The physical security protocol map
Find protocols by the task they perform, then follow the detailed references for each family.
On this page
The layers at a glance#
people, policy and approved physical outcomes
|
system or application behaviour
VMS · PACS · monitoring · integration
|
protocols and data contracts
ONVIF · OSDP · SIA · MQTT · BACnet · vendor API
|
transport, identity and protection
TCP/UDP · TLS · certificates · roles
|
network and field links
Ethernet · radio · serial · contacts
This is a reading map, not a claim that every technology sits at exactly one layer. Use architecture and layering for the distinctions and protocol roles for a more detailed matrix.
Choose the job#
| Job | Start with | Keep separate |
|---|---|---|
| Discover camera services and capabilities | ONVIF | Discovery, device identity, profile registration and optional features |
| Set up and carry a media stream | RTSP, RTP, RTCP and SDP | Session control, description, packets, codec and permissions |
| Deliver media to a browser | WebRTC | Signalling, authorisation and media connectivity |
| Integrate intercom calling | SIP and SRTP | Call signalling, protected media and door release |
| Connect a reader and controller | OSDP or legacy reader links | Electrical link, credential data and authentication |
| Understand card or mobile presentation | Credential formats and NFC, BLE and UWB | Radio, credential proof, proximity and access policy |
| Report an alarm to a receiver | Alarm protocols | Premises reporting, receiver handoff, supervision and response |
| Consume application events | MQTT, AMQP or web event delivery | Delivery, persistence, freshness, state and physical outcome |
| Exchange building data | BACnet, Modbus or OPC UA | Object or register meaning, safe control and engineering authority |
| Integrate enterprise identity | SAML and OIDC, SCIM or WebAuthn | Authentication, provisioning, authorisation and enforcement |
| Work with a specific platform | Vendor APIs | Product family, version, licence and supported interface |
Questions worth carrying into every page#
Ask which role each endpoint implements, what the data means, which version applies and how identity is checked. Then ask what happens when a message is delayed, repeated or lost.
For physical control, also identify who is authorised to request the change and which component can confirm the actual result. A successful transport or API exchange does not answer both questions.
Status and source limits#
Most imported technical pages retain their 25 August 2026 source baseline. Pages with a newer scoped check show that date separately. The standards and profile status register includes selected checks through 13 September 2026.
Use the verification policy and the primary sources linked from each protocol page. Confirm current editions, lifecycle dates and product support before a deployment decision.