Why this module exists. Most Indian enterprises have CCTV; few have CCTV that catches anything before-the-fact. The difference is in coverage planning, retention discipline, and integration with the SOC. This module covers what works.
CCTV coverage — where to place cameras
The principle: cover every transition between zones and every high-value asset. Practitioner placement list:
- Every external entry / exit, with sufficient resolution to identify faces at distance.
- Reception area — entry + exit + employee transit through.
- Every transition between security zones — corridor cameras catching the door.
- Data centre — cage entry, hot aisle, cold aisle, equipment racks.
- Critical IT equipment — KVM stations, console access points.
- Loading docks and any goods-receiving area.
- Parking — at least entry / exit and major rows.
The trap: covering generic floor space at high density (10 cameras per floor) while leaving transitions uncovered. Plan from threat model: who comes in, where do they go, where would they touch your data — that is where the cameras go.
Resolution and retention
- Resolution. Faces identifiable at 2-3 metres requires ~80 pixels per face. With 1080p cameras and standard lenses, that means careful placement; a single wide-angle camera covering a corridor will produce identification-poor footage of anyone more than 3 metres from the camera.
- Retention. 30 days is a common default. For critical zones (data centre, executive areas), 90+ days. For high-value retention (potentially evidentiary): 1 year, on dedicated NVR storage.
- Storage location. NVR / VMS on a separate VLAN with no internet access. Physical access to the NVR is itself a Tier-2 security zone.
Modern video analytics
Modern CCTV systems support analytics that materially expand the detective surface:
- Tailgating detection. Computer vision flags when two people enter on a single badge swipe. Real-time alert to SOC.
- Loitering detection. Person stationary in a sensitive area for >N minutes. Alerts on attacker recon behaviour.
- License plate recognition (LPR). Vehicle in/out logs. Useful for after-incident traceback.
- Crowd density. Useful for fire safety; secondary for security.
- Face recognition. Highly accurate, deployed for staff identification or known-suspect watchlists. DPDP-sensitive; deploy carefully.
The DPDP angle: video footage of identifiable individuals is personal data. Retention beyond business need, sharing with third parties, and certain analytics use cases trigger DPDP obligations.
Visitor management — the prerequisite
Visitors are the highest physical-access risk class. Modern visitor management systems integrate with badge issuance:
- Pre-registration by the internal host; visitor receives confirmation email with QR code.
- Arrival: visitor scans QR at kiosk, photo captured, ID verified by reception.
- Visitor badge printed with photo, host name, valid time window, zone restrictions.
- Host notified of arrival; required to escort throughout.
- Visitor badge deactivates automatically at end of valid window.
- Departure logged at kiosk.
Indian enterprises commonly deploy systems like Envoy, SmartSpace, Spintly. The cost is modest; the discipline-cost is convincing operations and senior managers to actually pre-register visitors.
The visitor-of-employee problem
Personal visitors of employees (family, friends, deliveries) routinely sneak through visitor management. The right policy:
- All visitors register; no exceptions.
- Deliveries received at a separate dock; couriers do not pass reception.
- Family members can have permanent visitor badges if frequent; same registration + escort requirements.
Integrated incident response — physical + cyber
The mature programme integrates physical incidents into the SOC. Examples:
- Door-held alarm fires while SIEM shows unusual login from a new device on the same floor → correlated incident.
- Badge swipe at 3am for employee on leave → automatic alert, investigate.
- CCTV motion-detection in server room at off hours → physical-IR fork.
The integration point is the SOC. Physical-security team operations get routed through the same ticketing / SIEM that handles cyber events. Cross-discipline investigators handle the integration cases.
The CCTV-on-an-incident workflow
- Incident triggers CCTV retrieval — automated where possible, manual otherwise.
- Footage is preserved with hash, timestamp, camera identifier.
- Section 65B certificate generated for the export (NVR is the “computer” producing the record).
- Chain of custody for the footage as evidence.
- Footage reviewed for the relevant time window plus 30 minutes on either side.
Common failure modes
- Camera blind spots. Coverage planned generically rather than by threat model.
- NVR exposed to internet. Default ports forwarded for remote viewing; routinely scanned and exploited.
- Footage retention shorter than incident detection window. Incident discovered 60 days later; footage purged at day 30.
- Analytics fatigue. Too many false-positive tailgating alerts; SOC mutes the rule; real events missed.
- DPDP exposure. Face recognition deployed without consent management; legal risk if challenged.
Key takeaways
- Plan camera coverage from threat model: zone transitions, high-value assets, entry/exit.
- Resolution sufficient for face ID; retention 30/90/365 days by zone criticality.
- Analytics (tailgating, loitering, LPR) materially expand the detective surface — and create DPDP exposure.
- Visitor management is non-negotiable; pre-registration + escort + time-bounded badge.
- Integrate physical and cyber incident response through the SOC.
- CCTV-as-evidence workflow needs Section 65B certificate at the time of export.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.