Sunday, May 22, 2016

HOW TO AUGMENT EMERGENCY PLANNING EFFECTIVENESS

SETTING DESIGN PARAMETERS OR “TRIGGERS”


The price of doing the same old thing is far greater than the price of change.


If we want the outcome of our emergency plans to be different then we probably need to take a different approach to how we design communities.  Right now, the buzz word is “smart” cities.  What we really mean is efficient cities.  Cities that allow for free exchange of movement between different sectors of the cities is essential especially with the growth rate of the world’s population.  Smart cities philosophies are easiest to incorporate when building new communities but what about the “old” city centers and residential areas.  Creating an environment where people want to live work and play is critical.  People want to be in areas not because they are efficient, yes that helps, but the real reason is because they feel safe with their families.

With that in mind, we can establish criteria now for the way we are going to design and construct our communities of the future.

I suggest setting the new design protocols for any pre-planning of neighborhoods, facilities or utility systems, especially if the goal is to decentralize poverty and to reduce crime. With that in mind all new construction after a certain date should fall into this category.  For existing facilities and communities, then we should set “triggers” or thresholds that once they occur we design and construct using the new criteria we’ve established. 

For buildings, those “triggers” could be as simple as; when there is a change in usage, or during major renovation that exceeds 50% of the plant value cost or there is a significant increase in floor space. 

For communities, they could be during major renovation projects when 50% of the system or community is destroyed or damaged and needs replacing, and during community-wide scheduled renovation projects when 50% or more of the infrastructure or buildings are being upgraded.

WHY CHANGE THE STATUS QUO

How’s the old saying go, “If we always do what we’ve always done, we’ll always have we’ve always had”.  

Sunday, April 17, 2016


IMPACT CENTRIC PLANNING

Planning for Low Probability-High Impact Events





TRADITIONAL RISK MANAGEMENT METHODOLOGIES

The traditional mindset of most leaders, whether government or civilian (yes, even in the corporate sector) is that a crisis, situation or event that has the potential to disrupt service or mission capabilities can be planned for by writing a comprehensive emergency plan.  Once that’s done, when an event, situation or crisis occurs, they’ll simply pull out the plan and follow it.  This thought-process is flawed from the beginning.  While plans are a good thing to have they are not what they are made out to be unless the crisis follows it.  Unfortunately, most crisis haven’t seen what you written and won’t do what you’ve outlined for it to do.

The mindset of most folks charged with developing the emergency management policy, procedures and plan focus on most likely scenarios first.  They do this because of limited resources, usually in the form of funding.  It’s always about the money! So they plan for what’s most likely and then hope and pray “the BIG One” doesn’t happen on their watch.

UNCONVENTIONAL CRISIS AND THE READINESS FACTOR

Crises can be divided into two categories – conventional and unconventional.  Their nomenclature pretty much says it all. 

Conventional events occur daily somewhere and we’ve usually prepared for them in terms of resources, training and response.  Mainly because we are used to dealing with them, so we make sure we have the resources on hand.  And if we can’t have our own resources then we set up mutual aid agreements with agencies in our neighborhood of the country to provide support.  Unconventional events on the other hand, are a completely different animal.  They are either so rare or so great we have no way of planning or containing them.  Severe novelty events occur infrequently – they are novel, at least we think that.  Honestly, they occur all the time somewhere.  Just watch the news and you’ll get a sense of how common they are.  So the other half of the definition is severe.  Unfortunately, when combined with novelty sever events can immediately overwhelm local resources, know-how and response.

How often do we hear community leaders say, “we never thought it would happen here”?  This attitude causes a failure in “readiness”, communities are “prepared”; i.e., resources stockpiled and training’s been conducted but really are they ready to handle to event because it is outside of their scope of possibilities. 

Community leaders often get paralyzed and delay critical decisions until the crisis fits into a more recognizable model they can get their arms around.  The delay in action causes a delay in achieving “on the ground” superiority over the event.  This in turn can perpetuate the condition, make it worse and cause for a longer timeline in gaining the upper hand.

OFF-SET OR WELL BANKING

Since managers cannot fund every project or procedure that will cope with a crisis scenario there is a way to program money into future planning and that’s through a process called “off-set” or “well banking”.  Think of it as money set aside for the “what if – worst case” scenarios that we have every intention on spending once we’ve programmed it into our budget cycle and we’ve saved enough.  I contend that corporations, communities, and other entities can set aside a small portion of their budgets for these worst case events.

More about Impact Centric Planning and other methodologies discussed during workshop at Naval Air Station Jacksonville 14-16 June.  Contact us at 805 509-8655 or https://hainessecuritysolutions.com to register.


Sunday, March 27, 2016


Beyond the Email Scandal

How To Properly Design and Construct
a Sensitive Compartmented Information Facility (SCIF)




I don’t know your political affiliation and honestly, I don’t care.  But one thing I do care about is, the way some political beings believe they are above the rules or beyond the approach of the rules.  The recent incident with Hilary and her emails highlights this phenomenon.  Even though I don’t have any “insider” information I can almost assuredly bet that several procedural and policy protocols were circumvented.
Since, there seems to be a common thread throughout the investigation that emails that were not classified upon further examination should have been.  So that’s the first issue.  Correct classification.
Second, I question how, were those emails physically stored.  Rumor has it there was a secure server.  If that’s the case, where was the server located and when dealing with classified was it done at the kitchen table or within a secured space that had been authorized for the handling of classified or, at least, sensitive material?
Almost certainly, there were printed copies of those emails, where were they physically stored? Due to her position I’m sure she had a SCI type clearance.  If that’s the case, did the space where she worked and stored the classified meet technical specifications of IDC/IDS-705 and other pertinent, guidelines?
Like I said, I don’t know for sure but I’d speculate they didn’t since there seems to have been a lackadaisical approach to the classification portion of the process; I would suspect the rest of the approach was “short” too.
We discuss the proper design and construction of a sensitive compartmented information facility (SCIF) which meets official government requirements for a secure area where classified information is handled. The stringent physical security requirements; such as, access control systems, thickness of doors, the strength of concrete and the use of alarms, and acoustical controls which prevent eavesdropping, information exposure or “jamming”, and surveillance prevention will be discussed.  The use of electronic media within the facility will also be explored during a 3-day workshop, held at Willow Grove Air National Guard Base (Horsham, PA), 24-26 May. 

Find out more about other physical security engineering workshops and our Physical Security Engineering Training and Certification Program at https://www.hainessecuritysolutions.com

Sunday, February 21, 2016


3 COMMON MYTHS ABOUT

ACCESS CONTROL AND PERIMETER SECURITY




Most people think access control involves using technology or a guard who checks some form of identification to allow entry into a facility or building – a guard or electronics, and that it.  The security industry has made tremendous gains in the last several years with regards to increasing technology’s capabilities to enhance control at building or compounds.  While these advances assist they are not the cure all.  They are simply tools that assist in the detection of unwanted behavior.  



With that in mind here are three common myths about access control:



Myth 1 – The perimeter or boundary line must be robust in order to adequately provide access control.  This simply is not true.  The US Air Force uses a painted red line on the ground around its nuclear deterrent capable aircraft.  There’s no fence, there no standing guard – just a red line.  The line basically says to everyone, “If you’re on that side of the line, we don’t care who you are or what you do, but, if you want to come on this side of the line we want you to go down to the opening so we can check you out”.  So, really anything can be used – a rope, series of shrubs/plants or a painted line, something that says, here’s the line of demarcation that I care about.



Myth 2 – Fences are a deterrent – NOT!  It takes less than 4 seconds for an unskilled person to climb over a fence, including those with concertina or razor wire.  While adding some type of top guard makes them look formidable they’re really not very effective as a deterrent.  They’re real values comes in the form of detection.  They allow us to detect unwanted behavior.   Think about it, most authorized people will proceed to an access control point, they won’t climb the fence.  Only unauthorized people climb fences; therefore, it serves as a detection mechanism.



Myth 3 – The boundary line or perimeter is the only point available for security personnel to affect access control.  Actually, there are four layers of physical security and each can provide for effective access control, if used correctly.  The layers are; 1 – boundary line or property perimeter, 2 – exterior enclave, 3 – asset façade, and 4 – internal controlled or restricted spaces.  Each layer provides an additional opportunity for control, if used effectively.  Not every asset has a layer 2 or 4 but all have layers 1 and 3, even if, the asset is free standing.  In this case, the façade serves as both layers 1 and 3.  Each layer should be used to deter (albeit limited), delay, detect and allow for response.  This layered approach is fundamental to effective access control.






We’ll discuss perimeter security and entry control facility design during a workshop 19-21 July near Tacoma, WA. For more information contact us at +1 (805) 509-8655.

Sunday, January 17, 2016

What Makes Great Space?

What Makes Great Space?
Making Smart Buildings Wise

With the explosion of the Internet of Things (IoT) and the push for interconnectivity of devices we've been concentrating on making buildings, transportation, and every other facet of our lives "Smart".  Many conferences or symposiums are being held all over the world to discuss this phenomena.  In fact, I participated in the Smart Cities India 2015 Conference and Expo and provided input to the IFSEC Security Conference this past December and will again participate this coming May at the 2nd Smart Cities India 2016 Conference and Expo in New Delhi, India. 

Our discussion centered on the technological ability of connecting devices to more efficiently and effectively manage systems  - transportation, food supply, energy, etc.  I think we can go a step beyond that and say, "Efficiency is nice but what I really care about is the ability to raise my family somewhere where I don't have to worry about them being safe".

By shaping the built environment and integrating solutions, both physical and technological, that are transparent we can create neighborhoods where people actually want to work, live and raise their families- not because they are efficient but because the are safe.  As urban centers of the future increase in population so will the demand for functionality on a multitude of levels. 

One clear local example of the effective and efficient use of space is "The Collection" located at River Park area in Oxnard, CA.  The neighborhoods, both residential and retail, are vibrant with dynamic examples of "Great Space" usage. 

We'll discuss Crime Prevention through Environmental Design (CPTED) and other design principles that define "Great Space" with a 2 day workshop on  May 2nd and 3rd at the River Park Executive Suites, in Oxnard. Please join us. Click on https//hainessecuritysolutions.com for the latest details.



Sunday, December 20, 2015


That's Like Closing the Barn Door After the Horses Get Away


How many times have we heard that?  Well, it happens all the time.  Just because you live in the country or away from city folks it doesn’t mean you can’t become a target of vandalism or theft or worse.  Here are some very common sense things you can do immediately to keep the horses safe and from loosing your britches, so to speak.



Check all gates and fence for damage.  If properly maintained they will keep animals in but the will not keep bad guys out.  You may have heard of the “broken window theory”.  Basically, it says in areas where there are rundown buildings, with broken windows crime is sure to follow.  Same goes for fences.  Fences that are not maintained suggest that security is not a very high priority and other areas of the farm, ranch and homestead are vulnerable, too.



Ensure ditches are maintained and clear of debris.  You need to do this for several reasons; 1) to make sure the ditches drain properly, 2) so that they don’t provide hiding places for the bad guys, or 3) allow the bad guys to drive through your fence.  A properly maintained ditch provides some protection.



Keep chemicals/fertilizer under strict control, especially, if being used in the field.  Do not leave outdoors overnight.  Bring the wagon back to the barn and secure it.  You’re going back that way anyway, so there’s really no extra effort.



Report unsolicited requests to buy fertilizers or chemicals from you to the authorities.



Control access to all buildings.  There are lots of electronic gadgets out there these days to assist in that area.  But they all basically fall into one of three categories, each being more secure and more expensive than the previous.  Something you have – like an access card, something you know – like a pin number, and something you are – like a retinal scan or fingerprint.  A system that has a combination of two of the three is preferable.  Make sure all buildings are protected.  Beside the animals, there are lots of items to steal.  Copper wiring, metal tubing, and lead seem to be high the thieves priority list these days.



Install visible deterrents, such as, motion activated lights and cameras.  Some systems allow for you to talk from the camera and warn the bad guy that they’re being watched.  Might be useful to "shoo" those high schoolers away who are "cow tipping" or "snipe hunting".



More common sense tips available https://hainessecuritysolutions.com/Technology_Improvements.html or under the Technology Improvement Tab.

Sunday, November 22, 2015


8 Tips for Do-It-Yourself
Home and Small Business Security Alarm Systems


There are lots of alarm companies that will tell you, that you need their alarm system in order to monitor activity in and around your house or business.  They will sell you an “all-inclusive package” of X number of cameras and sensors.  The reality is, whatever X represents is in most cases not going to be enough the cover your entire building or home.  They make their money when they sell you additional equipment.  They include X but what you really need is X more to provide complete coverage. 

New alarm systems allow the homeowner/business owner to monitor activity via an IP connection.  So you can monitor your system from anywhere there’s an internet signal.  With that in mind, alarm companies now have the owner monitor the activity and notify them instead of the old way where they would monitor and notify the owner when sometime seemed amiss.  In either case, if the responding patrol car doesn’t get there within 10 minutes chances are very high that the perps will be gone and all you will have is evidence on film that they stole something.  Don’t be fooled by what you see played out by Hollywood and on TV shows – Fact: 98% of crime captured by video surveillance does not result in an apprehension.

Now that you’ve been warned, here’s the other side.  Nowadays, relatively inexpensive systems are available for do-it-yourselfers.  Eventhough surveillance cameras are an assessment tool they can provide some deterrence, if there’ visible and especially if there’s a warning sign in the yard or at the front entrance.  Actually, the sign is the deterrent not the cameras or sensors, but you get the idea.  Additionally, if properly placed, electronic security along with an appropriately equipped and trained response force can be effective.  Here are ten things you can do to make sure your alarm system benefits you and provides the protection you seek.

  • Place outside cameras so that they view avenues of approach and can detect people as they come up to the front door or entrance.
  • Placement of cameras internal to structures is a little trickier.  They have to be able to capture the entire room and high enough so that the bad guy can’t knock it down or spray paint the lens.  Discreetly placed “nanny cams” can help but it seems they are always pointing in the wrong direction or covered up by something.
  • Perform regular maintenance by cleaning the lenses and housings.  Nothing worse than getting burglarized and find out that your camera system captured Charlotte building her web.
  • Test the system regularly.  Find out from the monitoring company how often you’re allowed to test the system without a charge.  I would recommend, at least twice a year.  More often if necessary.  Find out the priority for response.  If you live in a high crime neighborhood guess what, they’re not coming – unless the perps still there and in that case you shouldn’t be.  Police departments maintain these types of stats.
  • Check the cameras field of view.  Is it viewing what you want viewed?  Sounds pretty stupid doesn’t it, but how often have the camera angles changed because of high winds or by being bumped by a cat or other critter.
  • Insure you have the latest software available.  If password enabled, make sure you change the factory installed password once you start using it.
  • Get an Uninterrupted Power Supply (UPS) that is capable of running your security system until the power can come back on.  The UPS should be able to maintain the system for at least a day.
  • Don’t rely solely on one type of electronic security equipment, if you have cameras augment them with sensors and vice versa.  Chances of both systems failing at the same time is pretty slim.
  • Place volumetric sensors so that the beams shoot out across a room and not directly at the door or windows.  These sensors work by detecting variations in the beam, so as a person walks between one beam and another they get detected.  Think of it like your hand with the fingers being the beams radiating across a room.

Don’t forget that just because you have an alarm system it doesn’t make you invincible.  If the rest of your security posture sucks, they’re gonna get you.  It’s just matter of time!

More common sense tips available under the Technology Improvements Tab on our homepage or here: https://hainessecuritysolutions.com/Technology_Improvements.html