SANS Security Design
SANS Security Design
This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
ISBN 978-0-626-31167-4
SANS 2220-2-1:2014
Edition 1.2
WARNING
This document references other
documents normatively.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
SANS 2220-2-1:2014
Edition 1.2
Table of changes
Change No. Date Scope
Amdt 1 2005 Amended to change the designation of SABS standards to SANS
standards, to update the introductory paragraph in the normative
reference clause, and to update referenced standards and an act.
Amdt 2 2014 Amended to move reference to national legislation to the foreword,
and to update a referenced standard.
Foreword
This South African standard was approved by National Committee SABS/TC 068, Electrical and
electronic security systems, in accordance with procedures of the SABS Standards Division, in
compliance with annex 3 of the WTO/TBT agreement.
A vertical line in the margin shows where the text has been technically modified by amendment
No. 2.
Reference is made in 4.4.1 and 4.4.2 to the "relevant national legislation". In South Africa, this
means the Compulsory specification for electrical and electronic appliances, as published by
Government Notice No. R. 89 (Government Gazette No. 31844) of 6 February 2009. Amdt 2
Reference is made in 4.5 to the "relevant national legislation". In South Africa, this means the
Telecommunications Act, 1996 (Act No. 103 of 1996). Amdt 2
© SABS
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
SANS 2220-2-1:2014
Edition 1.2
Contents
Pages
Foreword
1 Scope .................................................................................................................................... 3
3 Definitions ............................................................................................................................. 4
4 Requirements ........................................................................................................................ 4
© SABS 1
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
SANS 2220-2-1:2014
Edition 1.2
2 © SABS
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
SANS 2220-2-1:2014
Edition 1.2
Part 2-1:
Access control systems: General characteristics
1 Scope
1.1 This part of SANS 2220 specifies the general characteristics of access control systems.
Specific requirements are given in SANS 2220-2-2 to SANS 2220-2-7.
1.2 Guidance on the planning, design, installation, operation and maintenance of access control
systems is given in SANS 10222-2.
2 Normative references
The following standards contain provisions which, through reference in this text, constitute
provisions of this part of SANS 2220. All standards are subject to revision and, since any reference
to a standard is deemed to be a reference to the latest edition of that standard, parties to
agreements based on this part of SANS 2220 are encouraged to take steps to ensure the use of the
most recent editions of the standards indicated below. Information on currently valid national and
international standards can be obtained from the SABS Standards Division. Amdt 1
IEC 60050-191, International electrotechnical vocabulary – Part 191: Dependability and quality of
service. Amdt 1
SANS 2220-1-7, Electrical security systems – Part 1-7: Intruder alarm systems: Power units.
SANS 2220-2-2, Electrical security systems – Part 2-2: Access control systems – Central
processor.
SANS 2220-2-3, Electrical security systems – Part 2-3: Access control systems – Card readers.
SANS 2220-2-4, Electrical security systems – Part 2-4: Access control systems – Reader
controllers.
SANS 2220-2-5, Electrical security systems – Part 2-5: Access control systems – Biometric readers.
SANS 2220-2-6, Electrical security systems – Part 2-6: Access control systems – Access cards.
SANS 2220-2-7, Electrical security systems – Part 2-7: Access control systems – Barriers.
© SABS 3
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
SANS 2220-2-1:2014
Edition 1.2
SANS 60529/IEC 60529, Degrees of protection provided by enclosures (IP Code). Amdt 1
SANS 60839-1-3/IEC 60839-1-3, Alarm systems – Part 1: General requirements – Section Three –
Environmental testing. Amdt 2
3 Definitions
For the purposes of this part of SANS 2220, the definitions given in SANS 10222-2 apply.
4 Requirements
4.1 Class
Access control systems are classified by the degree of security they provide. The supplier of a
system shall indicate to the purchaser the classification of the products making up the system, the
classification being related to the nature of the risk and the level of security that is to be provided.
For all classes, access codes shall be protected against unauthorized change. Except for class 1
access control systems, access shall be controlled by at least the presentation of an access card to
a card reader that recognizes the access code on or in the card. (In a class 3 system, biometrics
may be used instead of a card.) An access control system shall be of one of the following classes.
A class 1 access control system shall allow access to persons who key in a single common code.
The code may be alphabetic, numeric or alphanumeric.
In a class 2 access control system, each card shall have the same encoded data chosen from at
least 10 000 possibilities.
In a class 3 access control system, each card shall have a system code chosen from at least 200
possibilities and an individual code chosen from at least 10 000 possibilities. It shall be possible to
add cards to or delete cards from the system. The cards shall not be accepted by any system other
than the one in which they are intended to operate. Biometrics on its own may be used instead of a
card. This class of access control system shall incorporate a central control and monitoring system
whereby the central processor software can be used to generate reports on the status of any card.
The overall system shall have sufficient redundancy to achieve an MTBF (mean time between
failures) of 15 000 h, assessed in accordance with IEC 60050-191 and IEC 60300 (all parts).
Amdt 1
4.1.4 Class 4 — Unique access card
In a class 4 access control system, it shall be possible to decentralize the intelligence. Each card
shall have a code chosen from at least ten million possibilities and any attempt to change or modify
the code shall destroy the card. It shall be possible to add cards to or delete cards from the system.
The cards shall not be accepted by any system other than the one in which they are intended to
operate.
4 © SABS
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
SANS 2220-2-1:2014
Edition 1.2
This class of access control system shall incorporate a central control and monitoring system
whereby the central processor software can be used to generate reports on the status of any card.
The overall system shall have sufficient redundancy to achieve an MTBF of 25 000 h, assessed in
accordance with IEC 60050-191 and IEC 60300 (all parts). Amdt 1
4.1.5 Class 5 — Unique access card and personal identification number (PIN)
A class 5 access control system shall have at least the same features as a class 4 system but shall
also use a PIN of at least four digits or use biometrics.
4.2 General
An access control system shall
a) ensure controlled access to and exit from a controlled area and be capable of recording each
transaction,
b) allow easy access for purposes of servicing while restricting opportunities for deliberate
interference,
j) have enclosures for the electrical and electronic circuits and, when relevant, for the operating
mechanism. The enclosures shall, unless otherwise specified, provide protection of class IP41 in
accordance with SANS 60529, and Amdt 1
k) not use components that do not comply with the relevant of SANS 2220-2-2 to SANS 2220-2-7.
4.3 Environmental
All components of an access control system shall be inherently corrosion resistant or otherwise
protected against corrosion. Access control systems intended for use in hostile environments such
as cold stores, plating shops or corrosive atmospheres shall have special protection against the
particular environmental conditions.
4.4 Safety
4.4.1 Access control systems shall comply with the provisions of the relevant national legislation
(see foreword). Amdt 1; amdt 2
4.4.2 Components, e.g. switches, shall comply with the provisions of the relevant national
legislation (see foreword). Amdt 2
© SABS 5
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
SANS 2220-2-1:2014
Edition 1.2
4.4.3 Fixed wiring for access control systems shall comply with the provisions of SANS 10142-1.
Amdt 1
4.4.4 The mechanical construction of any part of the system shall be such that injury caused by
mechanical instability or by moving parts, protruding or sharp edges is prevented.
4.4.5 Where relevant, signal, voltage and electromagnetic radiation levels in readily accessible
areas shall not be dangerous.
All protective devices that are not capable of breaking the prospective short-circuit fault current shall
have appropriate short-circuit back-up protection.
b) to gain access to the electrical circuits, adjustment controls and tamper protection devices
without the tamper protection device causing the component under test to generate an alarm
signal (if relevant),
c) to disable the tamper protection device by means of normally available tools such as knives,
pliers and screwdrivers.
6 © SABS
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
SANS 2220-2-1:2014
Edition 1.2
a) the manufacturer's name, trade name or trademark (the term "manufacturer" includes the
manufacturer, importer or distributor);
c) a serial number;
d) except for access cards, the date of manufacture (codes may be used);
i) the rated maximum ambient operating temperature (ta), if above 50 °C; and
k) clear indications of the manner in which connections are to be made (unless only two terminals
or leads are provided and polarity is not important);
NOTE 1 Where it is impractical to put markings on the component, the relevant information shall be given on
an accompanying data sheet.
NOTE 2 Components intended to be built into other equipment need bear only the manufacturer's name (or
trademark) and the type reference (or catalogue reference).
NOTE 3 In certain cases, the manufacturer's name and the type reference may be replaced by a code
number if agreed upon with the client.
Markings need not be discernible when the component is installed and ready for use, but shall be
visible before the component is installed.
5.2 Information
If the manner of installing components is not obvious, each component of an access control system
shall be supplied together with instructions for the installation of the component. Any component
that may be damaged by reversal of the input polarity shall have this fact stated clearly in the
instructions.
© SABS 7
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
SANS 2220-2-1:2014
Edition 1.2
6.2 Attempt to open the enclosure by the normal means and also with normally available tools
such as knives, pliers and screwdrivers, without causing the component to generate an alarm
condition.
8 © SABS
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
SANS 2220-2-1:2014
Edition 1.2
Annex A
(informative)
Annex B
(informative)
Bibliography
SANS 9001/ISO 9001, Quality management systems – Requirements. Amdt 1
______________
© SABS 9
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.
The standard must reside on an internal network or intranet and may only be used for reference purposes in compliance with SABS
copyright rules. The standard or parts thereof may not be distributed in any form without permission from the SABS.
The objective of the SABS Standards Division is to develop, promote and maintain South African
National Standards. This objective is incorporated in the Standards Act, 2008 (Act No. 8 of 2008).
South African National Standards are updated by amendment or revision. Users of South African
National Standards should ensure that they possess the latest amendments or editions.
The SABS continuously strives to improve the quality of its products and services and would
therefore be grateful if anyone finding an inaccuracy or ambiguity while using this standard would
inform the secretary of the technical committee responsible, the identity of which can be found in
the foreword.
The SABS offers an individual notification service, which ensures that subscribers automatically
receive notification regarding amendments and revisions to South African National Standards.
Tel: +27 (0) 12 428 6883 Fax: +27 (0) 12 428 6928 E-mail: [email protected]
Buying Standards
Contact the Sales Office for South African and international standards, which are available in both
electronic and hard copy format.
Tel: +27 (0) 12 428 6883 Fax: +27 (0) 12 428 6928 E-mail: [email protected]
South African National Standards are also available online from the SABS website
http://www.sabs.co.za
Information on Standards
The Standards Information Centre provides a wide range of standards-related information on both
national and international standards. The Centre also offers an individual updating service called
INFOPLUS, which ensures that subscribers automatically receive notification regarding
amendments to, and revisions of, international standards.
Tel: +27 (0) 12 428 7911 / 0861 27 7227 Fax: +27 (0) 12 428 6928 E-mail: [email protected]
Copyright
The copyright in a South African National Standard or any other publication published by the SABS
Standards Division vests in the SABS or, in the case of a South African National Standard based on
an international standard, in the organization from which the SABS adopted the standard under
licence or membership agreement. In the latter case, the SABS has the obligation to protect such
copyright. Unless exemption has been granted, no extract may be reproduced, stored in a retrieval
system or transmitted in any form or by any means without prior written permission from the SABS
Standards Division. This does not preclude the free use, in the course of implementing the
standard, of necessary details such as symbols, and size, type or grade designations. If these
details are to be used for any purpose other than implementation, prior written permission must be
obtained.
Details and advice can be obtained from the Manager – Standards Sales and Information Services.
Tel: +27 (0) 12 428 6883 Fax: +27 (0) 12 428 6928 E-mail: [email protected]
© SABS. This non-printable standard is exclusively for approved users of the SABS’ Complete Collection of Standards and Related Documents.