Physical security systems
These pages explain the equipment and platforms used in physical security. Follow the devices, decisions and dependencies involved in each workflow.
On this page
Overview#
This section turns protocol knowledge into system models. Each page identifies which component is authoritative, separates observation from control and management, and makes ambiguous or degraded physical outcomes visible.
Domains#
- Video surveillance: cameras, video management, recording, analytics, PTZ, evidence, and health.
- Access control: PACS, panels/readers/doors, locks and egress, pedestrian portals and turnstiles, credentials, biometrics, mobile access, offline policy, visitors, and lifts.
- Intrusion and monitoring: panels, zones, sensors, communicators, receivers, supervision, verification, panic/duress, and fire boundaries.
- Intercom and emergency communications: call stations, media/routing, door control, emergency phones, public address, and mass notification.
- Perimeter and detection: layered perimeter design, ANPR/LPR, radar, fence/buried sensors, gates, barriers, and vehicles.
- Integration platforms: PSIM/command platforms, BMS/SCADA, SIEM/SOAR, identity/HR/visitor, cloud/mobile, and multi tenancy.
Shared system model#
people / vehicles / environment
-> sensors, readers, cameras, call stations, physical I/O
-> controllers, panels, edge compute, recorders
-> management platforms and integration gateways
-> enterprise/cloud data, identity, response, and operator workflows
For every arrow document:
- actors, ownership, direction, protocol/profile/version, and trust boundary;
- entity IDs, event/state/command meaning, source and receive times, and provenance;
- authenticated user/device/workload, resource/site/tenant authorisation, and audit;
- timeout, retry, sequence, duplicate, loss, offline, and reconciliation behaviour;
- sensitive data, retention, disclosure, and physical consequence;
- supported versions, conformance evidence, lifecycle, and recovery.
Four planes#
| Plane | Examples | Rule |
|---|---|---|
| Observation | video, door state, alarms, health | Preserve provenance, quality, time, loss, and privacy |
| Control | unlock, PTZ, alarm acknowledge, gate command | Least authority, independent confirmation, safe ambiguity |
| Management | configuration, firmware, users, certificates | Separate privileged identity, change control, recovery |
| Bootstrap/discovery | enrollment, DHCP/DNS, discovery, key setup | Candidate discovery is not authenticated trust |
No protocol success response proves a safe physical outcome. See physical security system architecture, events/state/commands/time, and verification and safety.
Standards boundary#
Official standards establish minimum/system/profile requirements, but adopted editions and local obligations differ. IEC catalogue summaries used here include IEC 62676-1-1:2013 for video surveillance system requirements, IEC 60839-11-1:2013 for electronic access control, IEC 62642-1:2010 for intrusion/hold up systems, and current IEC 62820-1-1:2026 for building intercoms. Normative texts are paywalled and this library doesn't reconstruct them.