In Depth

Safety and Security: The Intersection

Security and safety often go hand in hand, but sometimes they conflict. Here are ways to cooperate to achieve both departments' goals.

By Fred Hapgood

September 15, 2008CSO — In 1999, the Massachusetts state fire marshal issued a cautionary advisory about a new security product: a surveillance camera designed to look like a smoke detector. "This action has created a great concern for us in the fire service," Stephen Coan said. "If this [security cameras as smoke detectors] becomes widely known, we feel that the lives of people will be placed in jeopardy. Out of fear of being watched and the loss of privacy, it is possible that people will begin to cover over smoke detectors, endangering their lives...." Marshal Coan was not alone in his concern: In 2004, New York officials forced local outlets to stop selling the device for many of the same reasons.

Whatever else this incident might teach, it certainly illustrates the complex relation of safety to security. On one hand, the missions have much in common: Both are concerned with the integrity of systems and the protection of people. Yet there are also deep differences: Safety defends against outcomes that are unintended; security, against planned malevolence. Security is comfortable with the languages of incentives and probability; safety, less so. Safety is usually defined by area (Is this a safe neighborhood?); security, often by systems. Safety is a state of mind; security is a procedure. Safety concerns itself with people; security worries about assets, which include but are not confined to people. Security divides the population into good people and bad people; safety treats everyone alike.

At least potentially, these variations can spark conflicts. Security and safety are both interested in access, but security likes to see small numbers of well-identified people moving slowly, while safety wants the option of evacuating large numbers rapidly, without regard to identity. Safety might want to clean up scenes of incidents; security, to secure sites and preserve evidence. Safety systems like to be conspicuous, generally accessible and simple to operate; security might have second thoughts about all those virtues. (And then sometimes security likes to be conspicuous, while safety might have objections, as in a store or school.)

Chemicals security is advanced significantly by underground storage; the EPA, which is charged with ensuring the safety of underground water reserves and is therefore concerned with leaks, makes that difficult. "EPA regulations on chemical storage tanks do not specifically address security, nor do they seek to balance security versus environmental protection," observes Roxanne Smith, press officer at the EPA.

Exactly.

Managing this relationship can therefore be complex. Differences create cultural barriers, and barriers—silos in the organizational context—can slow the diffusion of good ideas. For instance, some feel that safety has been slow to embrace security cameras, even for such simple and straightforward applications as incident review and training, and for monitoring procedure compliance. Sloan Foster, VP of marketing for HBMG Inc., a company in Austin, Texas, that makes surveillance equipment, suspects that this reluctance does not reflect considered policy decisions as much as simple cultural inertia. "Safety people just haven't thought much about security cameras," she says. Of course there is a chicken-and-egg issue here—so long as the market is defined around security, which is what market development will focus on. As of July, not even Foster's own company promoted the safety applications of its products on its site.

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

Prepare for (ISC)2® Certification With Villanova - Online

Rolling the dice with your security? Take the Self-Assessment Test now

Diebold: Frost & Sullivan Global Physical Security Systems Integrator of the Year

Revolutionizing Endpoint Security with a Single Agent

Envision Identity-Based Access Control for the Datacenter

IT Service Management: Metrics That Matter

ITCi White Paper: Challenges and Opportunities of PCI

Effective Security with a Continuous Approach to ISO 27001 Compliance

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Envision Identity-Based Access Control for the Datacenter

Digital Identity Protection and Data Security Get Personal

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage

The Case for Business Software Assurance ~ Securing Your Applications

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Configuration Audit and Control for Virtualized Environments

Take our CSO role survey and receive a copy of the results

Ponemon Study: How Much Does a Data Breach "Cost"?

Data Protection: Challenges for the Traveling User

Key strategies for C-level executives and security staff

Configuration Assessment: Choosing the Right Solution

The PCI Data Security Standard

Configuration Audit and Control for Virtualized Environments

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

IDC Defines an Identity and Access Management Submarket

Using Likewise to Comply with PCI Data Security Standard

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

Solving Online Credit Fraud Using Device Reputation