud, data integrity and protection measures • Inside the mind of the hacker — what to expect and how to prepare
Register online at focusonseries.ca
FOCUSON
Cyber Security
March 30, 2016 Richmond Hill, Ont. Sheraton Parkway Toronto North Hotel
January/February 2016 • www.canadiansecuritymag.com CS_JanFeb_FocusOn.indd 1 Focus On Cyber .5 ad Jan16.indd 1
CS Jan 2016.indd 20
2016-01-20 AM 2016-01-18 10:44 1:47 PM
2016-01-27 2:43 PM
By Derek Knights
Book review 21
Writing the wrongs T
his time last year I reviewed a book called “Introduction to Forensic Writing,” by a Cop-turned-Professor and a Judge. They discussed documents designed to (or likely to) be presented in court. They said that poor writing can have an impact on civil or criminal outcomes. Report writing comes to mind in this context right away, but security practitioners create other documents that can enter the legal disclosure chain. Those written poorly or inaccurately can negatively affect both security agencies and clients. Our industry faces many challenges with the written product. Not everyone has a post-secondary education and many don’t have English or French as a first language. Studies indicate more than half of Canadians have low literacy levels, including 20 per cent of university graduates! Such obstacles make the road to good writing longer but not unending. (Check out www.literacy.ca for these and other studies.) Throughout 2015 I’ve been looking at books that might be helpful for security personnel both in the field and in the boardroom. Here are four selections I recommend — every office should have at least one!
A Street Officer’s Guide to Report Writing, by Frank Scalise and Douglas Strohsal (2013, Delmar Cengage Learning, ISBN 9781111542504). This is a terrific, well-written, easyto-understand explanation of the hows and whys of law enforcement report writing. The authors are senior members of the Spokane Police Department in Washington. Although from the U.S. and law-enforcement-based, this book is readily applicable to Canada’s security industry, particularly the four chapters simply titled: “Clear,” “Concise,” “Complete,” and “Accurate.” It’s fun to read, too — the authors are witty and personable. Write Well, by Judge Mark Painter (2007, Jarndyce & Jarndyce Press, ISBN 9780977272020). I discovered this book through email exchanges with His Honor, Judge Mark Painter of Ohio. I’d discovered an online paper he wrote and asked permission to use it in training. I learned he’d revised it into a book. At less than 100 pages, it has some U.S.-centric parts, but it’s very good at explaining the need for, and how-to of, clear and understandable writing. The Elements of Technical Writing, by Gary Blake and Robert W. Bly (1993, Longman Publishers, ISBN 9780020130857, multiple editions). I only recently discovered this book, and now find it invaluable; particularly when dealing with reports involving “technical” matters — makes sense. The authors discuss not only clarity of words but using numbers in reports, which is often critical in reports about industrial accidents. It doesn’t deal solely with reports but also proposals
and abstracts. The authors have another book together: The Elements of Business Writing. The Elements of Style, by William Strunk Jr. and E.B. White (Original 1918, multiple editions. I use the Fourth Edition, Pearson, ISBN 9780205309023.) The granddaddy book of modern grammar and style. It’s fallen out of favour with some but really only because there are so many more books available these days than when Strunk wrote the initial version. For its size and price, have one in every office and at every site. I suggest senior people start using these or other similar books regularly and work hard to improve writing at the management and supervisory level, then cascade the books and lessons to the field through training and mentoring. Your employees and your customers and clients will thank you. And so might a judge some day. Derek Knights, CPP, CISSP, CFE CIPP/C, PCI, is the senior manager, strategic initiatives, global security and investigations, at the TD Bank Group (www. tdbank.com).
Lawyer,
Mediator
Author of Visual
Evidence
Elliott Goldstein, Cell: 416.315.0066
& B.A., J.D.
elgold@rogers.com
Mediation of Disputes - Commercial, Shareholder, Employment. Litigation to Collect Debts or Defend Customer Lawsuits. Alarm Installation & Monitoring Contracts, Employment Agreements. Minute Book Reviews and Updates, Incorporations. Wills, Powers of Attorney for Property and Personal Care. Video Surveillance Law Seminars, Forensic Video Analysis Law.
www.videoevidence.ca 45 Redondo Drive, Thornhill (Vaughan), ON, Canada L4J 7S7
Fax: 905.597.6226 @SecurityEd • January/February 2016
Goldstein_CS_Sept.indd 1
CS Jan 2016.indd 21
2014-09-04 1:44 PM
2016-01-27 2:43 PM
22 product focus Access Control Biometric solution
Extended-range access control
Suprema Suprema announced three additional RF card format variant models to its BioStation 2 line up. The new models support 125KHz EM, 125KHz HID Prox, and 13.56MHz HID iClass SE RF standards and complete the RF line up that already supported 13.56MHz MiFare/DesFire/DesFire EV1/Felica/NFC formats. BioStation 2 blends hardware and sophisticated algorithms to improve accuracy and provide matching speeds of up to 20,000 fingerprints per second. The performance is matched with a large user and log capacity to accommodate mid to enterprise level applications. The terminal features extensive communication interfaces including TCP/IP, RS485, Wiegand and USB and offers built-in WiFi. www.supremainc.com
HID Global HID Global’s extended-range high frequency and long-range ultra-highfrequency (UHF) solutions provide new options for using a single card to open doors as well as access parking gates from a distance. The new portfolio includes two rugged and weather-resistant readers optimized for outdoor use. The iCLASS SE R90 Extended Range reader is suggested for distances up to 15 inches and supports popular smart card credential technologies, along with HID Mobile Access powered by Seos. The iCLASS SE U90 Long Range reader uses UHF and the dual-technology iCLASS SE and UHF combo smart card to operate over distances of up to 15 feet. www.hidglobal.com
Rack mount access controller
Server cabinet lock
Software House The iSTAR Ultra Rack Mount is a modular 32-door rack mount access controller featuring dual GigE network ports and FIPS 140-2 approved security. Paired with a dual rack mount power supply and battery enclosure, iSTAR Ultra manages power and wiring for access control systems by combining lock power, separately fused lock outputs, and fire interlocks while leveraging standard IT racks, reducing the costs and space requirements associated with wall mount controllers. Plus, iSTAR Ultra controls access to the rack itself, through its ability to manage and control ASSA ABLOY Aperio data center PoE locksets. www.swhouse.com
HES The HES KS200 Server Cabinet Lock extends access control to protect data centre assets from intrusion and expensive downtime, by bringing real-time access control in a single-card system to individual server cabinet doors. Designed to install quickly and easily, with minimal modifications on most swing-handle style server rack doors, the KS200 uses Wiegand wiring to integrate with existing access control systems and ID badges. It supports a Small Format Interchangeable Core (SFIC) mechanical key override and provides robust access control to meet strict regulatory compliance and protect data. www.hesinnovations.com
Lock solutions
Interlock controllers
Yale Locks & Hardware The multi-family solution includes nexTouch, the next generation of the Yale InTouch access control lock, Yale Real Living digital deadbolt, Accentra cloud-based lock management software, and a credential updater, based on secure HID technologies, for updating access rights and transmitting audit trails. The small business solution includes the same hardware plus integration with interactive service platforms, such as those from Alarm. com, Control4, Honeywell and iControl. Accentra cloud-based software can be accessed via PC, tablet or smart phone. Property managers can issue and revoke access for residents, visitors and staff. www.yalerealliving.com
Dortronics 4700 Series Interlock Controllers incorporate a watchdog circuit that constantly monitors operation. Also featured are LED indicators for inputoutput connection status, and system busy or system idle confirmation. The 4700 Series includes suppression protection on all outputs to prevent inductive load locking devices from damaging the circuitry. Additional features include interlock violation alarm relay output; 4 DPDT relays (three powered and one dry contact for signaling); panic release and custom programmable propped door, panic release and door unlock timers. www.dortronics.com
Ad Index Bosch Commissionaires Elliot Goldstein Focus On G4S
9 www.boschsecurity.com/hdsecurity 2 www.commissionaires.ca 21 www.videoevidence.ca 20 www.focusonseries.ca 11 www.g4s.ca
HIKVision Kaba Paladin Winsted
23 www.hikvision.com 24 kaba.to/GetFitCS 6, 7 www.paladinsecurity.com 17 www.winsted.com
January/February 2016 • www.canadiansecuritymag.com
CS Jan 2016.indd 22
2016-01-27 2:43 PM
CS_JanF
#HEARTBEATOFSECURITY
Security isn’t about products, it’s about people. Watch their stories unfold. www.hikvision.com
CS Jan 2016.indd 23 CS_JanFeb_Hikvision.indd 1
2016-01-27 3:27 2:43 PM PM 2016-01-20
Keyscan access control systems network with businesses of all sizes – Get fit! Keyscan electronic access control systems fit our customers’ specific needs for security, organizational efficiency and operational convenience. Our solutions include Keyscan Aurora access control management software providing a single software solution and robust integration options for our versatile networked hardware platform.
Keyscan integrated access control solution
Keyscan_CS_Nov.indd CS Jan 2016.indd 24 1
Our software will drive Keyscan access control systems from one door in a single location, to thousands of doors and users in multiple locations anywhere in the world.
Kaba Access & Data Systems Americas
Regardless of the project size or scope – Keyscan fits.
http://kaba.to/GetFitCS
1.888.539.7226
2015-11-10 AM 2016-01-27 10:24 2:43 PM