Showing posts with label Perimeter Security. Show all posts
Showing posts with label Perimeter Security. Show all posts

Saturday, May 10, 2014

FAA Announces Security Access Control Systems Meeting

The DOT’s Federal Aviation Authority (FAA) published a public meeting notice in Monday’s Federal Register (available on-line today; 79 FR 27032) for a meeting of the RTCA Special Committee 224 concerning Airport Security Access Control Systems. These access control systems do not include TSA passenger screening areas. The meeting will be held on June 3rd, 2014 in Washington, DC.

According to the notice the agenda includes:

• Updates from the TSA;
• Review and Discussion of PMC [RTCA Program Management Committee] Decisions on DO-230D—Standard for Airport Security Access Control Systems;
• Review of DO-230D Sections—Determine Required Update Sequence; and
• Terms of Reference—Discuss Possible Revisions

The meeting is open to the public but there is only limited seating available. The Chair may allow public presentations. To get advance approval for such presentations contact the RTCA Secretariat at (202) 833-9339.


NOTE: No I’m not taking this blog specifically into airport security. On the other hand, airports have many of the same security issues (outside of passenger areas) that can be found at large chemical facilities, an extensive (and usually poorly patrolled) perimeter and few internal movement controls. Lessons learned, and standards set, in airport security could certainly be applied to chemical facility security.

Tuesday, August 14, 2012

Another High Profile Perimeter Security Incident


A little over a week ago I wrote about the perimeter breach at a nuclear fuel processing site. Yesterday there were news reports about a stranded jet-skier who walked from a beach at JFK to the terminal (across two runways and gained access to the terminal) without encountering security personnel until he asked an airline employee for assistance. In both instances amateurs easily gained effective access to high-profile security areas with little effort.

As a long-time reader and security professional noted in a response to my earlier blog posting (BTW: That response is well worth reading in its entirety.):

“With all of the academics discussing regional resiliency and other highly important subjects, it pains me that the journeymen of our industry still do not understand these basic tenants of industrial security.”

Why is Perimeter Security So Difficult?


With all of the advances in video surveillance, video analytics and intrusion detection systems, perimeter security remains a manpower intensive operation. Someone has to monitor these systems and someone has to respond to system alerts. Since security is not a profit center, the personnel responsible for monitoring and response are too often underpaid and under qualified. All too often this results in people that have no real incentive to care about their job.

In the real world effective automated detection systems have a high false alarm rate, if they don’t they make it too easy for professionals to penetrate the perimeter (NOTE: It is impossible to design a perimeter that cannot be penetrated). In the industry these false alarms are well known as ‘nuisance alarms’. As time passes the aggravation caused by these nuisances results in sensitivity adjustments to the automated systems to reduce the number of such alarms, or in people ignoring the alarms when they do occur. This is simply human nature. In any case this results in a perimeter that is easier to penetrate.

How to Avoid Security Complacency


Probably the best way to avoid perimeter security complacency is to conduct periodic penetration testing. Specially trained Red Teams are given the mission to penetrate the security perimeter. Special training is required so that these teams only use the amount of penetration skills appropriate to the security level of the facility being protected. For example a nuclear weapons storage facility would require a higher degree of professionalism to be used in the attempted penetration than would a warehouse holding high-cost consumer goods.

Bonuses can be given to the security team that detects and intercepts the Red Team; the earlier the detection and interception the higher the bonus. Penetrations such as those noted in the two recent news reports require the application of negative inducements and corrective reassessment of security measures including training.

Responsive Activities Require Training and Testing


Any kind of activity that requires an immediate and effective response to an outside stimulus requires periodic training and testing. If you require a high-level response to infrequent events you must invest the time and resources necessary. Proper training and periodic evaluation of the necessary skill sets is an absolute necessity. Otherwise your organization is going to be embarrassed by these types of incidents, or worse, you’re going to have a catastrophic failure of your security that is going to result in death and destruction.

Wednesday, January 25, 2012

TSA Analysis of Video Surveillance System

I typically don’t try to promote specific security systems as I am not a ‘qualified expert’ in much of anything that would allow me to make an authoritative evaluation of any particular product. Every once in a while I run across (thanks in this case to a SCADAHacker tweet) an evaluation of a system by someone or an organization that should be qualified to do such an analysis and I think it’s worthwhile to look at such evaluations. I recently ran across a TSA report on the use of a video analytics system used to secure an airport perimeter that falls into this category.

The Report


The report was prepared as part of TSA’s Airport Perimeter Security project that provides a technical evaluation of perimeter security systems currently being employed at facilities around the country. This project should provide security managers with an important independent evaluation of integrated security products to supplement claims made by manufacturers and system integrators. This is apparently the first of 15 (perhaps 21, the wording of the report is sort of vague) such reports that TSA is currently preparing.

The actual evaluation was done by the National Safe Skies Alliance, a non-profit organization formed to “support testing of aviation security technologies and processes”.

Redacted Information


One would expect that an in depth review of a security system would involve the disclosure of some sensitive information that might be useful to someone trying to compromise that system. This report is no exception. TSA has dealt with that by redacting (blacking out) certain information in the report. While protecting the security of the installation being evaluated, it does somewhat compromise the usefulness of the evaluation.

For example the report redacted a site diagram (page 3, 15 Adobe) showing the areas covered by the video system; an understandable exclusion. Partially understandable, but certainly less helpful to security managers, was the redaction of the test intrusion detection rates in reporting the test results for the four individual intrusion techniques tested (with any details of the intrusion technique redacted). What makes this somewhat confusing is that in the summary discussion of the system accuracy the report notes that over 900 intrusion scenarios were performed (four intrusion techniques performed at a variety of locations within the detection range of seven devices) and that “every alarm instance was accurately reported through the primary management software” (page 13, 25 Adobe).

So what is redacted is the rate of failure to detect; darn that could be valuable information for security managers. What is less clear is how this would compromise system security unless the detection rate is extremely poor. If the system had a high rate (say 80% for the sake of discussion) that would warn attackers to stay away since there attack would have an 80% chance of being detected at the perimeter. On the other hand, if the detection rate were low (say less than 20%) that might make the attacker more willing to risk the attack.

Missing Information


While one can understand why much of the redacted information is not available, the information that is specifically missing from the report is much more bothersome. One of the general complaints about automated surveillance systems is their relative high-rate of nuisance alarms (natural environmental movements that set off the detectors) or false alarm (inappropriate detections with no known cause) rates. Those rates are missing from this report.

In the ‘Scope’ section of the report the author notes that the evaluation period was insufficiently long to establish nuisance or false alarm rates or to determine their cause. I find this hard to believe when there was time enough to evaluate 900 intrusion attempts by two field testers. At the very least the report should have included information about the number of nuisance or false alarms observed during the test period. This may not be statistically sufficient to establish a true rate, but it would provide valuable data in any case.

What concerns me more is the fact that the report states the reason the report could not distinguish between nuisance alarms and false alarms (an important distinction) was that the causes of alarms “had not been recorded by BUF (airport security personnel) personnel” so there was no way to verify alarm type. This would seem to indicate that security personnel were not really paying attention to the alarms on their system, or at the very least were not investigating alarms sufficiently to determine if an intrusion were actually taking place. This is not a fault of the report, but rather of the security management at the facility.

Interestingly, in the discussion of the results portion of the report there is a large redacted box in the section dealing with “Nuisance and False Alarm Reporting” (page 12, 24 Adobe). It would be really nice to know what was discussed there.

Overall Report Evaluation


I’m glad to see that TSA is having this type of system evaluation done. Unfortunately the usefulness of the information presented is compromised by the redaction of evaluated data. In most cases I can understand and even agree with the reasoning for the redaction in the public presentation of this data. For this to be worthwhile, however, TSA is going to have to find a way to make the un-redacted information available to airport security managers and security managers at other critical infrastructure sites. Otherwise this report will just sit on a shelf collecting dust.

Saturday, April 23, 2011

Enhanced Security Planning

Well, unless you were living way further out in the backwoods than I do, you have undoubtedly heard about the new Homeland Security National Terrorism Advisory System (NTAS) that was announced this week by Secretary Napolitano. If you’re associated with the CFATS program you will also be aware of the thundering loud silence from ISCD about how to adapt the RBPS 13 portion of your site security plan to the replacement for the old color-coded HSAS system that formed the basis for RBPS 13 in the Risk-Based Performance Standards Guidance document.

To be fair to Director Driggers, he and his staff have larger problems to deal with. Besides, there is probably no one left in the Directorate that was part of the team that wrote the guidance document in the first place. So with that in mind I’ll give a little support and update the comments that I posted earlier this week.

Why is Enhanced Security Planning Necessary?

I don’t need to tell security managers working at CFATS-covered facilities that security equipment, personnel, training and maintenance are very expensive. And with the realization that no security system is impregnable, there is always one more widget that can improve the situation. Unfortunately the rate of return (increased security/dollar spent) on those widgets also starts to fall off rather quickly.

The dark side of security planning is that security measures are a pain in the butt. A comprehensive security system interferes with the day-to-day operation of the facility in countless little ways. Sooner or later employees, especially the good ones, will find ways to circumvent the security processes to make their jobs easier. This is especially true if there seems to be no immediate prospect of an attack on the facility; I mean, what could it hurt????

So the security planner, knowing all of this, and under pressure to keep costs down because security is not a profit center, walks a fine line in trying to have enough security in place but not too much. So they look at the threat picture for chemical facilities (or whatever facility, this applies to everyone, but we are the chemical security community here) in the United States and its easy to see that the vast majority of terrorist attacks in the last ten years have been executed by less than effective terrorist wannabes.

Now this is good news as wannabes are much easier to defend against than the al Qaeda A team. To be on the safe side you plan your defenses for the Wannabe All Stars. You get that program in place, you train and practice, just to keep everyone sharp and everyone stays happy. And you have a facility security system that will deter, detect and delay the wannabes; the best of the wannabes maybe, but still wannabes.

The smart facility security officer knows, however, that the counter-wannabe security plan isn’t really good enough to prevent someone with truly evil intent, determination and a decent level of training and equipment from walking right through the security measures and capturing the flag. Hopefully it will be good enough to convince the A Team (from what ever league; trust me there are more evil doers than just al Qaeda out there) to go play at the next plant down the road with less proficient security.

No security manager worthy of the title can rest with just a defense against wannabes. They loose sleep at night worrying about what happens if they win the terrorist-site-selection lottery; if the A Team moves them to the top of their hit parade. Then the intelligence pukes (security guys and intel guys never really get along, they don’t trust each other too much) drop a message in the in-box saying that the bad guys have been talking about how lovely your facility would be with a large fireball in the center of the tank farm. Oh, and the ‘chatter’ sounds a lot like their visit is imminent. Have a nice day.

Too bad, you have a wannabe security plan in place and the pro’s are on the way. Too late to hold committee meetings, or get security upgrade requests onto the CEO’s desk for approval. Hell, the security widget salesman has heard the same news and isn’t returning your calls; he doesn’t want his product associated with a successfully attacked facility because his widget was half-installed. Besides, your insurance company is not going to pay the net-30 invoice anyway after the smoke clears.

Now, if you had a plan in place for how to deal with the pro’s; with all the approvals signed and purchase orders okayed, with everyone read in on what they had to do when you screamed ‘the A-Team is coming’; then you just might have a chance. If not, then just have them chisel your resignation letter on your headstone.

How do you do Enhanced Security Planning?

First off, you have to realize that security planning, just like any other kind of planning never stops. In production planning for instance, you formulate your plan then you monitor production and orders and modify your plan accordingly. In security planning you hope you never have to actually execute your A-Team plan. So to maintain proficiency you keep making new plans all of the time. Each new plan makes you more proficient at the planning and response process and makes you look at your overall site security plan from a slightly new perspective.

So the first thing you do is to identify your most important target at the facility. Then you determine the most common way that an A-Team terrorist would attack that target. Then you formulate a plan to counter that attack; simple enough, right? Oops, I forgot to tell you that you have to plan for 24-hour notice of the impending attack (hope you get more, pray you get at least that much), so scratch installing a new building around that target as part of your A-Team response plan.

So, you are going to have to depend on security upgrades that can be put in place quickly. Typically this is going to mean increased security personnel and changes to procedures. Installation of fixed equipment is too time consuming and expensive. If the supporting security company has portable security devices/equipment that can come into the facility when needed, this should certainly be examined. For the most part, however, the security equipment you have when you receive The Call, is what you are going to have to deter, detect and delay the attack.

Perimeter Patrolling

One good thing to remember in this planning effort; if you are within 24-hours of being attacked by the A-Team, you are under surveillance. They want to succeed real bad (at least as bad as you don’t want them to succeed) so they are not going to take chances that a small last minute security change will disrupt their attack plan; this is how they got to be the A-Team.

This means that visible up-grades to perimeter security are almost always a good idea. The fastest, easiest and cheapest security upgrade is increased patrolling inside and outside of the perimeter. The folks outside should be looking for the watchers; identify them, catch them, or disrupt them. If they are more worried about their own security than upgrades to your security you have probably prevented a successful attack. Oh, and don’t forget to include increased police patrols as part of your outside the perimeter patrol plan; they are very cost effective.

The increased interior patrols will make it harder for the A-Team to avoid early detection in their penetration of the facility perimeter. Just remember to keep your patrols following random routes and random patrol frequencies. This makes it harder to figure timing necessary to avoid even the increased patrols. You’re never going to have the funds or manpower necessary to eliminate all patrol gaps; adequately (not perfectly; see my blog on randomizing security patrols) randomize your patrols so that the attacker can only identify an adequate patrol gap after it has effectively closed.

Interior Patrolling and Guard Posts

Most high-risk facilities, in a low-risk, wannabe-threat environment are not going to need security patrols roving through operational areas of the facility. Nor will they typically feel a need to have much in the way of internal guard posts. These security tools are just too much of an intrusion into production areas and get in the way. They also require much more in the way of chemical hazard communications training for the guard force.

With the A-Team outside the gates, however, this is going to be the only real cost-effective way of increasing the delay factor inside of the facility perimeter. Again, you have to remember that you are being watched. In this case the counter surveillance tactics work just a little bit different. You probably want the A-Team to know that you have increased the number of security personnel inside the perimeter; have the new security personnel show up in a van or bus for instance. You almost certainly don’t want them to know where the security personnel are at or what they are doing. If you are using internal patrols, the patrol plan needs to try to keep them invisible from outside of the security perimeter as much as possible.

If you are going to use security patrols in the operational areas of the plant, they need to be adequately protected against the production hazards found in those areas. This will mean the proper issue, fitting and use of personal protective equipment as well as being trained to be able to detect the specific hazards associated with the areas in which they are operating. This argues for not using new security personnel for this type duty. There are two obvious solutions; first use the newbie augmentation personnel on perimeter duty and facility experienced personnel for internal patrols; or have production personnel accompany these internal patrols to help keep them out of operational harms way.

Internal guard posts are much trickier to use than it would seem at first glance. Putting a guard out in the middle of nowhere, even with communications, is inherently ineffective. A guard post is only going to be effective when there is a physical structure that naturally channels attacking forces through that point and the guard has some way of controlling movement through that area of restricted movement. Typically, this is a locked door or gate that the guard controls.

If an attacker must mover through that portal to effectively complete their assault, this makes the security guard an obvious target. Protecting the guard from attack increases the effectiveness of the portal at preventing unauthorized access. Using video cameras and electrically operated locks makes a door monitor in the security control room effectively a guard post at that portal.

One last thing to remember, to a trained combatant, a wall is just slightly more of an impediment to entry than a closed, unlocked door. If you’ve ever seen a violent drunk put a fist through a wall, you have a good idea of what I mean.

Executing the Plan

Now there are certainly other tools and techniques that can be used for enhanced security measures and I’ll discuss some of them in upcoming blogs. I certainly would like to hear from the community on their unique ideas about temporary security measures that can be easily put into place at relatively short notice during periods of high threat. But for the purposes of this discussion this should be enough to take a look at how these increased patrolling measures can be put into a enhanced security plan and executed when The Call is received.

First off, the resources to implement the plan need to be carefully determined. Lets say that it will require two three-man patrol teams and a patrol supervisor on each shift to execute the enhanced perimeter patrol plan. Every facility that I have seen uses an outside security company to provide their security guards. The security company contract would then need to be modified to include the responsibility for providing the augmented security force on some sort of minimal notice. I would also include provisions for periodic implementation for short periods to exercise the augmentation plan for training and evaluation purposes.

Where increased police patrols are made a part of the external patrol plan the same sort of agreement needs to be reached with the local police department. One doesn’t normally contract for these services (someone please correct me if I’m wrong), but some sort of written agreement is certainly in order, if just to clarify the requirements.

Then when the call comes in, the facility security manager makes a single call to the security company and says ‘execute security augmentation plan 14’ or something simple like that that allows for immediate movement without a lot of discussion. A similar call is made to the local police department. And everyone starts to move into the higher security mode called for in the facility site security plan.

A Fast Response is better than the Right Response

OOPS. The Call says that it is a group of radical defenders of the lives of Rainbow Darters in a nearby stream that will be attacking not al Qaeda. This group is not interested in attacking your tank of tetramethyldeath (the tank that you identified as your number one target), rather they are after a storage tank where you store a flammable chemical that interferes with the breeding instincts of the Rainbow Darter. The Call goes on to explain that this is the A Team of radical environmentalists with skills and training comparable to anyone that the radical jihadists could send at you.

Oh my, that tank was never considered to be an enhanced target. Oh my, what to do? Don’t sweat it. Initiate the plan for the tetramethyldeath storage tank. Get the cavalry on the way. You can modify the internal patrol plan as necessary (if it was considered necessary in the first place) and the perimeter patrol plan is almost certainly fine without modification other than to tell everyone to look out for hippies in t-shirts and ratty-jeans instead of ‘arabs in flowing desert robes’ (Oh, you didn’t assume that al Qaueda would look like someone out of Lawrence of Arabia? Good for You).

There is an old military adage that says “No plan survives contact with the enemy”. No plan is going to properly predict what the attacker is going to do. The important thing to remember about any sort of contingency planning is that it is easier to modify an existing plan than it is to start a plan from scratch. The important thing is to get people responding and moving. Just the arrival of additional security personnel on the site may be enough to prevent an attack from taking place. This is why enhanced security planning is so important.

Sunday, August 22, 2010

Gate Busting

Earlier this month I posted a blog about perimeter fencing and I talked about how easy it was to penetrate fences. I didn’t particularly address the issue of vulnerability of gates, but CNN® provided video evidence earlier this week of how easy it is for vehicles to break through many standard gates. According to the accompanying news story the pickup truck was being chased by police when it entered the airfield through the closed gate. Pursuing police were able to stop the truck before it got near any aircraft.

Perimeter Gates

Most gates, like most fences, are designed to keep honest people honest, not to provide a serious impediment to unauthorized entry by vehicles. Where there is no specific reason to expect antagonists to crash a gate, these standard gates are perfectly adequate to define a boundary. Where there is a suspected risk of terrorist attack, facilities relying on a perimeter fence to reduce the risk of a vehicle borne improvised explosive device (VBIED) being introduced to the facility will require a specially designed (and much more expensive) gate.

Airport Security

While this isn’t an airport security blog, I can’t help but mention how badly this incident reflects on the status of airport security. This country has spent untold billions of dollars on TSA screeners, high-tech screening devices, and complex programs to ensure that all packages going into cargo holds are properly screened. Now we see how totally inadequate simple perimeter security measures are around the same airports.

If this truck hadn’t been closely pursued by a number of police cars, there would have been little that would have prevented a VBIED from being driven into planes waiting on the tarmac. Even a truck load of heavily armed gunmen could have destroyed a number of loaded aircraft. Obviously the vulnerability assessment at this airport (and probably most others as well) failed to take a serious look a perimeter security measures.

Thursday, February 18, 2010

Water Security Breach

There is an interesting article over on Dispatch.com (Columbus, OH Dispatch) about a recent security breach at a local water treatment plant. The interesting thing about this breach is that the police can only narrow the time of the breach down to a time period of about 15 DAYS long. The intruders cut through two fences and stole 200 feet of copper wire from an on-site electrical sub-station while avoiding detection by facility security cameras.

According to the article, a spokesman from the American Water Works Association downplayed the seriousness of the breach since the drinking water treatment equipment on the 148 acre facility was not involved in the break-in. Hopefully that spokesman is not involved in advising member utilities on security matters.

Purpose of Perimeter Security

There are three complimentary reasons for having perimeter fences. The most obvious is to keep people out of the facility. All security professionals realize that fences can not stop unauthorized access, just deter it. To paraphrase a common folk saying; fences are designed to keep honest people honest. They will not keep out people determined to enter the facility.

With this in mind, we can see that a well constructed perimeter fence serves the second purpose of classifying intruders. Anyone breaching that barrier is a threat to the facility. Without a good perimeter barrier intruders could be anything from a casual passerby to someone with nefarious intent.

The third purpose is to provide early warning of intruders. This will allow a security response team, either guard force or police, to interdict and apprehend the intruders before they get into the restricted area at the heart of the facility; in this case the actual water treatment works or drinking water distribution system.

In this case while the perimeter barrier performed the first two functions, the third was completely lacking. While it was not apparently the intent of these intruders, someone wishing to do damage to the water supply for 1.1 million people could have conducted an extensive on-site reconnaissance of the facility security and conducted a well rehearsed attack on the water treatment equipment in the 15 day period that the breach had not been detected.

Critical Resources 

One would assume that an electrical substation on the grounds of the water treatment facility would be there, at least in part, to supply power to the water treatment equipment used on site. As such we would have to consider this substation a critical resource for this facility. A successful attack on this substation would shut down the water treatment facility and the supply of drinking water to much of the city of Columbus, OH.

Now there was another perimeter fence around this substation, but it was also penetrated without detection. It is not clear if this fence was simply a safety device, installed to keep untrained personnel away from dangerous electrical currents, or if it was an actual security barrier. It obviously performed neither function well.

One would like to assume that the security barrier around the actual treatment and distribution equipment would provide more of a warning of penetration. Based on the news report on this incident, I really doubt it. Oh well, it doesn’t matter anyway; no one wants to do harm to this country, there is no terrorist threat, and no one has ever attacked a water treatment facility. Why do we need security anyway……

Thursday, June 4, 2009

RBPS Guidance – RBPS #1 Restrict Area Perimeter

This is another in a series of blog postings that will provide a close-up look at the RBPS Guidance document. DHS recently released this document to assist high-risk chemical facilities in meeting the risk-based performance standards required for site security plans under 6 CFR §27.230. The other blogs in the series were the: Risk-Based Performance Standards Guidance Document RBPS Guidance – Getting Started In this posting will cover the first Risk-Based Performance Standard (RBPS), Restrict Area Perimeter. Almost the entire written portion of this RBPS remains unchanged from the Draft Guidance document. The only significant differences will be found in the Metrics, but even those changes are more cosmetic than effective. There is a great deal of overlap between this standard and RBPS 2 (Secure Site Assets), RBPS 3 (Screen and Control Access), RBPS 4 (Deter, Detect and Delay), and RBPS 10 (Monitoring). Anyone that is interested in really understanding how to fulfill the requirements of this standard needs to read those standards as well. Perimeter vs Asset Security One of the first things that a facility security manager is going to have to decide in developing a site security plan is how much of the facility footprint is going to be included in the security perimeter. While the first assumption that everything within the ‘fence line’ will be secured, many factors will go into that decision. The size of the facility, the COI to be protected and the facility terrain are all factors that must be considered. The one consideration that argues for the largest possible security perimeter is the need to provide the greatest amount of time for a security response to be mounted. This is illustrated in the Guidance document in Figure 1 on page 23. This shows how much more time the security force has to respond when the attack is detected at the facility perimeter. This is especially important when a facility relies on local law enforcement for the armed component of its response. One option for facilities with extremely large perimeters that is not adequately discussed in the Guidance document is for the facility to rely more on detection than barriers at the extreme limits of the perimeter. While this does little to stop accidental or incidental perimeter penetrations it does provide for the critical response time. It can result in more false alarms, especially if there is a lot of off-road traffic in the area. Security Measures The Guidance document notes that there are typically four types of security measures that are used to protect the facility perimeter. They are:
Perimeter barriers, Intrusion detection systems or other types of monitoring, Lighting, and Protective forces
The major point made here (and elsewhere in the RBPS Guidance document) is that there is no single security tool or method that will adequate protection of the facility. A carefully considered combination of techniques using a ‘layered approach’ will usually be the most successful way to prevent successful terrorist attacks on high-risk chemical facilities. What most people with out extensive security training fail to realize is exactly how ineffective most barriers are to determined intruders. The ubiquitous chain-link fence is very easy to go over or through. That is not to say that barriers have little use in a security plan. Security planners just need to insure that barriers are under some form of observation. The importance of lighting at the facility perimeter is often overlooked. Adequate lighting not only aids in monitoring the perimeter, but it also acts as an important psychological barrier because it removes the protective cloak of darkness. Facilities with long and remote perimeters will find adequate lighting to be expensive to install and maintain, but the alternative is to use more expensive observation techniques that can operate in low ambient light levels. RBPS Metrics I still have a minor problem with the use of the term “Metrics”. This implies measurements to standards. These metrics do not actually allow ‘measurement’ because Congress prohibited DHS from specifying any security measures in their approval of Site Security Plans. To be fair, I’m not sure what word I would have used in place of ‘Metrics’ so I guess I shouldn’t complain. I am more concerned with the fact that there are terms and concepts used in the metrics to describe ‘potential’ security measures that are not discussed in the body of the RBPS chapter. Metric 1.1 mentions the use of ‘clear zones’ but there is nothing to describe what those are, how they are used, or considerations in their employment. Similarly Metric 1.3 suggests the use of ‘standoff distance’ to mitigate the effect of VBIED, but there is no discussion of how to effect that standoff and how much standoff might be necessary. Then there is no discussion of how standoff is used to protect against direct fire weapons like rocket propelled grenades. Appendix C There are additional details in Appendix C about the various security measures described in the RBPS. The discussion of barriers is especially good, though it is no where near good enough to make one an expert on barrier technology. The information in Appendix C that will probably be most valuable is the list of references at the end of each discussion.
 
/* Use this with templates/template-twocol.html */