Assess physical layers on premises you own, and tune a biometric threshold
Task
Walk the layers of physical security -- perimeter, building, room and the equipment itself -- on premises you are entitled to assess, and record the control at each layer and its weakest point. Then take a set of biometric match scores, compute the false acceptance and false rejection rates at several thresholds, and find the crossover error rate.
Steps
- Write
lab/physical/layers.csvwith headerlayer,control,who_can_pass,weakest_pointfor perimeter, building entrance, the room your computers are in, and the equipment itself. - Record in
lab/physical/tailgating.txtwhere, at your chosen premises, someone could follow an authorised person through, and what control would prevent it. - Create
lab/physical/scores.csvwith headerwho,scoreand these synthetic rows: genuine users scoring 91, 88, 95, 72, 84, 90, 67, 93, 86, 79, and impostors scoring 35, 52, 61, 44, 70, 28, 58, 75, 40, 49. - Write
lab/physical/rates.shthat, for thresholds 50 to 90 in steps of 5, prints the threshold, the false acceptance rate (impostors at or above it) and the false rejection rate (genuine users below it), as percentages, one threshold per line separated by spaces, such as70 20 10. Save its output tolab/physical/rates.txt. - Record in
lab/physical/crossover.txtthe threshold where the two rates are closest, and which threshold you would choose for a server room and why.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
awk -F, 'NR>1 && NF==4 {n++} END {print n" layer(s) assessed"}' lab/physical/layers.csv
grep -c . lab/physical/tailgating.txt
awk -F, 'NR>1 {c[$1]++} END {for (w in c) print w": "c[w]}' lab/physical/scores.csv
grep -E '^70[^0-9]' lab/physical/rates.txt
grep -Eic 'false accept|FAR|lower|stricter|higher' lab/physical/crossover.txt
Four layers assessed, ten genuine and ten impostor scores. At a threshold of 70, two impostors (70 and 75) are accepted and one genuine user (67) is rejected: FAR 20 per cent, FRR 10 per cent. The rates cross between 70 and 75. A server room would choose a stricter threshold, accepting more false rejections to keep false acceptances down.
Notes
Real systems publish FAR and FRR curves from far larger test sets, and the CER is how products are compared. The trade-off is the same at any scale: sensitivity moves errors from one column to the other and never removes them.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.