Wednesday, May 6, 2020

Dear Manny and Jennifer Free Essays

Good day! Before anything else, my father and I would like to express our deepest gratitude to both of you with regard to the real estate properties information in Phuket, Thailand. Your suggestions were closely considered and after thinking things thoroughly, my father indicated that he would like to buy a hotel that is fully established and is currently in business. Another possibility would be a hotel that is completely erected and would be in full operation in a few months’ time. We will write a custom essay sample on Dear Manny and Jennifer or any similar topic only for you Order Now My father decided on this as he is concerned that it would be difficult if he bought a property that is not yet established since he has very little knowledge about Thailand’s real estate laws and regulations. He also understands the trouble of having to deal with the hotel in Phuket while he is in Hong Kong and so he believes that this is the best way to do it. My father is also wondering about the cost of these properties. Is it possible that the prices be forwarded so that he can decide better? I would like to assure both of you that he is not rushing to buy a property, so please do not worry. He is actually waiting for the best one in the market, and, when the opportunity comes, you can be sure that he will buy it right away. Again, thank you so much for your help. Your efforts are greatly appreciated. Without you two, we would not have been able to look in to this. We hope to hear from soon. Sincerely How to cite Dear Manny and Jennifer, Papers

Monday, May 4, 2020

Legal - Ethical & Professional Issues in Information Security

Question: Discuss about theLegal, Ethical Professional Issues in Information Security. Answer: Introduction Irrespective of the nature of Australian firm, companies are expected to adhere and follow legal and ethical framework as put forward by the Legal Framework. All workers regardless of their field and profession should function within the ethical and legal framework of the country. Companies should also follow ethical norms and implement appropriate legal framework and ensure that employee management is conducted in an ethical way. The essay here discusses legal and ethical framework in the professional environment in Australia with special focus on discussing the risk management in IT sector in Australia (Remley and Herlihy, 2012). Risk of working is common in any business environment. Companies sometimes violate the employee norms and law and thus lead to problem. Employee safety and risk management are key issues in administration demands special evaluation and analysis here in this essay. Body: Everyone in Australian professional environment are expected to function within the boundaries defined by the legal and ethical framework. Legal framework should be followed to eliminate risks and safety oriented issues in the internal working environment. Employees will not work properly if they do not feel safe and secured. Risks could be eliminated in a strategic way by implementing appropriate law and statues (Cohen and Liverman, 2011). While the laws of the country restricts and strictly mention the specific behaviour of the employee and management in a unique way, ethics, however defines codes of socially accepted behaviour and how one should present himself in the society. Ethics include cultural codes and also introduced customs as and when necessary. Laws however, need to be approved by the authority before implementation. Ethics are not always legally approved and hence could be implemented by the governing authority (Chase, 2015). For instances the following statues; Privacy Act (Commonwealth) 1988 Privacy Amendment Act 2000 Some of the most important laws followed here are; Workplace health and safety act Anti-Discrimination Act Equal Employment Opportunity Environmental Standards Duty of Care Privacy Act Data Privacy Act Work place safety is of tremendous importance as this act helps in developing safety and security of the employee. When the employee is safe and secured in the work environment he would automatically work properly and ensure business development in a defined way. After going through the norms mentioned by ACS book I put forward the following approach that could be considered for managing work environment. ACS Code of Ethics strictly highlights ways of improving professional work environment in an ethical way by following honour, dignity and effectiveness to the core (Hartman, 2011). Though this apparently seems possible, in a practical environment the supervisor may lead to a difficult situation which shall be impossible to overcome by a junior administrator. In such critical situations following the ACS codes and adhering to ethical norms will help in getting an edge in the situation and overcome the problem in a defined way, Such a system was not followed and rules were violated. The law also mentioned ways of evolving as a good and responsible citizen in the Australian society. Thus law is Australian society is unique and motivates and support performance of the employees within the company in a defined way. It also helps the management to understand and implement activities as per legal norms and follow ethical approaches to improve overall functionality of the business management in a defined way (Susilo and Mu, 2014). Conclusion: Ethical codes and legal framework are to be followed by every company and ensure employee involvement and employee safety. Developing a safe and risk free work environment automatically attracts employees towards the company and when knowledgeable and productive employees join the company it automatically enhances its performance in a defined way. Hence, companies adopt various ethical and legal frameworks to ensure improvement in production and employee performance. References Chase, Y. (2015). Professional Ethics: Complex Issues for the Social Work Profession.Journal of Human Behavior in the Social Environment, 25(7), pp.766-773. Cohen, H. and Liverman, C. (2011).Certifying personal protective technologies. Washington, D.C.: National Academies Press. Hartman, L. (2011).Perspectives in business ethics. Boston: McGraw-Hill. Remley, T. and Herlihy, B. (2012).Ethical, legal, and professional issues in counseling. Susilo, W. and Mu, Y. (2014).Information Security and Privacy. Cham: Springer International Publishing.

Sunday, March 29, 2020

A.J. Hackett Swott Analysis free essay sample

ThStrengthsLeveragesConcerns †¢Sole bungy operator within New Zealand since 1988. †¢Unparalleled safety record and reputation: 0 serious injuries. †¢Locations amidst NZ’s best natural landmarks protected by the Department of Conversation = $175,000 of government funding spent on nearby landscape upkeep and improvements. †¢Ability to gain worldwide public/media attention through the use of unique marketing strategies e. g. Eiffel Tower bungy stunt, free naked bungy campaign etc. †¢Unique corporate culture and charismatic leader: employee turnover rate in 2006 = 7. 4%, half the industry average. Actual jumpers account for only half of all visitors to Hackett jump sites. There is clearly an underlying interest in the surroundings as well as the jump process and history. †¢Use reputation as a way of leveraging better competitor relations and take advantage of mass marketing, promotion and package deals. †¢Target ‘green’ markets: buil d bungy awareness and attract new segments to the jump sites. †¢With such a unique corporate culture and well established reputation there is potential for safety standards to drop. We will write a custom essay sample on A.J. Hackett Swott Analysis or any similar topic specifically for you Do Not WasteYour Time HIRE WRITER Only 13.90 / page †¢With declining tourist numbers there is potential for DOC to remove a portion of its funding WeaknessesConstraintsProblems Newly appointed marketing team of six, all of which have never worked for the company at a corporate level = lack of internal experience and knowledge. †¢Heavy reliance upon international tourists: 78% of sales in 2006. †¢No evidence of product innovation and evolvement since inception = old and outdated formula. †¢Poor publicly accessible Hackett transportation combined with a low proximity to central city and lodgings: No jump sites within a 20 minute commute of downtown Queenstown. †¢Irregularly updated and complex website: the international face of the business is impaired. Limited accessibility and convenience for potential jumpers. †¢Increasing profit margins and external funding should have resulted in a strong business foundation, yet with a poor website and small inexperienced marketing team there is clearly some poor decision making being undertaken at a management level. †¢As successful industry leaders there is a tendency to become too comfortable and set in your ways as demonstrated by the lack of innovation. Hackett is heavily targeted, without change, their position as bungy leaders will be eclipsed. †¢The heavy reliance upon international ourists and the recent and expected future decline in their growth may force Hackett to explore other markets. Bibliography: â€Å"Bungee Jumping.

Saturday, March 7, 2020

POLYETHENEaint is choice essays

POLYETHENEaint is choice essays Polyethene also known as polyethylene or polythene, was the first of the polymers to be discovered. Polyethene is a polymer produced by reacting oxygen and ethene, in this reaction the small ethene molecules attach together to form long chain polymer molecules. This process is known as addition polymerisation. Polyethene in our world today has many uses, some of these are: mouldings-plastic bottles, lids and caps, different types of containers. films-glad wrap and various plastic bags. cable coverings-various pipes and insulating wire and cables As you can see polyethene has a huge variety of both domestic and industrial uses, this is fairly impressive when you see that polyethene has only been around sense 1933. Polyethene is a thermoplastic material which is often described as wax-like it is extremely tough and is has an excellent chemical resistance. It is also less dense than water and is the simplest polymer, these attributes lead to polythene being an extremely useful substance. Ethene (C2H4), is a simple hydrocarbon molecule which consists of 2 carbon atoms and 4 hydrogen atoms. Ethene's main use is in the production of polythene yet it is one of the most widely used petrochemicals in the world. Ethene is an unsaturated colourless gas which can be ignited in the presence of oxygen. Polyethene is produced by allowing the free roaming ethene gas molecules to bond together to form long chain polyethene molecules. In order for this to work a catalyst must be used, a catalyst is a substance that can alter the rate of a chemical reaction without undergoing any chemical change itself. During this process thousands of ethene molecules bond to from each molecule of polyethene. Polyethene is simply a set of ethene molecules bonded together to form a chain, these chains can often stretch up to many many times longer than the original ethene molecule. Although normally ethene monomers have...

Wednesday, February 19, 2020

Biology - Wood Frog Essay Example | Topics and Well Written Essays - 1000 words

Biology - Wood Frog - Essay Example For example, it has a moderate size up to two inches or two to three inches long ("Wood Frog - Rana Sylvatica: Minnesota DNR" ), and it has a smooth, moist and reddish skin. Moreover, it is cold blooded and can tolerate a large temperature and saves the water inside the body for the later usage for example, in some cases, up to 65% of the whole body water. Additionally, wood frog has webbed feet just as other amphibians but it does not have fully webbed feet. Moreover, it has a vertebra that is why it is usually identified as vertebrates; it also has notochord which identifies for the Chordates. It can live in water as well as in soil and it can lay eggs in water as well as in the soil. Furthermore, its eggs does not have any membrane which makes them amphibians, males and female frogs gather in ponds for reproduction, skin coloration is brown, and they also go to ponds and water lands for breeding. Moreover, its sound can be heard in the first periods of the spring and they have dar k pitch under their eyes The relationship between the wood frog and other organisms can be reflected by the fact that wood frog belongs to Kingdom Animal which is the broadest category of classification. This is because of the fact that most of the animals that are categorized as â€Å"animals† have some specific characteristics which are common to them. For example, organisms that are characterized as â€Å"animals† are eukaryotic i.e. the animals that have developed cell membrane and complex cell structures, for example plants, fungi etc. Moreover, organisms in Kingdom Animal are â€Å"motile† which means that they can freely move from one place to the other. The examples include snack, lion, deer etc. These are all animals and have common characteristics with the wood frog because they are all under Kingdom Animal. The second category of classification is the Phylum which is Phylum Chordates in case of the wood frog. Furthermore, the animals in Phylum Chordat es are identified with their Notochord which they have at least for some period of their lives, a hollow dorsal nerve chord, and an anal tail etc. Besides this, notochord is the flexible and rod shaped body which is found in the early embryos and, in some cases, becomes the axial support of the body. Similarly, the animals in Phylum Chordates include Hagfish, Star fish and lancelet etc. and these animals have the common characteristic with the wood frog that they all have notochord, a hollow dorsal nerve chord and an anal tail. In this way, wood frog is more closely related and associated with the animals of Phylum Chordates because they have many common characteristics. The third category of classification includes Class which is Amphibians in case of wood frog. The basic characteristics of amphibians are that their eggs are not surrounded by membranes, they have four limbs and they are cold blooded. For example, toads, salamanders etc. are the vertebrate chordates that have same c haracteristics as wood frog. In this way, wood frog is far more linked and has similarity with animal chordates such as salamanders, toads because they are in the same class and have similar characteristics. Similarly, wood frog is also associated with many other amphibians due to their order which is anura and family which is Ranidae. Moreover the common genre and species

Tuesday, February 4, 2020

Analysis of the Movie Exorcist Essay Example | Topics and Well Written Essays - 500 words

Analysis of the Movie Exorcist - Essay Example The documentary-like and gritty feel of the film also gives an added realistic mood and that might signify the reality of everyday life. Damien Karras is the main character who is both a psychiatrist and a priest. He is depicted as a torn man with doubts that are wiped away once he confronts the Devil. The scene where he visits Regan and records her growling voice while speaking to each other in Latin is probably the only humorously peculiar scene in the entire movie The trend towards more graphic violence in movies parallels the transition of the general viewing audience to a higher shock level. The audience is shocked by physical harm for instance fist fights or slapping, movie monsters like demon Pazuzu, urination scenes and vomit, gratuitous blood scenes. These scenes are supported with green projectile vomit, spinning heads, shaking beds and gross makeup. The movie is full of graphic domestic violence, documentary film violence (executions and accidents) and the desecration of the Virgin Mary. Expansive landscapes of death and demons walking like horrible spiders add the impression of the Beyond. From the emergence of the Hammer horrors on films have shocked the audience further by the fact that evil is so often allowed to triumph at the end of more recent films is as much connected with this change in the tolerance threshold as with the incidence of a darker, more pessimistic outlook on life. Sound effects play an important role in heating up the atmosphere of constant horror.  For instance, the slingshot sound effect and shadows create the impression of something terrible and unknown.

Monday, January 27, 2020

Advantages and Disadvantages of Biometrics

Advantages and Disadvantages of Biometrics ABSTRACT Organisations have goals and therefore acquire assets to ensure these goals are met and the continuity guaranteed. Financial sector while trying to promote convenient methods such as online banking and use of ATM for their customers to access their money strives to ensure only the right person has access to the account. Also, military and national security services store high sensitive and critical information that must only be accessed by specific individual thereby deploying security measures to keep this tradition. However, achieving these goals largely depends on securing and controlling the assets as documented which means only authorised individuals have access to these environments and eventually the assets. Sequel to the importance of access control, different security techniques have been deployed to safeguard these assets which ranges from PINs and passwords, ID cards, smart card est. Vulnerabilities to these methods have lead to the recent surge in biometrics industry as many believe this is the future. Reasons such that the physical presence of the authorized person is needed at the point of access and also, the fact that it is unique and almost impossible to duplicate emphasis the benefit of biometrics and explain its glooming popularity. However like any other security methods, biometrics has limitations and threats which can impact its effectiveness and efficiency. It is not suitable for every application and can be a very wrong choice for certain applications. Therefore, it is essential to manage these limitations and threats properly to enhance the success factor of biometrics. Finally, it is important for any sector deploying biometrics to understand the various issues associated with biometrics such as privacy, standards and what the law requires of biometrics. CHAPTER ONE INTRODUCTION Organizations strive to secure their assets and provide means of controlling access to these assets. This process requires identification and authorization to ensure the right person is accessing the right asset. Over the years, traditional methods of authentication, mainly passwords and personal identification numbers (PINs) have been popularly used. Recently, swipe card and PINs have been deployed for more security since one is something you have and the latter something you know. However, these methods still have vulnerabilities as swipe card can be stolen. Also, bad management of passwords has left people writing them on papers and desks or simply choosing easy and general words for quick remembrance which expose the password to intruders. More recently, stronger identification and authorization technologies that can assure a person is who he claims to be are becoming prominent and biometrics can be classified to this category. Biometric technology makes use of a persons physiological or behavioral characteristics in identification. Every human being is unique in nature and possesses physical parts completely different from any other person. The September 11, 2001 terrorist attack did not help security concerns as governments and organizations all around the world especially the border security agencies have greatly embraced this human recognition technology. As both private and public entities continue to search for a more reliable identification and authentication methods, biometrics has been the choice and considered the future. WHAT IS BIOMETRICS? Biometrics refers to the automatic identifications of a person based on his or her physiological or behavioral characteristics (Chirillo and Blaul 2003, p. 2). It is an authorization method that verifies or identifies a user based on what they are before authorizing access. The search for a more reliable authorization method to secure assets has lead to the revelation of biometrics and many organizations have shown interest in the technology. Two main types of biometrics have been used mainly physical and behavioral. A physical biometrics is a part of a persons body while, a behavioral biometric is something that a person does (Lockie 2002, p. 8). He added that although there are some more unusual biometrics which may be used in the future, including a persons unique smell, the shape of their ear or even the way they talk, the main biometrics being measured include fingerprints, hand geometry, retina scan, iris scan, facial location or recognition (all physical), voice recognition, signature, keystroke pattern and gait (Behavioral). However, it has been argued by Liu and Silverman (2001) that different applications require different biometrics as there is no supreme or best biometric technology. HISTORY OF BIOMETRICS According to Chirillo and Blaul (2003, p. 3) the term biometrics is derived from the Greek words bio (life) and metric (to measure). China is among the first known to practice biometrics back in the fourteenth century as reported by the Portuguese historian Joao de Barros. It was called member-printing where the childrens palms as well as the footprints were stamped on paper with ink to identify each baby. Alphonse Bertillon, a Paris based anthropologist and police desk clerk was trying to find a way of identifying convicts in the 1890s decided to research on biometrics. He came up with measuring body lengths and was relevant till it was proved to be prone to error as many people shared the same measurement. The police started using fingerprinting developed based on the Chinese methods used century before by Richard Edward Henry, who was working at the Scotland Yard. Raina, Orlans and Woodward (2003, p. 25-26) stated references to biometrics as a concept could be traced back to over a thousand years in East Asia where potters placed their fingerprints on their wares as an early form of brand identity. They also pointed Egypts Nile Valley where traders were formally identified based on physical characteristics such as eye color, complexion and also height. The information were used by merchant to identify trusted traders whom they had successfully transacted business with in the past. Kapil et al also made references to the Bible, first pointing to the faith Gileadites had in their biometric system as reported in The Book of Judges (12:5-6) that the men of Gilead identified enemy in their midst by making suspected Ephraimites say Shibboleth for they could not pronounce it right. The second reference is to The Book of Genesis (27:11-28) where Jacob pretended to be Esau by putting goat skins on his hands and back of his neck so his skin would feel h airy to his blind, aged fathers touch. This illustrates a case of biometric spoofing and false acceptance. They finally wrote Biometrics as a commercial, modern technology has been around since the early 1970s when the first commercially available device was brought to market (p. 26). HOW BIOMETRICS SYSTEMS WORK A biometric system is essentially a pattern-recognition system that makes a personal identification by determining the authenticity of a specific physiological or behavioral characteristics possessed by the user (Blaul 2003, p.3). Biometrics has so far been developed to work in two ways mainly verification and identification. Verification systems are designed to give answer to the question, Am I who I claim to be? by requiring that a user claim an identity in order for a biometric comparison to be performed. The user provides data, which is then compared to his or her enrolled biometric data. Identification systems gives answer to the question, who am I? and do not require a user to claim an identity as the provided biometric data is compared to data from a number of users to find a match (Nanavati 2002, p. 12). An illustration of a scenario using an identifying biometrics system is given below and thus gives an answer to the question Who am I? In October 1998 in the United Kingdom, Newham Council introduced face recognition software to 12 town centre cameras with the sole purpose of decreasing street robbery. Images are compared against a police database of over 100 convicted street robbers known to be active in the previous 12 weeks. In August 2001, 527,000 separate faces were detected and operators confirmed 90 matches against the database. Where a face is not identified with any in the database, the image is deleted; if a match is found a human operator checks the result. The introduction of face recognition technology to Newham city centre saw a 34% decrease in street robbery. The system has not led directly to any arrests, which suggests that its effect is largely due to the deterrence/displacement of crime. The face recognition system has been widely publicised by the council and 93% of residents support its introduction (Postnote Nov 2001, p. 1). The case study below illustrates a verifying biometrics system and supply answers to the question Am I who I claim to be? The US Immigration and Naturalization Service Passenger Accelerated Service System (INSPASS) has been introduced at eight airports in order to provide a quick immigration processing for authorised frequent flyers entering the US and Canada. On arrival at an airport, a traveller inserts a card that carries a record of their hand geometry into the INSPASS kiosk and places their hand on a biometric reader. A computer cross-references the information stored on the card at registration with the live hand geometry scan. The complete process takes less than 30 seconds. If the scans match, the traveller can proceed to customs; if not, travellers are referred to an Immigration Inspector. There are more than 45,000 active INSPASS users with, on average, 20,000 automated immigration inspections conducted each month (Postnote Nov 2001, p. 1). Verifying system is often referred to as a one-to-one process and generally takes less processing time compared to the identifying systems. This is due to the fact that in identifying systems, a user is compared to all users in the database (one-to-many). Verifying systems are also more accurate since they only have to match a users data against his or her stored data and do not need hundreds, thousands or even millions of comparisons like the identifying systems. However, it is important for an organization to decide the type appropriate for the applications. RESEARCH METHODOLOGY The research methodology designed for this dissertation is mainly the qualitative approach. A quantitative approach has been overlooked due to limited time as designing surveys, distribution take time and response time could not be predicted. Therefore, my effort will be concentrated on critically reviewing previous literatures in order to acquire an overview of, and intakes on the topic. For more details, Journals, Books, Publications, Documentaries and previous dissertations related to the topic will be reviewed, compared and analyzed. The objectives will be achieved by purely reviewing literatures and previous researches and the literatures critically analyzed by comparing information obtained from different sources. Findings, recommendations and conclusions will be made from the analysis. OBJECTIVES OF THE STUDY The aim of this research is to critically analyse biometric security as an emerging and booming industry by examining the positives and negatives and providing ways of improving the method effectively and most importantly efficiently. Since biometrics applies to many applications, access control will be the main focus of this dessertation. Also, issues such as privacy, laws governing biometrics and standards will be examined. The main objectives of this research are; To review biometric security and issues related to it. To evaluate the threats, advantages and disadvantages of biometrics. To propose ways of improving the effectiveness and efficiency of biometrics from previous researches. CHAPTER 2 LITERATURE REVIEW This chapter is aimed at critically reviewing and analysis of numerous works of researchers in the area of biometrics, threats to biometrics, advantages and disadvantages and ways of improving biometrics efficiency in access control. The effect of privacy (human rights) and the need to conform to biometrics standards will also be examined and reviewed. DEFINITION OF BIOMETRICS According to Jain, Ross and Pankanti (2006, p. 125), one great concern in our vastly interconnected society is establishing identity. Systems need to know Is he who he claims he is, Is she authorized to use this resource? or simply who is this? Therefore, a wide range of systems require reliable personal recognition schemes to either verify or identify of an individual seeking access to their services. The purpose of that scheme is to ensure that the rendered services are accessed by only the authorized and not any intruder or imposer (Ross 2004, p. 1). Biometric recognition, or simply biometrics, refers to the automatic recognition of individuals based on their physiological and, or behavioral characteristics (Jain, 2004 p. 1). Woodward (2003, p. 27) cited biometric industry guru Ben Millers 1987 biometric definition: Biometric technologies are automated methods of verifying or recognizing the identity of a living person based on a physical or behavioral characteristic. Shoniregun and Crosier (2008, p. 10) provided several definitions of biometrics which include: Biometrics is the development of statistical and mathematical methods applicable to data analysis problems in the biological science. Biometrics = identification/verification of persons based on the unique physiological or behavioral features of humans. Biometrics is the measurement and matching of biological characteristics such as fingerprint images, hand geometry, facial recognition, etc. Biometrics is strongly linked to a stored identity to the physical person. Nevertheless the various definitions, it can be seen that the science of biometrics is based on the fact that no two people are the same and this has a significant influence on its reliability and success factor. THE BIOMETRICS INDUSTRY According to Lockie (2002, p. 10), the biometric industry did not really get established until the middle of the twentieth century. The researchers at that particular time were investigating whether various human parts and characteristics, such as the iris or the voice, could be used to identify an individual. This was made public by publishing papers and as a considerable number of these strands of research began to form a piece, the biometrics industry as we know it these days was established. As organization search for more secure authentication methods for user access, e-commerce, and other security applications, biometrics is gaining increasing attention (Liu 2001, p.27). Higgins, Orlan and Woodward (2003, p. xxiii ), emphasized that even though biometrics have not become an essential part of all systems requiring controlled access, the emerging industry has come a long way from its modern founding in 1972 with the installation of a commercial finger measurement device on Wall Street. He made reference to the highly respected MIT Technology Review called biometrics one of the top ten emerging technologies that will change the world. The growth in biometric industries is reflected in the numbers. The trio cited Rick Noton, the executive director of the International Biometric Industry Association (IBIA), who reported in the Biometrics 2002 Conference in London, United Kingdom, that the industrys trade association has indicated the surge in biometric revenues over recent years. From $20 million in 1996, it has increased to $200 million in 2001 and Norton believes they will increase as the years pass on significantly in 5 years time. Also, a forecast made by the International Biometric Group (IBG), which is a biometric consulting and integration firm located in New York City, estimate that biometric revenues totaled $399 million in 2000 and will increase to $1.9 billion by 2005. Both IBIA and IBG believe that the private sector will be responsible for much of the growth. These give evidence of the relevance of biometrics in organizations in modern times. BIOMETRICS AND ACCESS CONTROL Over the years, biometrics has evolved rapidly and many vertical markets such as governments, transport, financial sectors, security, public justice and safety, healthcare and many more have adopted biometrics. Due to this wide range of users, biometrics has been deployed to many applications. Biometrics has been of high benefit to organization as they seek a reliable security method to safeguard assets. Fully understanding how biometrics work, it can be said that the ultimate aim of applying biometrics in the vertical markets listed above is to control access to a resource irrespective of the system used whether a verifying or an identifying process It has been stated by S. Nanavati, Thieme and R. Nanavati (2002, p. 14), that biometric systems are deployed for two primary purposes which are physical and logical access. LOGICAL VERSUS PHYSICAL ACCESS Physical access systems monitors, restricts, or grant movement of a person or object into or out of a specific area (Thieme 2002, p. 14). This could be implemented to control entry into rooms or even the main building. Popular examples are control towers, bank vaults, server rooms and many other sensitive rooms requiring controlled access. In physical access, biometrics replaces the use of keys, PIN codes access cards and security guards although any of these could be combined with biometrics as a complementation. Common physical access application is time and attendance. Thieme also gave a definition of logical access systems as one that monitor, restrict or grant access to data or information listing examples such as logging into a PC, accessing data stored on a network, accessing an account, or authenticating a transaction. In this case, biometrics replaces and can be designed to complement PINs, passwords and also tokens. Basic biometric functionality precisely acquiring and comparing of biometric data is often identical in both physical and logical systems. For example, the same iris scan data can be used for both doorway and desktop applications. Thieme explained that the only difference between the two is the external system into which the biometric functionality is integrated. The biometric functionality is integrated into a larger system. This applies for both physical and logical access system and actions such as access to any desktop application or access to a room via a doorway are effected by a biometric match. However, not every system can be classified as physical or logical access as the end result does not indicate access to data or a physical location and the result therefore may be to investigate more. An ATM secured by biometrics allows access to money, a physical entity. This is made possible by allowing the user logical access to his or her data. In the example above, the application is even difficult to classify as either physical or logical. Thieme (2002, p. 15) suggested that the distinction between physical and logical access systems is a valuable tool in understanding biometric. He noted that key criteria such accuracy, fallback procedures, privacy requirements, costs, response time and complexity of integration all vary effectively when moving from logical to physical access. WHAT ARE BIOMETRIC STANDARDS Stapleton (2003, p. 167) defined a standard in a general term as a published document, developed by a recognized authority, which defines a set of policies and practices, technical or security requirements, techniques or mechanisms, or describes some other abstract concept or model. The growth of the biometric industry has been relatively slowed by the absence of industry wide standards and this has also impeded various types of biometric deployment. Nanavati (2002, p. 277) stated that the relative youth of the technology in use, coupled with the disunified nature of the industry, has impacted the developments of standards resulting in a sporadic and frequently redundant standards. Nanavati also noted that the live-scan fingerprint imaging is the only segment of biometric industry with widely accepted and adopted standards. Due to this absence of biometric standards, some institutions have been concerned of being tied into technologies they actually believed as not mature or even dev elopmental. However in an effort to actively address the standards issue, the biometric industry has finalized some blueprints and the process of getting industries to accept these standards is ongoing WHY IS STANDARDIZATION NECESSARY? The high rate of biometric development and rapid growth in adoption of biometric technologies in recent years has resulted in ever-increasing levels of what is expected in terms of accuracy, adaptability, and reliability in an ever-wider range of applications. Due to the adoption of biometric technologies in large-scale national and international applications, involving a potentially unlimited range of stakeholders, Farzin Deravi (2008, p. 483) stated that it has become essential to address these expectations by ensuring agreed common frameworks for implementation and evaluation of biometric technologies through standardization activities. Majority of biometric systems, including both the hardware and software are made and sold by the owner of the patent at this stage in their development. They are being proprietary in numerous aspects including the manner in which biometric devices and systems as a whole communicate with applications, the method of extracting features from a biometric sample, and among many more, the method of storing and retrieving biometric data. This resulted in many companies in most cases, being wedded to a particular technology, once they agree to implement that particular technology. Nanavati (2002, p. 278) stated that in order to incorporate a new technology, the companies are required to rebuild their system from scratch upward, and in some cases duplicating much of the deployment effort. Deravi (2008 p. 483) noted that the need for interoperability of biometric systems across national boundaries has implied a rapid escalation of standardization efforts to the international arena, stating that the sense of urgency for the need for standardization has been the priority of internal security concerns. The industry wide or universal adoption of biometric standard will not make biometric technology interoperable at least, to the state where an old device can be replaced by a new device without rebuilding the system. However, Nanavati (2002 p. 278) argued the core algorithms through which vendors locate and extract biometric data are very unlikely to be interoperable or standardized, the reason being that these algorithms represents the basis of most vendors intellectual property. Numerous reasons are responsible for the motivation towards standardization. These include the desire for reducing the overall cost of deploying biometrics technologies and optimize the reliability of biometric systems, to reduce the risk of deploying solutions to biometric problems, to ensure in the area of encryption and file format, that the basic building blocks of biometric data management have been developed based on best practice by industry professionals. Nanavati (2002 p. 278) concluded that standards ensure that, in the future, biometric technology will be developed and deployed in accordance with generally accepted principles of information technology. EXISTING BIOMETRIC STANDARDS Shoniregun and Crosier (2008 p. 22) stated that the evolving interest and developments have made developments of standards a necessity with the sole aim of allowing compatibility of different systems. The detailed standards in the Biometrics Resource Centre (2002) report are summarised below: Common Biometric Exchange File Format (CBEFF): The Common Biometric Exchange File Format (CBEFF) sets a standard for the data elements essential in supporting biometric technology in a common way irrespective of the application involved or the domain in use. It makes data interchange between systems and their components easier, while promoting interoperability applications, programs as well as systems based on biometrics. INCITS MI-Biometrics Technical Committee: The committee which was established by the Executive Board of the International Committee for Information Technology standards (INCITS) with the responsibility to ensure a focused and reasonably comprehensive approach in the United States for the rapid development and approval of previous national and international generic biometric standards (Shoniregun ad Crosier 2008, p. 22) BioAPI Specification (Version 1.1): The BioAPI standard defines the architecture for biometric systems integration in a single computer system. (Deravi 2008, p. 490). The Bio API specification has been one of the most popular standards efforts since it was formed in April 1998 according to Nanavati (2002, p. 279). Nnavati stated that the standard was formed to develop an API that is both widely accepted and widely available while being compatible with various biometric technologies. Other general standards available are Human Recognition Module (HRS), ANSI/NIST-ITL 1-2000, American Association for Motor Vehicle Administration and American National Standards Institute (ANSI) which specifies the acceptable security requirements necessary for effective management of biometric data especially for the financial services industry. BRITISH BIOMETRICS STANDARDS The British Standards Institution (BSI) commenced work in June 2004 on biometrics standards and since then, has published according to Shoniregun and Crosier (2008, p. 24) a set of four new BS ISO/IEC 19794 STANDARDS, reported to have covered the science of biometrics, and using biological characteristics in identifying individuals. The objective of publishing these standards is to promote interoperability between the several products in the market. BS ISO/IEC 19784-2:2007: This standard defines the interface to an archive Biometric Function Provider (BFP). The interface assumes that the collected biometrics data will be managed as a database, irrespective of its physical realization. Crosier (2008, p. 24) defined the physical realization as smartcards, token, memory sticks, files on hard drives and any other kind of memory can be handled via an abstraction layer presenting a database interface.) BS ISO/IEC 19795-2:2006: According to Shoniregun (2008, p. 25), this standard provides recommendations and requirements on collection of data, analysis as well as reporting specific to two types of evaluation (scenario evaluation and technology evaluation). BS ISO/IEC 19795-2:2006 further specifies the requirements in the development and full description of protocols for scenario and technology evaluations and also, in executing and reporting biometric evaluations. BS ISO/IEC 24709-1:2007: ISO/IEC 24709-1:2007 specifies the concepts, framework, test methods and criteria required to test conformity of biometric products claiming conformance to BioAPI (ISO/IEC 19784-1). (www.iso.org). Crosier (2008, p. 25) stated ISO/IEC 24709-1:2007 specifies three conformance testing models which allows conformance testing of each of the BioAPI components mainly a framework, an application and a BSP. BS ISO/IEC 24709-2:2007: The standard BS ISO/IEC 247 defines a number of test assertions composed in the assertion language explicitly required in ISO/IEC 24709-1. The assertions allow a user to test the conformance of any biometric server producer (BSP) that claims to be a conforming implementation of that International Standard to ISO/IEC 19784-1 (BioAPI 2.0) (www.iso.org). BIOMETRICS AND PRIVACY The fact that biometric technologies are based on measuring physiological or behavioral and archiving these data has raised concerns on privacy risks, and also raised discussion on the role biometrics play when it comes to privacy. As stated by Nanavati (2002, p. 237), increase in the use of biometric technology in the public sector, workplace and even at home has raised the following questions: What are the main privacy concerns relating to biometric usage? What kinds of biometric deployments need stronger protections to avoid invading privacy? What biometric technologies are more prone to privacy-invasive usage? What kinds of protections are required to ensure biometrics are used in a non privacy-invasive way? Woodward (2003, p. 197) cited President Clintons speech in his commencement address at Morgan State University in 1997: The right to privacy is one of our most cherished freedomsWe must develop new protections for privacy in the face of new technological reality. Recently, Biometrics has been increasingly deployed to improve security and a very important tool to combat terrorism. Privacy issue is central to biometrics and many people believe that deploying biometrics poses a considerable level of risk to human rights, even though some are of the opinion that biometrics actually protect privacy. Human factors influence the success of a biometric-based identification system to a great extent. The ease as well as comfort in interaction with a biometric system contributes to how people accept it. Jain, Ross and Prabhakar (2004 p. 24) stated an example of a biometric system being able to measure the characteristic of a users without touching, such as those using voice, face, or iris, and concluded that it may be perceived to be a more user-friendly and hygienic system by the users. They added that on the other hand, biometric characteristics not requiring user participation or interaction can be recorded without the knowledge of the user, and this is perceived as a threat to human privacy by many individuals. According to Sim (2009, p. 81), biometrics compared to other security technologies has significant impacts on users privacy (Civil Liberties). It can protect privacy when deployed in an appropriate manner; but when misused, it can result in loss of privacy. ADVANTAGES OF BIOMETRIC OVER TRADITIONAL METHODS Password and PINs have been the most frequently used authentication method. Their use involves controlling access to a building or a room, securing access to computers, network, the applications on the personal computers and many more. In some higher security applications, handheld tokens such as key fobs and smart cards have been deployed. Due to some problems related to these methods, the suitability and reliability of these authentication technologies have been questioned especially in this modern world with modern applications. Biometrics offer some benefits compare to these authentication technologies. INCREASED SECURITY Biometric technology can provide a higher degree of security compared to traditional authentication methods. Chirillo (2003 p. 2) stated that biometrics is preferred over traditional methods for many reasons which include the fact that the physical presence of the authorized person is required at the point of identification. This means that only the authorized person has access to the resources. Effort by people to manage several passwords has left many choosing easy or general words, with considerable number writing the Advantages and Disadvantages of Biometrics Advantages and Disadvantages of Biometrics ABSTRACT Organisations have goals and therefore acquire assets to ensure these goals are met and the continuity guaranteed. Financial sector while trying to promote convenient methods such as online banking and use of ATM for their customers to access their money strives to ensure only the right person has access to the account. Also, military and national security services store high sensitive and critical information that must only be accessed by specific individual thereby deploying security measures to keep this tradition. However, achieving these goals largely depends on securing and controlling the assets as documented which means only authorised individuals have access to these environments and eventually the assets. Sequel to the importance of access control, different security techniques have been deployed to safeguard these assets which ranges from PINs and passwords, ID cards, smart card est. Vulnerabilities to these methods have lead to the recent surge in biometrics industry as many believe this is the future. Reasons such that the physical presence of the authorized person is needed at the point of access and also, the fact that it is unique and almost impossible to duplicate emphasis the benefit of biometrics and explain its glooming popularity. However like any other security methods, biometrics has limitations and threats which can impact its effectiveness and efficiency. It is not suitable for every application and can be a very wrong choice for certain applications. Therefore, it is essential to manage these limitations and threats properly to enhance the success factor of biometrics. Finally, it is important for any sector deploying biometrics to understand the various issues associated with biometrics such as privacy, standards and what the law requires of biometrics. CHAPTER ONE INTRODUCTION Organizations strive to secure their assets and provide means of controlling access to these assets. This process requires identification and authorization to ensure the right person is accessing the right asset. Over the years, traditional methods of authentication, mainly passwords and personal identification numbers (PINs) have been popularly used. Recently, swipe card and PINs have been deployed for more security since one is something you have and the latter something you know. However, these methods still have vulnerabilities as swipe card can be stolen. Also, bad management of passwords has left people writing them on papers and desks or simply choosing easy and general words for quick remembrance which expose the password to intruders. More recently, stronger identification and authorization technologies that can assure a person is who he claims to be are becoming prominent and biometrics can be classified to this category. Biometric technology makes use of a persons physiological or behavioral characteristics in identification. Every human being is unique in nature and possesses physical parts completely different from any other person. The September 11, 2001 terrorist attack did not help security concerns as governments and organizations all around the world especially the border security agencies have greatly embraced this human recognition technology. As both private and public entities continue to search for a more reliable identification and authentication methods, biometrics has been the choice and considered the future. WHAT IS BIOMETRICS? Biometrics refers to the automatic identifications of a person based on his or her physiological or behavioral characteristics (Chirillo and Blaul 2003, p. 2). It is an authorization method that verifies or identifies a user based on what they are before authorizing access. The search for a more reliable authorization method to secure assets has lead to the revelation of biometrics and many organizations have shown interest in the technology. Two main types of biometrics have been used mainly physical and behavioral. A physical biometrics is a part of a persons body while, a behavioral biometric is something that a person does (Lockie 2002, p. 8). He added that although there are some more unusual biometrics which may be used in the future, including a persons unique smell, the shape of their ear or even the way they talk, the main biometrics being measured include fingerprints, hand geometry, retina scan, iris scan, facial location or recognition (all physical), voice recognition, signature, keystroke pattern and gait (Behavioral). However, it has been argued by Liu and Silverman (2001) that different applications require different biometrics as there is no supreme or best biometric technology. HISTORY OF BIOMETRICS According to Chirillo and Blaul (2003, p. 3) the term biometrics is derived from the Greek words bio (life) and metric (to measure). China is among the first known to practice biometrics back in the fourteenth century as reported by the Portuguese historian Joao de Barros. It was called member-printing where the childrens palms as well as the footprints were stamped on paper with ink to identify each baby. Alphonse Bertillon, a Paris based anthropologist and police desk clerk was trying to find a way of identifying convicts in the 1890s decided to research on biometrics. He came up with measuring body lengths and was relevant till it was proved to be prone to error as many people shared the same measurement. The police started using fingerprinting developed based on the Chinese methods used century before by Richard Edward Henry, who was working at the Scotland Yard. Raina, Orlans and Woodward (2003, p. 25-26) stated references to biometrics as a concept could be traced back to over a thousand years in East Asia where potters placed their fingerprints on their wares as an early form of brand identity. They also pointed Egypts Nile Valley where traders were formally identified based on physical characteristics such as eye color, complexion and also height. The information were used by merchant to identify trusted traders whom they had successfully transacted business with in the past. Kapil et al also made references to the Bible, first pointing to the faith Gileadites had in their biometric system as reported in The Book of Judges (12:5-6) that the men of Gilead identified enemy in their midst by making suspected Ephraimites say Shibboleth for they could not pronounce it right. The second reference is to The Book of Genesis (27:11-28) where Jacob pretended to be Esau by putting goat skins on his hands and back of his neck so his skin would feel h airy to his blind, aged fathers touch. This illustrates a case of biometric spoofing and false acceptance. They finally wrote Biometrics as a commercial, modern technology has been around since the early 1970s when the first commercially available device was brought to market (p. 26). HOW BIOMETRICS SYSTEMS WORK A biometric system is essentially a pattern-recognition system that makes a personal identification by determining the authenticity of a specific physiological or behavioral characteristics possessed by the user (Blaul 2003, p.3). Biometrics has so far been developed to work in two ways mainly verification and identification. Verification systems are designed to give answer to the question, Am I who I claim to be? by requiring that a user claim an identity in order for a biometric comparison to be performed. The user provides data, which is then compared to his or her enrolled biometric data. Identification systems gives answer to the question, who am I? and do not require a user to claim an identity as the provided biometric data is compared to data from a number of users to find a match (Nanavati 2002, p. 12). An illustration of a scenario using an identifying biometrics system is given below and thus gives an answer to the question Who am I? In October 1998 in the United Kingdom, Newham Council introduced face recognition software to 12 town centre cameras with the sole purpose of decreasing street robbery. Images are compared against a police database of over 100 convicted street robbers known to be active in the previous 12 weeks. In August 2001, 527,000 separate faces were detected and operators confirmed 90 matches against the database. Where a face is not identified with any in the database, the image is deleted; if a match is found a human operator checks the result. The introduction of face recognition technology to Newham city centre saw a 34% decrease in street robbery. The system has not led directly to any arrests, which suggests that its effect is largely due to the deterrence/displacement of crime. The face recognition system has been widely publicised by the council and 93% of residents support its introduction (Postnote Nov 2001, p. 1). The case study below illustrates a verifying biometrics system and supply answers to the question Am I who I claim to be? The US Immigration and Naturalization Service Passenger Accelerated Service System (INSPASS) has been introduced at eight airports in order to provide a quick immigration processing for authorised frequent flyers entering the US and Canada. On arrival at an airport, a traveller inserts a card that carries a record of their hand geometry into the INSPASS kiosk and places their hand on a biometric reader. A computer cross-references the information stored on the card at registration with the live hand geometry scan. The complete process takes less than 30 seconds. If the scans match, the traveller can proceed to customs; if not, travellers are referred to an Immigration Inspector. There are more than 45,000 active INSPASS users with, on average, 20,000 automated immigration inspections conducted each month (Postnote Nov 2001, p. 1). Verifying system is often referred to as a one-to-one process and generally takes less processing time compared to the identifying systems. This is due to the fact that in identifying systems, a user is compared to all users in the database (one-to-many). Verifying systems are also more accurate since they only have to match a users data against his or her stored data and do not need hundreds, thousands or even millions of comparisons like the identifying systems. However, it is important for an organization to decide the type appropriate for the applications. RESEARCH METHODOLOGY The research methodology designed for this dissertation is mainly the qualitative approach. A quantitative approach has been overlooked due to limited time as designing surveys, distribution take time and response time could not be predicted. Therefore, my effort will be concentrated on critically reviewing previous literatures in order to acquire an overview of, and intakes on the topic. For more details, Journals, Books, Publications, Documentaries and previous dissertations related to the topic will be reviewed, compared and analyzed. The objectives will be achieved by purely reviewing literatures and previous researches and the literatures critically analyzed by comparing information obtained from different sources. Findings, recommendations and conclusions will be made from the analysis. OBJECTIVES OF THE STUDY The aim of this research is to critically analyse biometric security as an emerging and booming industry by examining the positives and negatives and providing ways of improving the method effectively and most importantly efficiently. Since biometrics applies to many applications, access control will be the main focus of this dessertation. Also, issues such as privacy, laws governing biometrics and standards will be examined. The main objectives of this research are; To review biometric security and issues related to it. To evaluate the threats, advantages and disadvantages of biometrics. To propose ways of improving the effectiveness and efficiency of biometrics from previous researches. CHAPTER 2 LITERATURE REVIEW This chapter is aimed at critically reviewing and analysis of numerous works of researchers in the area of biometrics, threats to biometrics, advantages and disadvantages and ways of improving biometrics efficiency in access control. The effect of privacy (human rights) and the need to conform to biometrics standards will also be examined and reviewed. DEFINITION OF BIOMETRICS According to Jain, Ross and Pankanti (2006, p. 125), one great concern in our vastly interconnected society is establishing identity. Systems need to know Is he who he claims he is, Is she authorized to use this resource? or simply who is this? Therefore, a wide range of systems require reliable personal recognition schemes to either verify or identify of an individual seeking access to their services. The purpose of that scheme is to ensure that the rendered services are accessed by only the authorized and not any intruder or imposer (Ross 2004, p. 1). Biometric recognition, or simply biometrics, refers to the automatic recognition of individuals based on their physiological and, or behavioral characteristics (Jain, 2004 p. 1). Woodward (2003, p. 27) cited biometric industry guru Ben Millers 1987 biometric definition: Biometric technologies are automated methods of verifying or recognizing the identity of a living person based on a physical or behavioral characteristic. Shoniregun and Crosier (2008, p. 10) provided several definitions of biometrics which include: Biometrics is the development of statistical and mathematical methods applicable to data analysis problems in the biological science. Biometrics = identification/verification of persons based on the unique physiological or behavioral features of humans. Biometrics is the measurement and matching of biological characteristics such as fingerprint images, hand geometry, facial recognition, etc. Biometrics is strongly linked to a stored identity to the physical person. Nevertheless the various definitions, it can be seen that the science of biometrics is based on the fact that no two people are the same and this has a significant influence on its reliability and success factor. THE BIOMETRICS INDUSTRY According to Lockie (2002, p. 10), the biometric industry did not really get established until the middle of the twentieth century. The researchers at that particular time were investigating whether various human parts and characteristics, such as the iris or the voice, could be used to identify an individual. This was made public by publishing papers and as a considerable number of these strands of research began to form a piece, the biometrics industry as we know it these days was established. As organization search for more secure authentication methods for user access, e-commerce, and other security applications, biometrics is gaining increasing attention (Liu 2001, p.27). Higgins, Orlan and Woodward (2003, p. xxiii ), emphasized that even though biometrics have not become an essential part of all systems requiring controlled access, the emerging industry has come a long way from its modern founding in 1972 with the installation of a commercial finger measurement device on Wall Street. He made reference to the highly respected MIT Technology Review called biometrics one of the top ten emerging technologies that will change the world. The growth in biometric industries is reflected in the numbers. The trio cited Rick Noton, the executive director of the International Biometric Industry Association (IBIA), who reported in the Biometrics 2002 Conference in London, United Kingdom, that the industrys trade association has indicated the surge in biometric revenues over recent years. From $20 million in 1996, it has increased to $200 million in 2001 and Norton believes they will increase as the years pass on significantly in 5 years time. Also, a forecast made by the International Biometric Group (IBG), which is a biometric consulting and integration firm located in New York City, estimate that biometric revenues totaled $399 million in 2000 and will increase to $1.9 billion by 2005. Both IBIA and IBG believe that the private sector will be responsible for much of the growth. These give evidence of the relevance of biometrics in organizations in modern times. BIOMETRICS AND ACCESS CONTROL Over the years, biometrics has evolved rapidly and many vertical markets such as governments, transport, financial sectors, security, public justice and safety, healthcare and many more have adopted biometrics. Due to this wide range of users, biometrics has been deployed to many applications. Biometrics has been of high benefit to organization as they seek a reliable security method to safeguard assets. Fully understanding how biometrics work, it can be said that the ultimate aim of applying biometrics in the vertical markets listed above is to control access to a resource irrespective of the system used whether a verifying or an identifying process It has been stated by S. Nanavati, Thieme and R. Nanavati (2002, p. 14), that biometric systems are deployed for two primary purposes which are physical and logical access. LOGICAL VERSUS PHYSICAL ACCESS Physical access systems monitors, restricts, or grant movement of a person or object into or out of a specific area (Thieme 2002, p. 14). This could be implemented to control entry into rooms or even the main building. Popular examples are control towers, bank vaults, server rooms and many other sensitive rooms requiring controlled access. In physical access, biometrics replaces the use of keys, PIN codes access cards and security guards although any of these could be combined with biometrics as a complementation. Common physical access application is time and attendance. Thieme also gave a definition of logical access systems as one that monitor, restrict or grant access to data or information listing examples such as logging into a PC, accessing data stored on a network, accessing an account, or authenticating a transaction. In this case, biometrics replaces and can be designed to complement PINs, passwords and also tokens. Basic biometric functionality precisely acquiring and comparing of biometric data is often identical in both physical and logical systems. For example, the same iris scan data can be used for both doorway and desktop applications. Thieme explained that the only difference between the two is the external system into which the biometric functionality is integrated. The biometric functionality is integrated into a larger system. This applies for both physical and logical access system and actions such as access to any desktop application or access to a room via a doorway are effected by a biometric match. However, not every system can be classified as physical or logical access as the end result does not indicate access to data or a physical location and the result therefore may be to investigate more. An ATM secured by biometrics allows access to money, a physical entity. This is made possible by allowing the user logical access to his or her data. In the example above, the application is even difficult to classify as either physical or logical. Thieme (2002, p. 15) suggested that the distinction between physical and logical access systems is a valuable tool in understanding biometric. He noted that key criteria such accuracy, fallback procedures, privacy requirements, costs, response time and complexity of integration all vary effectively when moving from logical to physical access. WHAT ARE BIOMETRIC STANDARDS Stapleton (2003, p. 167) defined a standard in a general term as a published document, developed by a recognized authority, which defines a set of policies and practices, technical or security requirements, techniques or mechanisms, or describes some other abstract concept or model. The growth of the biometric industry has been relatively slowed by the absence of industry wide standards and this has also impeded various types of biometric deployment. Nanavati (2002, p. 277) stated that the relative youth of the technology in use, coupled with the disunified nature of the industry, has impacted the developments of standards resulting in a sporadic and frequently redundant standards. Nanavati also noted that the live-scan fingerprint imaging is the only segment of biometric industry with widely accepted and adopted standards. Due to this absence of biometric standards, some institutions have been concerned of being tied into technologies they actually believed as not mature or even dev elopmental. However in an effort to actively address the standards issue, the biometric industry has finalized some blueprints and the process of getting industries to accept these standards is ongoing WHY IS STANDARDIZATION NECESSARY? The high rate of biometric development and rapid growth in adoption of biometric technologies in recent years has resulted in ever-increasing levels of what is expected in terms of accuracy, adaptability, and reliability in an ever-wider range of applications. Due to the adoption of biometric technologies in large-scale national and international applications, involving a potentially unlimited range of stakeholders, Farzin Deravi (2008, p. 483) stated that it has become essential to address these expectations by ensuring agreed common frameworks for implementation and evaluation of biometric technologies through standardization activities. Majority of biometric systems, including both the hardware and software are made and sold by the owner of the patent at this stage in their development. They are being proprietary in numerous aspects including the manner in which biometric devices and systems as a whole communicate with applications, the method of extracting features from a biometric sample, and among many more, the method of storing and retrieving biometric data. This resulted in many companies in most cases, being wedded to a particular technology, once they agree to implement that particular technology. Nanavati (2002, p. 278) stated that in order to incorporate a new technology, the companies are required to rebuild their system from scratch upward, and in some cases duplicating much of the deployment effort. Deravi (2008 p. 483) noted that the need for interoperability of biometric systems across national boundaries has implied a rapid escalation of standardization efforts to the international arena, stating that the sense of urgency for the need for standardization has been the priority of internal security concerns. The industry wide or universal adoption of biometric standard will not make biometric technology interoperable at least, to the state where an old device can be replaced by a new device without rebuilding the system. However, Nanavati (2002 p. 278) argued the core algorithms through which vendors locate and extract biometric data are very unlikely to be interoperable or standardized, the reason being that these algorithms represents the basis of most vendors intellectual property. Numerous reasons are responsible for the motivation towards standardization. These include the desire for reducing the overall cost of deploying biometrics technologies and optimize the reliability of biometric systems, to reduce the risk of deploying solutions to biometric problems, to ensure in the area of encryption and file format, that the basic building blocks of biometric data management have been developed based on best practice by industry professionals. Nanavati (2002 p. 278) concluded that standards ensure that, in the future, biometric technology will be developed and deployed in accordance with generally accepted principles of information technology. EXISTING BIOMETRIC STANDARDS Shoniregun and Crosier (2008 p. 22) stated that the evolving interest and developments have made developments of standards a necessity with the sole aim of allowing compatibility of different systems. The detailed standards in the Biometrics Resource Centre (2002) report are summarised below: Common Biometric Exchange File Format (CBEFF): The Common Biometric Exchange File Format (CBEFF) sets a standard for the data elements essential in supporting biometric technology in a common way irrespective of the application involved or the domain in use. It makes data interchange between systems and their components easier, while promoting interoperability applications, programs as well as systems based on biometrics. INCITS MI-Biometrics Technical Committee: The committee which was established by the Executive Board of the International Committee for Information Technology standards (INCITS) with the responsibility to ensure a focused and reasonably comprehensive approach in the United States for the rapid development and approval of previous national and international generic biometric standards (Shoniregun ad Crosier 2008, p. 22) BioAPI Specification (Version 1.1): The BioAPI standard defines the architecture for biometric systems integration in a single computer system. (Deravi 2008, p. 490). The Bio API specification has been one of the most popular standards efforts since it was formed in April 1998 according to Nanavati (2002, p. 279). Nnavati stated that the standard was formed to develop an API that is both widely accepted and widely available while being compatible with various biometric technologies. Other general standards available are Human Recognition Module (HRS), ANSI/NIST-ITL 1-2000, American Association for Motor Vehicle Administration and American National Standards Institute (ANSI) which specifies the acceptable security requirements necessary for effective management of biometric data especially for the financial services industry. BRITISH BIOMETRICS STANDARDS The British Standards Institution (BSI) commenced work in June 2004 on biometrics standards and since then, has published according to Shoniregun and Crosier (2008, p. 24) a set of four new BS ISO/IEC 19794 STANDARDS, reported to have covered the science of biometrics, and using biological characteristics in identifying individuals. The objective of publishing these standards is to promote interoperability between the several products in the market. BS ISO/IEC 19784-2:2007: This standard defines the interface to an archive Biometric Function Provider (BFP). The interface assumes that the collected biometrics data will be managed as a database, irrespective of its physical realization. Crosier (2008, p. 24) defined the physical realization as smartcards, token, memory sticks, files on hard drives and any other kind of memory can be handled via an abstraction layer presenting a database interface.) BS ISO/IEC 19795-2:2006: According to Shoniregun (2008, p. 25), this standard provides recommendations and requirements on collection of data, analysis as well as reporting specific to two types of evaluation (scenario evaluation and technology evaluation). BS ISO/IEC 19795-2:2006 further specifies the requirements in the development and full description of protocols for scenario and technology evaluations and also, in executing and reporting biometric evaluations. BS ISO/IEC 24709-1:2007: ISO/IEC 24709-1:2007 specifies the concepts, framework, test methods and criteria required to test conformity of biometric products claiming conformance to BioAPI (ISO/IEC 19784-1). (www.iso.org). Crosier (2008, p. 25) stated ISO/IEC 24709-1:2007 specifies three conformance testing models which allows conformance testing of each of the BioAPI components mainly a framework, an application and a BSP. BS ISO/IEC 24709-2:2007: The standard BS ISO/IEC 247 defines a number of test assertions composed in the assertion language explicitly required in ISO/IEC 24709-1. The assertions allow a user to test the conformance of any biometric server producer (BSP) that claims to be a conforming implementation of that International Standard to ISO/IEC 19784-1 (BioAPI 2.0) (www.iso.org). BIOMETRICS AND PRIVACY The fact that biometric technologies are based on measuring physiological or behavioral and archiving these data has raised concerns on privacy risks, and also raised discussion on the role biometrics play when it comes to privacy. As stated by Nanavati (2002, p. 237), increase in the use of biometric technology in the public sector, workplace and even at home has raised the following questions: What are the main privacy concerns relating to biometric usage? What kinds of biometric deployments need stronger protections to avoid invading privacy? What biometric technologies are more prone to privacy-invasive usage? What kinds of protections are required to ensure biometrics are used in a non privacy-invasive way? Woodward (2003, p. 197) cited President Clintons speech in his commencement address at Morgan State University in 1997: The right to privacy is one of our most cherished freedomsWe must develop new protections for privacy in the face of new technological reality. Recently, Biometrics has been increasingly deployed to improve security and a very important tool to combat terrorism. Privacy issue is central to biometrics and many people believe that deploying biometrics poses a considerable level of risk to human rights, even though some are of the opinion that biometrics actually protect privacy. Human factors influence the success of a biometric-based identification system to a great extent. The ease as well as comfort in interaction with a biometric system contributes to how people accept it. Jain, Ross and Prabhakar (2004 p. 24) stated an example of a biometric system being able to measure the characteristic of a users without touching, such as those using voice, face, or iris, and concluded that it may be perceived to be a more user-friendly and hygienic system by the users. They added that on the other hand, biometric characteristics not requiring user participation or interaction can be recorded without the knowledge of the user, and this is perceived as a threat to human privacy by many individuals. According to Sim (2009, p. 81), biometrics compared to other security technologies has significant impacts on users privacy (Civil Liberties). It can protect privacy when deployed in an appropriate manner; but when misused, it can result in loss of privacy. ADVANTAGES OF BIOMETRIC OVER TRADITIONAL METHODS Password and PINs have been the most frequently used authentication method. Their use involves controlling access to a building or a room, securing access to computers, network, the applications on the personal computers and many more. In some higher security applications, handheld tokens such as key fobs and smart cards have been deployed. Due to some problems related to these methods, the suitability and reliability of these authentication technologies have been questioned especially in this modern world with modern applications. Biometrics offer some benefits compare to these authentication technologies. INCREASED SECURITY Biometric technology can provide a higher degree of security compared to traditional authentication methods. Chirillo (2003 p. 2) stated that biometrics is preferred over traditional methods for many reasons which include the fact that the physical presence of the authorized person is required at the point of identification. This means that only the authorized person has access to the resources. Effort by people to manage several passwords has left many choosing easy or general words, with considerable number writing the