Monitoring and health
Monitor the function each service provides, including video freshness, event delivery and controller state. Record connectivity separately from those functional checks.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Research and static guidance only; product and deployment specific behaviour requires controlled environment validation and authoritative product evidence.
On this page
Overview#
Service reachability isn't the same as security function. A camera may answer ping while video is frozen; a controller may be online while its reader bus is degraded; a broker may be healthy while authorisation rejects every publisher.
Health layers#
| Layer | Signals |
|---|---|
| Physical/power | Power source, PoE/battery/UPS state, enclosure/tamper, temperature, link, serial errors |
| Device | Boot/reboot, firmware, CPU/memory, clock, storage, sensor/reader/stream state |
| Protocol | Authentication, certificate, sequence/CRC, timeout, retry, reconnect, queue, subscription, multicast |
| Application | Recording continuity, door decisions, alarm delivery, intercom call, analytics/event pipeline |
| Security | Account/role/config change, failed login, legacy mode, trust anchor change, update failure |
| Data/evidence | Gaps, drift, corruption, retention, export verification, duplicate or out of order events |
| Dependency | DNS, DHCP, time, IdP, CA, broker, database, vendor cloud, cellular, storage and backup |
Monitor expected absence#
Some failures appear as silence. Define expected heartbeats, stream samples, event rates, sequence continuity, polling interval, certificate renewal, backup completion and configuration checkpoints. Alert on missing expected evidence, not only explicit errors.
Alert design#
- State the affected component, function and scope.
- Preserve first occurrence, duration, flapping and recovery.
- Correlate downstream symptoms to upstream dependency failure.
- Suppress duplicate noise without hiding persistent security degradation.
- Route high impact safety/availability conditions through the approved operational process.
- Avoid sensitive faces, credentials, tokens and facility details in broad alert channels.
Checks for your system cases#
Verify expected alerts for controlled loss and restoration scenarios involving a non production stream, reader/controller link, time source, certificate trust, storage capacity, broker subscription, authentication path, and vendor dependency. Record alert latency, recovery indication, missing evidence, false positives, and unexpected side effects in the environment validation record.
Sources#
- NIST 800 137, NIST SP 800-137: Information Security Continuous Monitoring, accessed 25 August 2026.
- NIST 800 82, NIST SP 800-82 Rev. 3, OT monitoring guidance, accessed 25 August 2026.