HOME

TheInfoList



OR:

Security convergence refers to the convergence of two historically distinct security functions –
physical security Physical security describes security measures that are designed to deny unauthorized access to facilities, equipment, and resources and to protect personnel and property from damage or harm (such as espionage, theft, or terrorist attacks). Physi ...
and
information security Information security is the practice of protecting information by mitigating information risks. It is part of information risk management. It typically involves preventing or reducing the probability of unauthorized or inappropriate access to data ...
– within enterprises; both are integral parts of a coherent
risk management Risk management is the identification, evaluation, and prioritization of risks, followed by the minimization, monitoring, and control of the impact or probability of those risks occurring. Risks can come from various sources (i.e, Threat (sec ...
program. Security convergence is motivated by the recognition that corporate assets are increasingly information-based. In the past, physical assets demanded the bulk of protection efforts, whereas information assets are demanding increasing attention. Although generally used in relation to cyber-physical convergence, security convergence can also refer to the convergence of security with related risk and resilience disciplines, including
business continuity planning Business continuity may be defined as "the capability of an organization to continue the delivery of products or services at pre-defined acceptable levels following a disruptive incident", and business continuity planning (or business continuity ...
and
emergency management Emergency management (also Disaster management) is a science and a system charged with creating the framework within which communities reduce vulnerability to hazards and cope with disasters. Emergency management, despite its name, does not actu ...
. Security convergence is often referred to as 'converged security'.


Definitions

According to the United States Cybersecurity and Infrastructure Security Agency, security convergence is the "formal collaboration between previously disjointed security functions." Survey participants in a
ASIS Foundation
study ''The State of Security Convergence in the United States, Europe, and India'' define security convergence as "getting security/risk management functions to work together seamlessly, closing the gaps and vulnerabilities that exist in the space between functions." In his book ''Security Convergence: Managing Enterprise Security Risk'', Dave Tyson defines security convergence as "the integration of the cumulative security resources of an organization in order to deliver enterprise-wide benefits through enhanced risk mitigation, increased operational effectiveness and efficiency, and cost savings."


Background

The concept of security convergence has gained currency within the context of the Fourth Industrial Revolution, which, according to founder and Executive Chairman of the
World Economic Forum The World Economic Forum (WEF) is an international non-governmental organization, international advocacy non-governmental organization and think tank, based in Cologny, Canton of Geneva, Switzerland. It was founded on 24 January 1971 by German ...
(WEF)
Klaus Schwab Klaus Martin Schwab (; born 30 March 1938) is a German mechanical engineer, economist, and founder of the World Economic Forum (WEF). He acted as the WEF's chairman since founding the organisation from 1971 until 2025 when he was replaced by P ...
, "is characterised by a fusion of technologies that is blurring the lines between the physical, digital, and biological spheres." Key results of this fusion include developments in cyber-physical systems (CPS) and the growth of the
Internet of Things Internet of things (IoT) describes devices with sensors, processing ability, software and other technologies that connect and exchange data with other devices and systems over the Internet or other communication networks. The IoT encompasse ...
(ioT), which have seen a proliferation in the number and types of internet connected physical objects. In 2017,
Gartner Gartner, Inc. is an American research and advisory firm focusing on business and technology topics. Gartner provides its products and services through research reports, conferences, and consulting. Its clients include large corporations, gover ...
predicted that there would be 20 billion internet-connected things by 2020. Security convergence was endorsed as early as 2007 by three leading international organizations for security professionals – ASIS International, ISACA and ISSA – which together co-founded the Alliance for Enterprise Security Risk Management to, in part, promote the concept.


Types of convergence


Cyber-physical convergence


Risk convergence

In the context of the Internet of Things, cyber threats more readily translate into physical consequences, and physical security breaches can also extend an organisation's cyber threat surface. According to the United States Cybersecurity and Infrastructure Security Agency, "The adoption and integration of Internet of Things (IoT) and Industrial Internet of Things (IIoT) devices has led to an increasingly interconnected mesh of cyber-physical systems (CPS), which expands the attack surface and blurs the once clear functions of cybersecurity and physical security." According to the WEF '' Global Risks Report 2020'', "Operational technologies are at increased risk because cyberattacks could cause more traditional, kinetic impacts as technology is being extended into the physical world, creating a cyber-physical system". According to the
United States Department of Homeland Security The United States Department of Homeland Security (DHS) is the U.S. United States federal executive departments, federal executive department responsible for public security, roughly comparable to the Interior minister, interior, Home Secretary ...
, "The consequences of unintentional faults or malicious attacks n cyber-physical systemscould have severe impact on human lives and the environment." Notable examples of attacks on internet connected facilities include the 2010 Stuxnet attack on Iran's Natanz nuclear facilities and the December 2015 Ukraine power grid cyberattack. “Today’s threats are a result of hybrid and blended attacks utilizing
Information Technology Information technology (IT) is a set of related fields within information and communications technology (ICT), that encompass computer systems, software, programming languages, data processing, data and information processing, and storage. Inf ...
(IT), physical infrastructure, and Operational Technology (OT) as the enemy avenue of approach," notes former CISA Assistant Director for Infrastructure Security Brian Harrell. "Highlighting this future threat landscape will ensure better situational awareness and a more rapid response.”


Organisational convergence

Traditionally distinct, or 'siloed', approaches to physical security and cyber security are viewed by proponents of security convergence as unable to adequately protect an organisation from attacks involving both cyber and physical (cyber-physical) dimensions. The organisational aspect of security convergence focuses on the extent to which an organisation's internal structure is capable of adequately addressing converged security risks. According to the Cybersecurity and Infrastructure Security Agency, "physical security and cybersecurity divisions are often still treated as separate entities. When security leaders operate in these siloes, they lack a holistic view of security threats targeting their enterprise. As a result, attacks are more likely to occur". "Many of the conventional physical and information security risks are viewed in isolation," states a
PricewaterhouseCoopers PricewaterhouseCoopers, also known as PwC, is a multinational professional services network based in London, United Kingdom. It is the second-largest professional services network in the world and is one of the Big Four accounting firms, alon ...
document ''Convergence of Security Risks''. "These risks may converge or overlap at specific points during the risk lifecycle, and as such, could become a blind spot to the organisation or individuals responsible for risk management." In a survey of more than 1,000 senior physical security, cybersecurity, disaster management, and business continuity professionals, th
ASIS Foundation
study ''The State of Security Convergence in the United States, Europe, and India'' found that despite “years of predictions about the inevitability of security convergence, just 24 percent of respondents have converged their physical and cybersecurity functions.” The survey also found that 96 percent of organisations that had converged two or more security functions reported positive results from convergence, with 72 percent reporting that convergence strengthened their overall security. Overall, 78 percent of those surveyed believed that convergence would strengthen their overall security function. Citing the work of Jay Wright Forrester on
systems thinking Systems thinking is a way of making sense of the complexity of the world by looking at it in terms of wholes and relationships rather than by splitting it down into its parts.Anderson, Virginia, & Johnson, Lauren (1997). ''Systems Thinking Ba ...
, Optic Security Group CEO Jason Cherrington argues that a
system of systems The term system of systems refers to a collection of task-oriented or dedicated systems that pool their resources and capabilities together to create a new, more complex system which offers more functionality and performance than simply the sum of ...
approach provides a useful lens to understanding how security sub-groups within an organisation contribute to an organisation's overall security goals. "In an ideal SoS world, organisations would see their security as a collection of task-oriented or dedicated systems that pool their resources and capabilities together as part of an overall system offering more functionality and performance than the sum of its parts. Importantly, oversight of the overall system would ensure that any gaps between its component systems are identified and failures avoided."


Solutions convergence (unified security)

The increasing prevalence of hybridised cyber-physical security threats has driven the parallel emergence of a range of converged security solutions that cover both cyber and physical domains. According to Jason Cherrington, "in contemporary security threats we’re seeing a convergence of physical and digital vectors; and that protection against these hybridised threats requires a hybridised approach." According to the United States Cybersecurity and Infrastructure Security Agency: "Organizations with converged cybersecurity and physical security functions are more resilient and better prepared to identify, prevent, mitigate, and respond to threats. Convergence also encourages information sharing and developing unified security policies across security divisions."


Bibliography

* Anderson, K.,
Convergence: A Holistic Approach to Risk Management
, Network Security, Elsevier, Ltd., Volume 2007, Issue 5, May 2007. * Anderson, K.,
IT Security Professionals Must Evolve for Changing Market
, SC Magazine, October 12, 2006.


References

{{reflist


External links


Alliance for Enterprise Security Risk Management
Security Data security Physical security