For a change of pace, this system is for a single-story branch location for a local credit union that is presumed to have a sprinkler system in addition to the obligatory security and access control measures. It also has an ITM in a drive-through lane with a canopy overhead.
Life Safety
The alarm system has two zones reserved for sprinkler monitoring, as it is presumed that this building is sprinklered due to being commercial new construction. The building is small enough to not have significant life safety needs otherwise, although there is an Exitronix S900C-SM-R exit sign/emergency light combo to direct folks to the auxiliary exit door and illuminate the corridor leading that way in case of a power outage.
Security
Passive Measures
All glazing in the building is presumed to be of a laminated, forced-entry-resistant type. The exterior doors are also heavy-duty hollow metal units, capable of accommodating multi-point locking mechanisms and forced-entry-resistant glazing. There are also fixed mullions in the main vestibule door frames to provide secure strike points for the door latches and locks, as well as direct traffic flow.
The (small bedroom closet sized) vault is presumed to be of a modular type, as is typical in modern financial institution branch locations. The data room and workroom receive a lesser degree of fortification using expanded metal mesh in the walls to provide secure mounting and protect them from cutting attacks.
In addition, both of the building’s main data connections are laid on separate paths using galvanized rigid steel conduit to carry the fibers, with the conduit laid in wet concrete and then backfilled with another 6” of concrete cover. This prevents someone from trivially severing the data connection to the building then jamming the cellular signal to the panel’s communicators to prevent the communications failure or the jamming condition from being reported to the monitoring station.
Alarms
The primary alarm panel is a Bosch B9512G with two B444 cell modules (one for each carrier). B915 keypads in the vestibule and workroom, and a D8108A attack resistant enclosure with an ICP-EZTS tamper to house the main panel and its batteries, with the panel located in the main workroom, near the data room, due to the small size of the vault. The onboard Ethernet port is used for video verification with Bosch cameras and as the primary alarm communicator.
At this main location, in addition to the panel, there is a B208 input expander and a B520 auxiliary supply mounted on D137 brackets. The panel is connected to 2 19Ah batteries to supply 72h of standby and 30min in alarm, and the B520 is connected to a third 19Ah battery in an Altronix BC100.
The remaining three B208 cards and another B520 supply card are located in the access control enclosure. Alarm notification is supplied by a Resideo AB12M at the base of the clerestory. All the alarm power transformers use D8004 enclosure kits to protect them from inadvertent disconnection.
Initiation
Initiation for the system consists of pairs of Magnasphere HSS-L2C-101 door contacts on all doors save for the inner vestibule doors, which have both a HSS-L2C-111 and a HSS-L2C-101 on each leaf. The vault and ITM doors have HSS-L2S-817s on them, and use Bosch ISN-SM-50 seismic sensors, with another identical sensor in the D8108A.
The glazing is further protected by Resideo/Honeywell FG1625RT glassbreak sensors, save for the glazing in the breakroom window, which receives 24-hour protection from a FG1025Z directional glassbreak. Motion detection is supplied by Bosch ISC-PDL1-WA18G dual tech motion detectors with their mask trouble contacts wired as tampers, and the IP camera system is used to video verify alarms. Honeywell 268 squeeze-action holdup switches are used at all teller stations and at the cash-handling table to provide holdup alarm functionality, and Honeywell 264 bill trap clips are also present in the teller drawers.
These detectors, as well as the locks on the vault and ITM, boil down to the following zone mapping, with the first 8 zones being the panel zones, the second 8 zones being on the B208 in the panel enclosure, and the remaining zones on the B208s in the access control enclosure:
- the panel’s seismic sensor
- the vault’s seismic & heat sensors (the latter being a FDD 7050C)
- the vault’s contact
- the ITM’s seismic sensor
- the ITM’s contacts
- the ITM lock’s shunt circuit
- sprinkler waterflow
- sprinkler supervisory
- JamAlert
- bell tamper
- duress/holdup, combining the holdup switches at the teller stations and the cash handling desk with the duress contacts on the ITM and vault locks and a set of bill traps in the teller cash drawers
- workroom exterior door (back door)
- workroom interior door (to teller area)
- breakroom directional glassbreak (alarm/tamper)
- breakroom directional glassbreak trouble
- workroom/breakroom motion sensors
- lobby/teller area motion sensors
- office 1 motion sensors
- office 2 motion sensors
- office 3 motion sensors
- main outer door contacts
- main inner door contacts
- main outer door deadbolt monitoring strike
- lobby/teller area glassbreaks
- office 1 glassbreaks
- office 2 glassbreaks
- office 3 glassbreaks
- hoteling room glassbreak
- hoteling room motion sensors
- server room contacts
- server room motion sensors
- entry vestibule glassbreak
- side door contacts
- side corridor motion sensor
- intercom camera analytics alarms
- office 1 door
- office 2 door
- office 3 door
- hoteling room door
- and keyswitch (arm/disarm) control from the access control system
The outputs to the ACS consist of a relay contact on the bell output signal, an arm/disarm output relay, and a trouble relay. (None of the detectors are configured to use latching outputs or alarm memory functions.)
Video Recording and Verification
A set of 15 Bosch NUV-3703-F04 dome IP cameras are present to provide the main video recording and verification functionality, set up as follows:
- 2 cameras cover the lobby from each end of the clerestory
- 2 cameras cover the teller area from the back wall
- 1 camera is present in each office
- 3 cameras cover the workroom
- 1 covers the ITM and side door from under the canopy
- 1 covers the area outside the front door
- 2 cameras, 1 on the corner of the clerestory and the other on the corner of the building, cover the trash enclosure, back door, and associated breakroom glazing
- 1 camera covers the server/data room
- 1 camera covers the hoteling room
- and 1 camera covers the hallway to the side door
This is supplemented by:
- The camera in an Axis I8116-E intercom at the main inner door
- and a Hanwha PNM-9000QB covert camera unit with SLA-T2480VA heads in the ITM and in signs at each teller station.
Recording and power functionality is provided using a Mobotix Mx-S-NVR1B-16-POE NVR with a pair of 10TB WD Purples in it for a full month of archiving and a TP-Link TL-SG1008P on the Mobotix NVR’s LAN port for extra camera ports. The NVR, in turn, is powered from an industrial 48V setup consisting of two Phoenix Contact PS-EE-2G/1AC/48DC/480W/SCs (1585287s) set for 54V and combined by a Traco TIB-REM480 FET redundancy module, backed up using a Nextys (TDK-Lambda) DCW20 DC-UPS with two cross connected strings of C&D UPS12-675PLMFs for 72.5h of battery life. The bank is protected from overcurrent by a 20A RK5 fuse in a fuseblock located on the wall next to the bank positive terminal. The NVR also monitors the Nextys’ dry contacts for power failure and low battery indications.
The two indoor supplemental cameras connect to PoE ports on the TP-Link, while the non-PoE ports connect to the intrusion panel as well as the two outdoor supplemental cameras and the NVR. Those outdoor supplemental cameras consist of:
- an Axis P1518-LE on the side of the building, facing the driveway entrance, to provide an alarm-triggered LPR capability
- and a Pelco SRXF3-8180-ERS to provide a wide-angle overview of the area outside the front door.
These cameras receive 12V power from a FPO75-E1 with a pair of 18Ah batteries in it, providing them with 6h of power.
Access Control
The ACS cabinet is an Altronix Trove1BL1R in the data rack. In addition to the Bosch expanders mentioned above, this cabinet contains a Mercury MP4502 control board that talks to the bank’s access control headend over a VPN tunnel, as well as a MR50-S3 that provides I/O expansion to interface to the alarm panel. An AL400ULB with a PD8ULCB and 2 12Ah batteries for 12h of runtime is used to power this all while providing room to add an additional door.
The readers for the ACS are HID Signo 20s, save for the back door, which receives a Signo 20K to permit 2FA. The intercom system is also tied into the ACS using an Axis A9210 network relay module to receive supervised door inputs and provide a remote secure relay output to unlock the door independently of the rest of the ACS “brains” – this module is powered from a PoE port on the video system’s supplemental switch.
The ACS controlled doors use Securitron CEPT power transfers with Accurate mortise locksets, consisting of:
- a M9159ESEC-MP with AE (REX) on the back outer (workroom) door (the most vulnerable door to forced entry in the place)
- M9159ESECs on the access controlled interior doors (to the workroom & data closet)
- and additional M9159ESECs on the inner vestibule doors
The side door has a 9159SEC-MP on it, as it is presumed to not need access control, and the outer vestibule doors have 9122SEC-MPs with interior indicator trim on them to provide after-hours locking. Should the side door need access control, the lockset can be replaced with a M9159ESEC-MP, and there’s enough expansion capacity in the system to accommodate another MR50-S3 and an Altronix VR2T module to power a Signo 20 at that door without enlarging the power supply or batteries.
Communications
A FortiGate FG-80F, Juniper SRX300, or equivalent UL listed dual-SFP firewall appliance provides the main firewall and WAN connections for the branch, with 2 fiber links (xPON or P2P) to 2 different providers. The uplink from the NVR is connected directly to the firewall appliance’s internal LAN switch, which also accepts a copper uplink from the main switch for the branch.
Power to this appliance is supplied by a Samlex SEC-1215UL charger and a C&D UPS12-705PLMF battery to provide 72.5h of standby as it carries traffic from the NVR and alarm system. The shipped power supply is used to provide a redundant backup.