CCTV AND NETWORK SECURITY · 21 SEPTEMBER 2026
CCTV cybersecurity at handover: a commissioning worksheet
A CCTV system is also a network of computers, user accounts, applications and stored evidence. Handover should prove not only that video is visible, but also that the delivered system has an approved inventory, controlled access, reduced exposure and a maintainable update process.
Start with an owned device inventory
Record every camera, recorder, VMS server, operator workstation, PoE switch, router, firewall, wireless bridge and remote-access component. The inventory should include device ID, location, role, manufacturer, model, serial number, IP address, MAC address, software version, support status, network zone and operational owner.
Inventory is the foundation for updates and incident response. A device that is not listed can remain unpatched, retain an old account or be missed when a project team changes. The AXIS OS Hardening Guide treats device lifecycle, account management, secure configuration and reduced exposure as continuing operational controls, not one-time installation settings.
Inventory row: device ID · location · role · manufacturer/model · serial number · IP/MAC · software version · network zone · owner · update track · support status · exception.
Separate identities and remove temporary access
Confirm that installer accounts, default passwords and shared temporary credentials are removed or transferred through the owner's approved process. Create named roles for administration, live viewing, playback, export and maintenance according to actual duties. A person who only monitors cameras should not automatically receive configuration or user-management rights.
Record who approves new users, how leavers are removed, whether multi-factor authentication is available for remote or cloud access, and where recovery information is held. Do not place live credentials in the general handover document.
Map the permitted network paths
Document which systems are allowed to communicate. Cameras may need to reach an NVR or VMS, approved time source, management system and selected analytics services. They do not need unrestricted access simply because all devices share a switch. Use a dedicated security network or VLAN where the design supports it, then enforce the required paths through switching, routing and firewall policy.
This worksheet should be read with the enterprise VLAN and switch handover guide. VLAN names alone do not prove isolation. Test the allowed and denied communication from representative ports and record the result.
Communication row: source zone/device · destination zone/device · service or port · purpose · direction · allowed or denied · policy reference · witnessed result · exception.
Reduce device exposure before acceptance
Review every enabled service against the approved system design. Disable unused discovery, troubleshooting and legacy services where the selected equipment permits it. Prefer encrypted management and streaming protocols when they are supported by the complete camera, recorder and VMS combination.
Axis recommends HTTPS-only device access, disabling outdated TLS versions, removing unused applications, and using secure video streaming when the VMS supports it. These are manufacturer-specific examples, so the final settings must follow the documentation for the actual products installed. Do not copy a control from one brand into another device without verifying compatibility.
Verify software, certificates and time
Record the installed software version and approved update track for each device family. Confirm who receives vendor security notices, who tests updates against the VMS, who approves deployment and how a failed change is recovered. Where certificates are used, document the issuer, purpose, expiry date and renewal owner without exposing private keys.
Accurate time is also a security control because logs and video events must be correlated. Use the CCTV time synchronization and evidence export worksheet to verify cameras, recorders and operator systems against the approved source.
Test logging and an incident scenario
Enable the access and security logs supported by the chosen system, define their retention location, and confirm that authorized staff can retrieve them. The AXIS OS Forensics Guide recommends reviewing client addresses receiving streams and investigating unknown access attempts. This translates into a useful acceptance test: generate an approved failed sign-in, confirm it appears in the expected log, and verify that the owner knows how to export the record.
Run one tabletop scenario before handover. For example, assume a camera account is exposed or an unknown client is receiving a stream. Record who isolates the device, preserves logs, changes credentials, validates other devices, restores service and closes the incident. The purpose is to prove ownership and recovery, not to perform an unsafe live attack.
Commissioning worksheet
- Inventory: all networked CCTV and supporting infrastructure is listed with owner and software status.
- Accounts: defaults and temporary installer access are removed, and user roles match duties.
- Network paths: approved communication is documented and representative allowed and denied paths are tested.
- Services: unused services and applications are disabled where supported, with exceptions recorded.
- Encryption: management, streaming and remote-access methods are recorded and validated across the actual system.
- Updates: notification, testing, approval, deployment and rollback responsibilities are assigned.
- Certificates: purpose, expiry and renewal ownership are documented where applicable.
- Logs: access records can be retrieved and an approved failed sign-in is visible.
- Remote access: users, method, approval, multi-factor authentication status and revocation process are recorded.
- Recovery: configuration backups and one incident-response scenario are witnessed.
What the owner should receive
Handover should include the approved inventory, network diagram, address plan, account-role matrix, communication matrix, software and certificate register, update procedure, configuration backups, logging procedure, incident contacts, acceptance results and open exceptions. Sensitive credentials, private keys and recovery codes belong in the owner's secure transfer process, not in a widely shared project folder.
Planning a secure CCTV network for a building or campus?
Share the camera schedule, recorder design, switch layout, fiber backbone and remote-viewing requirements. We can coordinate cabling, network segmentation, PoE switching, commissioning records and handover around the selected technology.
Discuss the CCTV network ↗