Electronic Security Systems
Electronic security systems protect commercial and institutional sites such as offices, schools, hospitals, warehouses, banks, and campuses. Three subsystems do most of the work. An intrusion and hold-up alarm system detects break-ins and duress and reports them to a monitoring center. An electronic access control system decides, door by door, whether a credential may open a lock. A video surveillance system captures and records the images that let people assess an alarm and investigate an incident. Integration software ties the three together, while power supplies, networks, and cybersecurity measures keep them working.
This article treats these systems as engineered electronics: the physics of detectors, the supervision of alarm circuits, the interfaces between readers and controllers, the arithmetic of camera resolution and video storage, and the standards used to grade and certify them. Smart Security Systems covers consumer products for the home. Building Automation Systems covers heating, lighting, and energy control in the same buildings, and Critical Infrastructure Protection covers protection programs for utilities and transport networks.
System Architecture and Design Principles
A commercial installation is built in layers. Field devices sit at the edge: detectors, door contacts, card readers, locks, and cameras. Local controllers gather their signals and make time-critical decisions; an intrusion panel decides whether a detector has caused an alarm, and an access control unit decides whether to release a lock. A network carries events, video, and commands to head-end servers that hold databases, recordings, and management software, and an off-site monitoring center watches the intrusion system around the clock.
Keeping decisions in the controllers is a deliberate reliability choice. An access control unit that stores its own credential database keeps admitting authorized people when the server or network fails and buffers events until the link returns, and an intrusion panel keeps detecting and signaling over a backup path. The head end adds coordination and reporting, but the site stays protected without it.
Designers often describe the purpose of the layers as a sequence: deter, detect, delay, assess, and respond. Cameras and signage deter; detectors detect; doors, locks, and safes delay; video and alarm verification let an operator assess; and guards or police respond. The central timing requirement follows: detection must come early enough that the delay still facing the intruder exceeds the time the response needs to arrive. Design therefore starts with a risk assessment of assets, threats, and consequences, which sets the grade or class each subsystem must meet.
| Subsystem | European and international | United States | Industry specifications |
|---|---|---|---|
| Intrusion and hold-up alarms | EN 50131 series; IEC 62642 series | UL 639, UL 681, UL 827, UL 2050 | ANSI/SIA CP-01-2019; SIA DC-05-2016; SIA DC-09-2026 |
| Electronic access control | IEC 60839-11 series, including IEC 60839-11-5:2020 | UL 294; FIPS 201-3 for federal credentials | SIA OSDP 2.2.2; ONVIF Profiles A, C, and D |
| Video surveillance | IEC 62676 series, including IEC 62676-4:2025 | Section 889 procurement rules | ONVIF Profiles G, M, S, and T |
Intrusion Detectors
Intrusion detectors fall into two groups. Perimeter detection on doors, windows, and walls reports an attack on the building shell, and space detection reports a person moving inside a protected room; commercial designs usually combine both. In the United States, UL 639, Standard for Intrusion-Detection Units, covers indoor and outdoor units that detect the presence, movement, or sound of an intruder. In Europe, parts of the EN 50131-2 series cover individual detector types, such as EN 50131-2-3 for microwave detectors and EN 50131-2-7-1 for acoustic glass-break detectors.
Passive Infrared Detectors
The passive infrared (PIR) detector is the workhorse of interior protection, and it emits nothing. A pyroelectric element produces a small charge when the infrared power falling on it changes, and a segmented Fresnel lens or mirror divides the room into narrow zones. Most sensors pair two elements wired in opposition, so a uniform change, such as a drift in room temperature, cancels, while a warm image moving across the zones reaches one element before the other and produces an alternating signal. A PIR detector is therefore most sensitive to motion across its zones and least sensitive to a person walking straight toward it.
Skin near 33 °C (306 K) radiates most strongly near the wavelength given by Wien's displacement law:
λmax = b / T = 2898 µm·K / 306 K ≈ 9.5 µm
The detector responds to the contrast between person and background. Treating both as blackbodies, a fair approximation for skin, the difference in radiant exitance is σ(Tskin4 − Tbg4), where σ is the Stefan–Boltzmann constant and temperatures are in kelvins: about 79 W/m2 against a 20 °C background but only about 13 W/m2 against a 31 °C background. Counting only the 8 to 14 µm band around the emission peak gives almost the same ratio. That sixfold loss is why PIR range shrinks in hot rooms and why many detectors compensate for ambient temperature. Sunlight, heaters, and air from ducts cause many false alarms, and ANSI/SIA PIR-01-2000, Passive Infrared Motion Detector Standard, sets out features intended to enhance false-alarm immunity.
Dual-Technology Detectors
A dual-technology detector adds a microwave Doppler channel to the PIR channel and alarms only when both agree. The microwave section, a small Doppler radar, transmits a low-power signal and mixes the reflection with it. A target moving with radial speed v, much less than the speed of light c, shifts the reflected frequency by
fd = 2vf0 / c
so a person approaching at 1 m/s produces a tone of about 70 Hz at f0 = 10.525 GHz and about 161 Hz at 24.125 GHz. In the United States, 47 CFR 15.245 permits field disturbance sensors, other than perimeter protection systems, to operate in bands that include 10.500 to 10.550 GHz and 24.075 to 24.175 GHz. The two principles fail differently: microwave energy passes through non-metallic partitions and responds to fans and moving blinds, while PIR responds to heat, so requiring agreement removes many nuisance alarms. The price is that defeating either channel silences the detector, which is why detectors for high-risk sites add anti-masking circuits that report a covered or sprayed lens.
Contacts, Glass-Break, and Shock Detectors
Opening contacts pair a reed switch in the frame with a magnet in the moving door, window, or hatch. Because a strong external magnet can hold a simple reed switch closed, high-security doors use balanced magnetic switches, which also change state when an extra magnetic field is applied. Glazing is protected by acoustic glass-break detectors, which analyze the sound of breaking glass across frequency and time to tell it from other loud noises, or by shock sensors on the glass or frame. Fence sensors, buried cables, and infrared or microwave beams extend detection to the site boundary, at the cost of more nuisance alarms from weather and wildlife.
Control Panels, Zones, and Line Supervision
The control and indicating equipment, or alarm panel, is the brain of an intrusion system; EN 50131-3 sets its European requirements. A commercial panel contains a microcontroller, wired zone inputs, a data bus for keypads, expanders, and wireless receivers, outputs for sirens and strobes, a power supply with a standby battery, and one or more communicators. Every action enters an event log.
Detectors are grouped into zones, and zones into areas, or partitions, that can be set independently, so a warehouse can be armed while its office stays open. Entry and exit zones on the normal access route start a timer that gives a user time to unset the system; instant zones alarm at once; and 24-hour zones, such as enclosure tampers and hold-up buttons, stay active whether or not the system is set. A duress code unsets the system in the normal way while silently reporting that the user is under threat.
End-of-Line Supervision
A detector's alarm output is a relay contact at the end of a cable that may run tens of meters. If the panel looked only for an open or closed circuit, an intruder could cut or short the cable in advance. Line supervision builds known resistances into the circuit so that one analog measurement distinguishes several states. With double end-of-line (DEOL) wiring, the normally closed alarm contact is bridged by an alarm resistor RA and connected in series with an end-of-line resistor REOL and a normally closed tamper switch. The panel feeds the loop through a pull-up resistor RP from a reference voltage and, with an input that draws negligible current, measures
Vzone = Vref × Rzone / (RP + Rzone)
| Condition | Loop resistance | Zone voltage | Panel reports |
|---|---|---|---|
| Cable shorted | 0 Ω | 0.00 V | Fault or tamper |
| Alarm contact closed | 2.2 kΩ | 2.50 V | Normal |
| Alarm contact open | 4.4 kΩ | 3.33 V | Alarm |
| Cable cut or tamper switch open | Open circuit | 5.00 V | Tamper |
Decision thresholds midway between the expected voltages fall at about 1.25, 2.92, and 4.17 V. Cable resistance barely matters: a 100 m run of two-conductor 0.22 mm2 copper cable adds about 15.6 Ω of loop resistance and shifts the normal-state voltage by only 9 mV. Wrong resistor values matter far more, and values differ between manufacturers. On this panel, 1 kΩ resistors make an open alarm contact read 2.38 V, inside the normal band, so the zone looks healthy but never reports an alarm. Panels can instead use addressable detectors on a data bus, which report their identity, masking, and faults digitally.
Alarm Transmission and Monitoring
Commercial systems report to a staffed monitoring center, called a central station in North America and an alarm receiving centre in Europe. The panel's communicator formats each event with its zone, event type, area, and user, and delivers it over one or more paths.
Paths and Protocols
The traditional path is a digital communicator that dials the monitoring center over a telephone line. The Ademco Contact ID format, published by the Security Industry Association (SIA) as SIA DC-05-2016, encodes events in standard dual-tone multifrequency (DTMF) tones so that transmitters and receivers from different manufacturers interoperate. As carriers retire copper telephone lines, installations increasingly report over internet protocol. SIA DC-09-2026, SIA DCS-Internet Protocol Event Reporting, an ANSI standard, describes how premises equipment reports events to a central station over IP. Cellular communicators add a path that does not depend on the building's wired network.
Any path can fail silently through a cut cable, a failed router, or a jammed radio, so the path itself is supervised. The communicator sends periodic polling messages, and a missed poll raises a communication fault. Dual-path systems send events over a primary path, typically IP, and a secondary path, typically cellular, and report the loss of either. The polling interval sets how long a cut line can go unnoticed, so higher-risk sites poll more often.
Monitoring and Verification
The monitoring center receives each event, displays it with the site's instructions, and follows a set procedure to verify the alarm, call keyholders, and dispatch guards or police. In the United States, UL 827, Central-Station Alarm Services (ninth edition, 2022), sets requirements for central stations. Its scope includes burglar-alarm service for mercantile and banking premises, fire-alarm service under NFPA 72, residential monitoring stations, redundant sites, and hosted service providers.
False alarms are the chronic weakness of intrusion systems. They waste police time, and some police agencies respond only to verified alarms or require permits. Sequential confirmation treats an alarm as confirmed only when a second, independent detector triggers within a set time. Audio and video verification let an operator hear or see the protected space before dispatch. Panel design matters as much as detection: ANSI/SIA CP-01-2019, Control Panel Standard – Features for False Alarm Reduction, recommends such features for control panels and their arming and disarming devices.
Grading and Certification
In Europe the reference is EN 50131-1, Alarm systems – Intrusion and hold-up systems – Part 1: System requirements. Its current text is the 2006 edition as amended through A3:2020, which added a framework for connecting to and controlling alarm systems remotely. It specifies requirements for systems installed in buildings with wired or wire-free interconnections, defines four security grades, from grade 1, the lowest, to grade 4, the highest, and four environmental classes. Further parts of the series cover detectors, control and indicating equipment, and security fog devices grade by grade; a detector must meet every requirement of its specified grade. The IEC publishes an international series under the same title, IEC 62642.
In the United States, UL 681, Installation and Classification of Burglar and Holdup Alarm Systems (15th edition, 2014, last revised in 2025), covers systems that protect premises, stockrooms, safes, vaults, night depositories, and security containers. It classifies systems as central station, mercantile, bank, proprietary, or national industrial security systems and includes holdup alarm initiating devices; residential systems fall under UL 1641. UL 2050, National Industrial Security Systems (sixth edition, 2025), serves contractor sites that hold classified U.S. government information: the National Industrial Security Program rule at 32 CFR 117.15 names UL 2050 among the criteria for approving an intrusion detection system and requires installation by an alarm service company certified by a nationally recognized testing laboratory.
Certification schemes connect these documents to real installations. An independent body typically audits installing companies, inspects samples of their work, and checks their monitoring arrangements, so insurers and government customers can rely on a declared grade or class. The grade chosen at design then governs detector selection, cabling, standby duration, transmission paths, and maintenance.
Credentials, Readers, and Reader Interfaces
Electronic access control replaces mechanical keys with credentials that can be issued, limited, and revoked centrally. At each door a reader collects a credential and passes it to an access control unit (ACU), which checks it and decides whether to release the lock. Security depends on every link in that chain: credential, reader, wiring, and controller.
Credential Technologies
Authentication factors fall into three categories: something a person has, such as a card or phone; something a person knows, such as a PIN; and something a person is, a biometric. The 125 kHz proximity cards still in common use transmit a fixed number with no cryptography and can be copied with inexpensive equipment. Contactless smart cards at 13.56 MHz under ISO/IEC 14443 can authenticate cryptographically, but only if the cryptography is sound: the widely deployed MIFARE Classic used a proprietary 48-bit cipher that academic researchers reverse-engineered and broke in 2007 and 2008. Current designs use standard ciphers such as AES with keys diversified per card. Mobile credentials do the same job on a phone over near-field communication or Bluetooth Low Energy, and U.S. federal agencies use Personal Identity Verification (PIV) cards specified by FIPS 201-3 (January 2022), whose certificates a physical access control system can validate.
Biometric Readers
A biometric reader compares a live fingerprint, face, iris, or palm-vein sample with an enrolled template and accepts a match whose score exceeds a threshold. Raising the threshold lowers false acceptances and raises false rejections, so the setting is a policy decision made door by door, and liveness detection guards against fake fingers and photographs. Biometric templates are regulated personal data in many jurisdictions.
The Wiegand Interface
For decades most readers connected to controllers through the Wiegand interface, which SIA published in 1996 as SIA AC-01-1996.10, Access Control Standard Protocol for the 26-Bit Wiegand Reader Interface; the subcommittee that sponsored it has since disbanded. Data travel one way, from reader to panel, on two data lines, one pulsed for each 0 bit and the other for each 1 bit. Further conductors carry power and control the reader's LED and beeper.
In the 26-bit layout assumed for this example, an even-parity bit over the first 12 data bits precedes an 8-bit facility code and a 16-bit card number, and an odd-parity bit over the last 12 data bits follows. To encode facility code 123 and card number 4567:
- Write the facility code as 8 bits, 01111011, and the card number as 16 bits, 0001000111010111.
- The first 12 data bits, 011110110001, contain seven 1s, so the leading even-parity bit is 1.
- The last 12 data bits, 000111010111, also contain seven 1s, so the trailing odd-parity bit is 0.
- The reader sends 1, then the 24 data bits, then 0: the frame 10111101100010001110101110, 26 bits in all.
In that layout, 8 bits allow 256 facility codes and 16 bits allow 65,536 card numbers per code: 16,777,216 combinations shared by every site that uses it. Parity detects a single-bit error but provides no secrecy. Because the lines are unencrypted and unsupervised, a small device spliced in behind a reader can record credentials and replay them, and a cut data line looks like an idle reader.
Open Supervised Device Protocol
The Open Supervised Device Protocol (OSDP) replaces Wiegand with a bidirectional, supervised serial link. SIA maintains the specification, currently version 2.2.2 of October 2024, and the IEC published OSDP as IEC 60839-11-5:2020. OSDP normally runs on a two-wire RS-485 bus shared by several readers. Each device takes an address from 0 to 126, the controller can change a device's address and bit rate by command, and continuous polling reports a disconnected or tampered reader at once.
OSDP Secure Channel encrypts and authenticates traffic with AES-128, which SIA describes as required in federal government applications. The specification defines a default secure channel base key, SCBK-D, for setting up new devices, so commissioning must install a unique key. SIA's OSDP Verified program tests product conformance. Because many readers support both interfaces, migration is usually gradual, and it achieves little unless the site also retires 125 kHz cards: an encrypted link that carries a clonable number still admits a cloned card.
| Characteristic | Wiegand | OSDP |
|---|---|---|
| Direction | One way, reader to controller | Two way |
| Wiring | Two data lines plus LED, beeper, and power conductors for each reader | Two-wire RS-485 bus shared by several devices, plus power |
| Supervision | None | Continuous polling reports lost or tampered devices |
| Encryption | None | Secure Channel with AES-128 |
| Standard | SIA AC-01-1996.10 | SIA OSDP 2.2.2; IEC 60839-11-5:2020 |
Controllers, Door Hardware, and Safe Egress
An access control unit serves one or more doors, checking each credential against access levels and schedules, releasing the lock, and watching the door. Controllers also enforce anti-passback, which rejects a card presented twice for entry without an exit between; two-person rules for sensitive rooms; interlocks, which keep both doors of a vestibule from opening together; and elevator control, which enables floor buttons only for authorized cards. In the United States, such equipment is evaluated to UL 294, Standard for Access Control System Units (eighth edition, 2023), which defines four security performance levels, from Level I to Level IV.
Each controlled door needs two inputs besides the reader. A door position switch reports whether the door is closed, and a request-to-exit device, such as a push button, a motion sensor above the door, or a switch in the exit hardware, signals that someone is leaving from the secure side. With both, the controller can tell a legitimate exit from a forced door and raise a held-open alarm when a door stays open too long.
Locking Hardware
The main families of electrified locking hardware are electric strikes, which replace the strike plate and release the latch without retracting it; electromagnetic locks, which hold a steel armature plate against a magnet on the frame; and electrified mortise locks and exit devices, which lock inside the door's own hardware. Each is either fail-safe, unlocking when power is removed, or fail-secure, staying locked without power while still allowing free exit from the secure side. Electromagnetic locks are inherently fail-safe; strikes and electrified locksets can be ordered either way. Fail-safe hardware suits doors that must unlock on power failure or fire alarm, and fail-secure hardware suits perimeter doors and storerooms.
Lock circuits are also a small power-electronics problem. A lock coil is an inductor, so interrupting its current produces a voltage spike that lasts until the stored energy ½LI2 is dissipated, arcing relay contacts and disturbing nearby electronics. A diode across a DC coil clamps the spike but slows the decay of the current, which delays the release of an electromagnetic lock; a diode in series with a Zener diode, or a varistor, clamps at a higher voltage and releases faster. Voltage drop on long runs matters as much; along the cable it is
Vdrop = 2IρLc / A
where I is the lock current, Lc the one-way cable length, A the conductor area, and ρ = 1.72 × 10−8 Ω·m for copper at 20 °C. A 0.5 A lock at the end of 100 m of 0.75 mm2 cable loses 2.3 V, or 19 percent of a 12 V supply; doubling the conductor area halves the loss. A lock that receives too little voltage may hold weakly or fail to retract.
Egress and Life Safety
Security must never trap people in a fire. Building and fire codes, in the United States the NFPA 101 Life Safety Code and the International Building Code, set the conditions under which a door on an exit route may be electrically locked, including how the lock must behave on power failure and on fire alarm activation. Designers commonly release such locks through a hardwired connection from the fire alarm system rather than through software integration, and the authority having jurisdiction approves each arrangement.
Video Surveillance Cameras and Image Quality
Current commercial systems use IP cameras: embedded computers with an image sensor, an image signal processor, a video encoder, and a network interface. Power over Ethernet delivers power and data on one cable. IEEE 802.3at provides 30 W at the switch port and about 25.5 W at the camera, while pan-tilt-zoom cameras with heaters and infrared illuminators may need IEEE 802.3bt, which reaches 90 W at the port. Outdoor housings are rated for ingress under IEC 60529, for example IP66, and for impact under IEC 62262, where IK10 corresponds to a 20 J impact. Planning guidance comes from IEC 62676-4, Video surveillance systems for use in security applications – Part 4: Application guidelines, whose second edition was published on October 9, 2025.
Pixel Density and Field of View
Camera selection starts from the task each view must support: detecting that a person is present takes far fewer pixels than recognizing a known individual or identifying a stranger. The practical measure is pixel density on the target, in pixels per meter across the scene. For a camera with N horizontal pixels and a distortion-free lens of horizontal field of view θ, the width W of a scene plane square to the lens axis at distance d and the pixel density PD are
W = 2d tan(θ/2) and PD = N / W
The required density for each task comes from the site's operational requirement and the current edition of IEC 62676-4. With an illustrative requirement of 250 px/m at a doorway 10 m from the camera:
- A 1920-pixel camera must cover a scene no wider than W = 1920 / 250 = 7.68 m.
- At 10 m, that width corresponds to a field of view of θ = 2 arctan(7.68 / 20) ≈ 42°.
- The same camera with a 90° lens covers 20 m at that distance and delivers only 96 px/m.
- A 3840-pixel camera meets the requirement with a field of view up to about 75°, or it keeps a 90° view but reaches 250 px/m only out to 7.68 m.
Lens sharpness, focus, motion blur, compression, and lighting all reduce the detail recorded, so the density is confirmed on site with a test target.
Low Light, Contrast, and Compression
Infrared illuminators let a camera switch to monochrome imaging at night. Emitters at 850 nm show a faint red glow, while 940 nm emitters are nearly invisible but reach less far, because silicon sensors respond more weakly at that wavelength. Wide dynamic range processing combines exposures to render a bright doorway and a dim lobby in one frame. Thermal cameras detect people and vehicles by their heat in darkness and light fog but cannot identify a face. Manufacturers measure low-light sensitivity under differing conditions, so site trials are more reliable than datasheet lux figures. Bit rates from H.264 and H.265 encoders rise with movement, foliage, rain, and low-light sensor noise, so night-time rates often exceed daytime rates; variable bit rate encoding with a cap keeps storage predictable.
Recording, Video Management, and Storage
A network video recorder (NVR) is an appliance that receives camera streams, writes them to internal disks, and serves live and recorded video. A video management system (VMS) is software on standard servers that scales across many recorders and sites and adds failover recording, user management, maps, alarm handling, and access control integration. Cameras can also record to a memory card to cover network outages.
ONVIF Profiles
Interoperability between products from different manufacturers rests largely on ONVIF, an industry forum whose profiles define the features that conformant devices and clients support. Conformance is declared per profile, so a buyer checks that camera, recorder, and software share the profiles a feature needs. ONVIF deprecated Profile Q on April 1, 2022, and is deprecating Profile S, for which March 31, 2027, is the last date for product conformance submissions; Profile V has release-candidate status.
| Profile | Used by | Scope |
|---|---|---|
| S | Video | Basic video streaming and configuration; deprecation in process |
| T | Video | IP video streaming with H.264 and H.265 encoding, imaging settings, and motion and tampering events |
| G | Video | Recording on the device or over the network, and client control of recording |
| M | Video and access control | Metadata and events for analytics applications, including metadata for geolocation, vehicles, license plates, faces, and bodies |
| A | Access control | Configuration of access rules, credentials, and schedules, and retrieval of status and events |
| C | Access control | Site information, door access control, and event and alarm management |
| D | Access control and video | Peripherals such as token readers, biometric readers, recognition cameras, keypads, and sensors, and outputs such as locks, displays, and LEDs |
Storage Sizing
Recorder storage follows from camera count, bit rate, retention period, and the fraction of time each camera records:
C = N × R × 86,400 s/day × D × k / 8
where C is the capacity in bytes, N the number of cameras, R the average bit rate in bits per second, D the retention in days, and k the recording duty factor, equal to 1 for continuous recording. With illustrative inputs:
- Take 64 cameras averaging 4 Mbit/s, recording continuously for 30 days.
- One camera writes 4 × 106 × 86,400 / 8 bytes, or 43.2 GB, per day, and 1.296 TB in 30 days.
- Sixty-four cameras need 82.9 TB, or 75.4 TiB, before file-system overhead.
- A RAID 6 array of twelve 10 TB drives gives ten drives of usable capacity, 100 TB (90.9 TiB), which the archive fills to about 83 percent, leaving little margin.
- Recording only on motion, with an assumed duty factor of 0.4, cuts the requirement to 33.2 TB, at the risk of missing events the motion trigger does not catch.
- The recorders must also ingest 64 × 4 = 256 Mbit/s continuously, about a quarter of a 1 Gbit/s link, before allowing for bit-rate peaks.
Retention and Evidence
Retention periods come from policy, contracts, and law, and data-protection rules in many jurisdictions forbid keeping footage longer than necessary. For recordings to serve as evidence, cameras and recorders must share an accurate time source, exports should carry a digital signature or hash that reveals alteration, and the system should log who viewed, exported, or deleted footage.
Video Analytics and Privacy-Law Touchpoints
No operator can watch hundreds of screens attentively, so analytics software watches them instead. Classic video motion detection flags changing pixels and is easily fooled by shadows, rain, and headlights. Current analytics use neural networks, in the camera or on servers, to classify people and vehicles and apply rules to them: crossing a virtual line, loitering near an entrance, entering an area that should be empty, or leaving an object behind. License plate recognition reads vehicle registrations at gates, face recognition compares faces with a watch list, and the resulting metadata lets investigators search long recordings without replaying them.
Performance figures for analytics are vendor claims measured under the vendor's conditions. Accuracy depends on placement, pixel density, lighting, and weather, so every rule should be tested on site at night and in bad weather and tuned against the nuisance alerts it produces. An analytic that floods operators with false alerts trains them to ignore it.
Surveillance and biometric systems also carry legal obligations that shape camera placement, retention, and feature selection. The following are touchpoints to check with counsel for each deployment, not legal advice:
- European Union, General Data Protection Regulation. Article 9 of Regulation (EU) 2016/679 prohibits processing biometric data for the purpose of uniquely identifying a person unless an exception applies, such as explicit consent or obligations under employment law authorized by law. Recital 51 explains that photographs count as biometric data only when processed through specific technical means that allow unique identification or authentication. Article 35 requires a data protection impact assessment for systematic monitoring of a publicly accessible area on a large scale.
- European Union, Artificial Intelligence Act. Article 5 of Regulation (EU) 2024/1689 prohibits AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage, and it restricts real-time remote biometric identification in publicly accessible spaces for law enforcement to narrowly defined cases.
- Illinois, Biometric Information Privacy Act. The act, 740 ILCS 14, requires a private entity to publish a retention and destruction policy; to inform people in writing and obtain a written release before collecting biometric identifiers such as fingerprints or scans of face geometry; and to destroy them when the purpose has been satisfied or within three years of the person's last interaction, whichever comes first. A prevailing party may recover liquidated damages of $1,000 for each negligent violation and $5,000 for each intentional or reckless one, or actual damages if greater; a 2024 amendment treats repeated collection from the same person by the same method as a single violation.
- United States, federal procurement. Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019, implemented by FAR 52.204-25, bars executive agencies from procuring equipment or systems that use covered telecommunications equipment as a substantial or essential component, and from contracting with entities that use it. Covered equipment includes video surveillance and telecommunications equipment produced by Hytera, Hikvision, or Dahua, or their subsidiaries and affiliates, for public safety, security of government facilities, physical security surveillance of critical infrastructure, and other national security purposes.
Integration and PSIM Platforms
The subsystems become far more useful when they share events. A forced door can call up the nearest camera on the operator's screen and bookmark the recording. An intrusion alarm can lock internal doors and switch on lights. Integration happens at several levels. The simplest is hardwired: a relay output on one system drives an input on another, which is robust and easy to test but limited to on-off signals. High-level integration uses software interfaces, either vendor application programming interfaces or open specifications such as the ONVIF profiles, to pass detailed events, video, and commands. Many manufacturers also sell unified platforms in which access control, video, and intrusion detection share one database and user interface.
Physical security information management (PSIM) software sits above the individual systems. It collects events from access control, video, intrusion, fire, intercom, and building systems from many vendors. It correlates them, so that a door alarm, a motion event, and a camera analytic in one corridor appear as a single incident. It presents the incident on a map with live video, guides the operator through the site's standard operating procedure, and records every action for audit. PSIM suits large, multi-site, or high-consequence operations, where operators must handle many systems consistently and show afterward what they did.
Integration with building automation runs both ways, sharing occupancy information and equipment alarms. Two rules keep integration safe. First, life-safety functions, such as fire alarm release of locks, stay on dedicated hardwired interfaces that work when the integration server does not. Second, every integration path is a network connection that an attacker could use, so each one belongs inside the network design described under cybersecurity below.
Power Supplies and Battery Backup
Security systems must keep working when the mains fails, and an intruder may cut the power deliberately. Intrusion panels, access controllers, and lock power supplies therefore include a charger and a standby battery, usually a 12 V or 24 V valve-regulated lead-acid battery, and they report their own faults: mains failure, low battery, charger failure, and blown output fuses. Separately fused or current-limited outputs keep a short on one circuit from disabling the whole system. The standby period the battery must support is set by the applicable standard, the insurer, or the contract.
Battery Sizing
A battery must carry the standby load for the required period and then still power the warning devices through an alarm. With standby current Is for ts hours, total alarm-state current Ia for ta hours, and a margin factor m for aging and low temperature, the required capacity in ampere-hours is
CAh = (Ists + Iata) × m
- Take an illustrative panel with detectors and keypads that draws 0.55 A in standby and 1.40 A with sirens sounding, a 24-hour standby requirement, and a 15-minute alarm period.
- Standby consumes 0.55 × 24 = 13.2 Ah and the alarm 1.40 × 0.25 = 0.35 Ah, for a total of 13.55 Ah.
- A 25 percent margin raises the requirement to 16.9 Ah, so the designer selects the next standard size above it, such as an 18 Ah battery.
- The designer then confirms that the charger can recharge that battery within the time the applicable standard allows.
Rated capacity applies at a specified discharge rate and temperature. Capacity falls at higher currents, in the cold, and with age, which is why the margin exists and why batteries are load-tested and replaced on a schedule. Fail-safe electromagnetic locks draw current all the time, so eight locks at 0.5 A each draw 4 A, or 48 W at 12 V, around the clock, and keeping them locked for 4 hours after a mains failure takes 16 Ah before margin. The PoE switches that power cameras, and the servers and recorders at the head end, need uninterruptible power supplies sized for the same outage, because a system that detects an intruder but cannot record or report the event has failed.
Cybersecurity of Physical Security Devices
Every camera, recorder, access controller, IP reader, and alarm communicator is a networked computer, often left untouched for years after installation. Such devices have already been conscripted at scale. Alert TA16-288A, issued on October 14, 2016, and now published by the Cybersecurity and Infrastructure Security Agency (CISA), reported that the Mirai botnet had infected Internet of Things devices, primarily home routers, network-enabled cameras, and digital video recorders, by trying a short list of 62 common default usernames and passwords. Attacks attributed to such botnets exceeded 620 Gbps against the KrebsOnSecurity website and reached at least 1.1 Tbps against the hosting company OVH.
Physical security devices face two kinds of attack. Network attacks exploit default passwords, unpatched firmware, exposed management interfaces, and unencrypted protocols; they can turn a camera into a foothold inside the corporate network or blind the system before a break-in. Field attacks exploit the edge: cloning 125 kHz cards, tapping Wiegand wiring, or opening a reader to reach its terminals. Defenses include:
- Change every default password at installation, give each device unique credentials, and disable unused services such as Telnet and Universal Plug and Play.
- Place security devices on segmented networks with firewalls that allow only the flows the system needs, never expose cameras or recorders directly to the internet, and provide remote access through a managed gateway.
- Authenticate devices to the network with IEEE 802.1X where supported, and encrypt management traffic and video with TLS using managed certificates.
- Keep an inventory of devices and firmware versions, follow manufacturers' security advisories, apply signed firmware updates, and replace devices that no longer receive them.
- Enable OSDP Secure Channel with unique keys, retire 125 kHz credentials, and fit tamper switches to readers and controller enclosures.
- Send device and server logs to central monitoring so that failed logins and configuration changes are noticed.
The zone-and-conduit model of IEC 62443, described in Industrial Cybersecurity, suits the security network well: treat the video system, the access control system, and the alarm communicators as zones, and define every conduit between them and the enterprise network explicitly. Beyond the Section 889 procurement restrictions described above, the European Union's Cyber Resilience Act, Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements, such as networked cameras, recorders, and controllers. It entered into force on December 10, 2024; its reporting obligations for manufacturers apply from September 11, 2026, and its main obligations from December 11, 2027.
Installation, Commissioning, and Maintenance
Good installation begins on paper. A design package records the risk assessment, the grade or class, device locations and coverage, each camera view with its required pixel density, cable schedules, the IP address plan, and the power, battery, and storage calculations. Installers work to it and record every departure.
Installation Practice
Detection and data cables run apart from mains wiring, or cross it at right angles, to limit induced noise. RS-485 buses use twisted pair daisy-chained from device to device, with termination at both ends of the bus and the shield grounded at one point. Outdoor cameras, gate readers, and cables between buildings need surge protection at both ends and bonding to the grounding system, as described in Lightning and Surge Protection. Detectors are mounted as their manufacturers specify, away from heaters, vents, and direct sunlight, and cameras are placed so that faces are not backlit by windows or low sun.
Commissioning and Acceptance
Commissioning proves that the installed system does what the design says, device by device and then as a whole:
- Walk-test every detector and confirm the zone and description reported at the panel and at the monitoring center.
- Test every tamper and fault condition: open enclosures, short and cut zone wiring, remove mains power, and disconnect the primary path to confirm that the backup path reports.
- At each door, test valid and invalid credentials, request-to-exit, forced-open and held-open alarms, lock release, behavior on power failure, and release by the fire alarm system.
- For each camera, check the field of view and pixel density against the design with a test target by day and by night, and confirm recording, time stamps, export, and, once the retention period has passed, the survival of the oldest required recordings.
- Test each integration end to end, and confirm that default passwords are gone, firmware is current, and unused services are disabled.
- Hand over as-built drawings, schedules, network and credential records, and training, and obtain the client's written acceptance.
Maintenance and Troubleshooting
Maintenance intervals come from the applicable standard, the insurer, and the service contract. A routine visit walk-tests detectors, cleans lenses and camera windows, load-tests batteries, checks both transmission paths, reviews logs for recurring faults, and confirms that recordings are complete. Credential audits remove people who have left, and firmware reviews catch devices that have fallen behind.
| Symptom | Likely causes | First checks |
|---|---|---|
| Repeated false alarms from one detector | Heat sources, drafts, sunlight, insects, or poor mounting | Compare alarm times with heating and sun patterns; inspect the detector's view |
| OSDP reader drops offline | Missing bus termination, reversed polarity, duplicate address, or low supply voltage | Check termination, addresses, and voltage at the reader |
| Gaps in recorded video | Network congestion, disk failure, or storage undersized for night bit rates | Compare camera bit rates with design values and check disk health |
Conclusion
Electronic security systems join detection, access control, and video into one protective chain, and each link can be engineered and tested. Detectors turn infrared contrast, Doppler shifts, and opening contacts into supervised signals a panel can trust. Access control depends on credentials that resist copying, supervised and encrypted reader links, and door hardware that fails in the right direction. Video depends on pixel density matched to the task and on storage sized by arithmetic. Integration multiplies the value of all three, provided that life safety stays on hardwired interfaces and every connection sits inside a deliberate network design.
Standards such as EN 50131, the UL alarm classifications, OSDP, IEC 62676-4, and the ONVIF profiles give designers and customers a shared measure of adequate protection. A system designed from a risk assessment, commissioned against that design, and maintained afterward keeps protecting people and property for years.