
DEF CON 33 - Access Control Done Right the First Time - Tim Clevenger
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 22:48
Access Control Done Right: Avoiding Minimum Viable Installations (Published: March 15, 2023)
Implement robust access control systems from the start, rejecting vendors' minimal viable products common in low-bid scenarios. Key recommendations include:
- Use Mercury Security hardware (industry standard) for local processing, power-outage resilience, and vendor flexibility via firmware updates.
- Plan equipment placement carefully: consider environment, power, physical security, and future access.
- Install composite access control cable—cheaper alternatives cause failures and vulnerabilities.
- Cluster equipment centrally; avoid long daisy-chains for better reliability and troubleshooting.
- Implement essential security: tamper switches, supervision resistors, fail-safe mechanisms, and secure HID Corporate 1000 badge tech.
- Maintain rigor: regular testing, active alerts, thorough documentation, and battery replacement every 3-5 years.
Proper implementation demands quality components and security focus—not default minimum installations.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Uh thank you for coming. My name is Tim Clevenger. This is access control done right the first time. Uh by day I'm a network cyber security engineer. Uh but in a previous life uh I worked as a CIS admin for an alarm company that did access control systems. And they offered to uh let me get out of the dark server room and go drive a truck around and install troubleshoot maintain access control systems that had been installed by them and by other companies. And so working on those systems, I just came up with a few kind of tips and tricks to uh make your access control system, whether you're installing a new one, upgrading, or uh just doing maintenance, make it a little more maintainable, a little more reliable, a little more secure. Um many vendors, you know, it's a low bid situation, and t…