Secure system baselines
Use the relevant product guidance to establish security settings. Record the intended outcome, implemented controls, exceptions and evidence for the deployed configuration.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Research and static guidance only; product and deployment specific behaviour requires controlled environment validation and authoritative product evidence.
On this page
Overview#
These are minimum engineering outcomes, not universal vendor configuration commands. Apply exact manufacturer guidance, model/firmware capabilities, operational risk, and local safety requirements. Record every unsupported control and compensating measure.
Universal baseline#
- Inventory exact hardware, firmware/software, enabled protocols, interfaces, licences and support status.
- Remove or change default/shared credentials; issue unique device/workload identity.
- Enable the strongest supported authenticated encrypted mode and validate peer identity.
- Disable unused services, discovery after commissioning where feasible, legacy fallback, unused accounts and unmanaged cloud access.
- Enforce role and object scoped authorisation for viewing, administration, export, credential management and actuation.
- Segment device, management, integration, operator, monitoring and support paths.
- Configure trustworthy time, centralized health/security logging, bounded storage and alerting.
- Verify signed update provenance and maintain a recovery/rollback path.
- Back up configuration and trust dependencies under separate protection.
- Document safe degraded behaviour, physical tamper controls, privacy/retention and decommissioning.
Component additions#
| Component | Additional minimum outcomes |
|---|---|
| Camera/encoder | Separate media view from configuration; protect RTSP/media credentials; constrain multicast; disable anonymous snapshots; mask sensitive areas; monitor stream/config/tamper/time changes |
| NVR/VMS/VSaaS | Separate operator/admin/export roles; protect recording and signing keys; constrain device onboarding; audit search/export/delete; capacity and retention alarms; secure failover |
| Reader/controller/PACS | Prefer authenticated supervised reader links; remove installation/default keys; protect credential lifecycle; authorise outputs separately; preserve certified egress/fire dependencies |
| Alarm/intercom | Protect receiver accounts and event origin; use dual path supervision appropriately; secure audio/video and call control; never allow integrations to suppress certified behaviour |
| Gateway/broker | Unique workload identities; per direction/topic/API policy; schema and size limits; bounded queues/retries; no transparent insecure transit; full command/event correlation |
| Management server | Harden host/database; separate service accounts; protect admin interface, backups and API secrets; control plugins/SDKs; monitor privilege and policy changes |
| Operator workstation | Managed endpoint, strong login, least privilege, controlled export/removable media, screen/privacy protection, no direct device administration by default |
| Cloud connector | Explicit tenancy and data flow; mTLS/workload identity; constrained outbound destinations; token/key rotation; offline behaviour; vendor support and deletion/export boundaries |
Legacy exception record#
When a device can't meet the baseline, record the missing property, exact affected interface, exploit/precondition, business and physical impact, isolation, upstream control, monitoring, replacement target, accountable risk owner, and expiry/review date. Avoid vague entries such as accepted because legacy.
Checks for your system record#
Validate the resulting configuration in a representative non production environment against the applicable manufacturer documentation. Capture the exact version, commands/settings, expected and observed result, rollback path, accountable reviewer, and limitations in the environment validation record.
Sources#
- NIST 800 82, NIST SP 800-82 Rev. 3, OT security controls and architecture, accessed 25 August 2026.
- NISTIR 8259A, NISTIR 8259A IoT Device Cybersecurity Capability Core Baseline, accessed 25 August 2026.
- CISA SBD, CISA Secure by Design, manufacturer principles and guidance, accessed 25 August 2026.