Security system level protection: What requirements should the video surveillance part meet?
Sort out the requirements directly related to the video surveillance system in MLPS 2.0, including identity authentication, access control, audit logs and data integrity, and provide a list of rectifications that can be implemented.
Which systems require waiting maintenance
If the video surveillance system belongs to critical information infrastructure or is included in the classification scope, It needs to be constructed and rectified according to the requirements of Class Protection 2.0. Most security projects involve level two, Some government, financial, and energy projects are Level 3.
Requirements directly related to video surveillance
| Aspects | Key points of requirements | implementation practices |
|---|---|---|
| Identity Authentication | Unique identification + password complexity + failed lockout | Disable default account, enable complexity policy and lockout |
| Access control | Assign permissions by role, default minimum permissions | Distinguish between administrators/operators/auditors |
| Security audit | Record key operations and keep logs for more than 6 months | Enable platform audit and store logs independently |
| Data integrity | Anti-tampering of important data | Video file verification and anti-deletion |
| Border protection | Network area isolation | Separation of video network and office network |
Rectification list (can be directly compared and executed)
- Clear all default accounts and shared accounts, make each person have a separate account, and log out promptly after resignation.
- Password policy: length ≥8 (recommended ≥12), complexity requirements, 90-day replacement, 5 failed lockouts.
- Enable platform operation auditing: log-ins, configuration changes, video deletions, and video exports must leave traces.
- The logs are sent to independent storage to avoid being deleted by the machine; they are retained for no less than 6 months.
- The video network and the office network are VLAN or physically isolated, and the front-end camera network segment is prohibited from accessing the Internet.
- Close redundant services on the device (Telnet, FTP, UPnP), and upgrade the firmware to the manufacturer's latest secure version.
- Enable watermark or verification mechanism on video files, encrypt them when exporting and record the operator.
Common misunderstandings
It is inaccurate to interpret waiting guarantee as "buying a firewall" or "doing an evaluation". It is more about the implementation of management systems and technical configurations. Most of the items in the above list It is a configuration and process issue and does not require the purchase of additional equipment.
Related content
Linkage integration of video surveillance, access control, and alarm systems: interface methods and implementation points
09-19
Moiré and false color in surveillance images: lens and sensor matching issues
09-18
Progressive transformation from analog to network: reusing coaxial and hybrid networking solutions
09-17
Lens dirt and protective window cleaning: invisible causes of image quality degradation
09-16
Surveillance video as evidence: retrieval process, preservation and legal effect
09-15
Permission classification and desensitization of video data: who can watch and who can export
09-14
Computer room dynamic environment monitoring: temperature and humidity, mains power, water leakage and smoke detector access
09-12
UPS selection and backup time calculation: Monitor how long it will last after a power outage
09-11
