Security About 2 min read

Secure system baselines

Use the relevant product guidance to establish security settings. Record the intended outcome, implemented controls, exceptions and evidence for the deployed configuration.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Research and static guidance only; product and deployment specific behaviour requires controlled environment validation and authoritative product evidence.

Verification and testing

Overview#

These are minimum engineering outcomes, not universal vendor configuration commands. Apply exact manufacturer guidance, model/firmware capabilities, operational risk, and local safety requirements. Record every unsupported control and compensating measure.

Universal baseline#

  • Inventory exact hardware, firmware/software, enabled protocols, interfaces, licences and support status.
  • Remove or change default/shared credentials; issue unique device/workload identity.
  • Enable the strongest supported authenticated encrypted mode and validate peer identity.
  • Disable unused services, discovery after commissioning where feasible, legacy fallback, unused accounts and unmanaged cloud access.
  • Enforce role and object scoped authorisation for viewing, administration, export, credential management and actuation.
  • Segment device, management, integration, operator, monitoring and support paths.
  • Configure trustworthy time, centralized health/security logging, bounded storage and alerting.
  • Verify signed update provenance and maintain a recovery/rollback path.
  • Back up configuration and trust dependencies under separate protection.
  • Document safe degraded behaviour, physical tamper controls, privacy/retention and decommissioning.

Component additions#

Component Additional minimum outcomes
Camera/encoder Separate media view from configuration; protect RTSP/media credentials; constrain multicast; disable anonymous snapshots; mask sensitive areas; monitor stream/config/tamper/time changes
NVR/VMS/VSaaS Separate operator/admin/export roles; protect recording and signing keys; constrain device onboarding; audit search/export/delete; capacity and retention alarms; secure failover
Reader/controller/PACS Prefer authenticated supervised reader links; remove installation/default keys; protect credential lifecycle; authorise outputs separately; preserve certified egress/fire dependencies
Alarm/intercom Protect receiver accounts and event origin; use dual path supervision appropriately; secure audio/video and call control; never allow integrations to suppress certified behaviour
Gateway/broker Unique workload identities; per direction/topic/API policy; schema and size limits; bounded queues/retries; no transparent insecure transit; full command/event correlation
Management server Harden host/database; separate service accounts; protect admin interface, backups and API secrets; control plugins/SDKs; monitor privilege and policy changes
Operator workstation Managed endpoint, strong login, least privilege, controlled export/removable media, screen/privacy protection, no direct device administration by default
Cloud connector Explicit tenancy and data flow; mTLS/workload identity; constrained outbound destinations; token/key rotation; offline behaviour; vendor support and deletion/export boundaries

Legacy exception record#

When a device can't meet the baseline, record the missing property, exact affected interface, exploit/precondition, business and physical impact, isolation, upstream control, monitoring, replacement target, accountable risk owner, and expiry/review date. Avoid vague entries such as accepted because legacy.

Checks for your system record#

Validate the resulting configuration in a representative non production environment against the applicable manufacturer documentation. Capture the exact version, commands/settings, expected and observed result, rollback path, accountable reviewer, and limitations in the environment validation record.

Sources#