← All CCTV Flashcard Decks

CCTV Security Standards and Compliance Flashcards

6 cards from real CCTV practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CCTV Security Standards and Compliance flashcards as text
  1. What does 'cybersecurity hardening' of an IP CCTV system typically include?

    Answer: Changing default passwords, disabling unused ports/services, applying firmware updates, and network segmentation

    Cybersecurity hardening involves multiple practices including changing default credentials, disabling unnecessary network services, keeping firmware updated, and isolating cameras on a separate VLAN.

  2. What is a 'VLAN' and why is it used in IP CCTV network architecture?

    Answer: A Virtual Local Area Network used to logically isolate camera traffic from other corporate network traffic

    A VLAN segments the camera network from other IT systems, limiting the impact of a compromised camera on corporate systems and reducing attack surface.

  3. What is the purpose of 'video integrity verification' or digital watermarking in CCTV systems?

    Answer: To detect or prove whether recorded footage has been altered or tampered with

    Digital watermarking or hash-based integrity verification embeds or generates a unique signature for footage, allowing detection of any post-capture editing or tampering.

  4. Which US body publishes cybersecurity guidelines applicable to video surveillance systems in critical infrastructure?

    Answer: National Institute of Standards and Technology (NIST)

    NIST publishes the Cybersecurity Framework and Special Publications (e.g., NIST SP 800-82) that guide cybersecurity practices for industrial and physical security systems including CCTV.

  5. What does it mean for a CCTV system to be 'FedRAMP authorized' in a US government context?

    Answer: The system has been independently tested and approved for use in US federal government cloud environments

    FedRAMP (Federal Risk and Authorization Management Program) is a government-wide program providing standardized security assessment and authorization for cloud products used by federal agencies.

  6. When a US company receives a law enforcement request for CCTV footage, what is the generally recommended first step?

    Answer: Preserve the relevant footage immediately and consult legal counsel before releasing it

    Organizations should immediately preserve relevant footage to prevent overwriting, then consult legal counsel to verify the request is properly authorized (e.g., via subpoena or court order) before releasing.