Introduction
This management alert details issues the U.S. Postal Service Office of Inspector General (OIG) identified during the Management of the Enterprise Physical Access Control System (ePACS) audit (Project Number 26-023). Our objective is to provide immediate notification regarding insufficient access controls over an ePACS fileshare and system controllers. See Appendix A for additional information about this audit.
Background
To protect its facilities, restricted areas, and information resources, the Postal Service limits access to authorized personnel whose duties require it. To enforce these limits, the Postal Service protects its facilities, restricted areas, and information resources through physical, environmental, and administrative security controls.
A critical component of physical security for plants and other postal facilities is ePACS, a badge-based access control system. Facilities must implement ePACS if they exceed 60,000 square feet, have 200 or more employees, are a mail processing facility, serves as a data or technology center, or if a risk assessment determines there is a need. The ePACS architecture includes physical badge readers, databases to manage user rights and log access history, and controllers to process access decisions and operate door hardware. It is supported by a Security Management System (SMS) — an administrative hub using a graphical user interface that integrates physical badge readers with access control, visitor management, and alarm monitoring.
Add your first comment to this post