
Organizations protecting Controlled Unclassified Information (CUI) often focus heavily on cybersecurity controls such as multifactor authentication, encryption, vulnerability management, and network protection. Physical security, however, remains an equally important part of protecting the systems and environments where CUI is processed, stored, or transmitted.
Video monitoring can provide an effective component of that physical security program, but simply installing cameras does not automatically satisfy NIST SP 800-171.
An effective video monitoring system must support a defined security objective. Organizations should determine what locations must be monitored, what activity needs to be detected, how suspicious activity will be identified, who will review monitoring information, how incidents will be handled, and where recordings will be stored.
Those decisions become particularly important when comparing NIST SP 800-171 Revision 2 with Revision 3. Revision 3 retains the fundamental objective of protecting facilities containing systems that process, store, or transmit CUI, but substantially increases the specificity surrounding physical monitoring, access records, response, and Department of Defense (DoD) organization-defined review frequencies.
Start With the Requirement, Not the Camera
Under NIST SP 800-171 Revision 2, requirement 3.10.2 directs organizations to protect and monitor the physical facility and supporting infrastructure for organizational systems.
NIST SP 800-171A Rev. 2 breaks that requirement into four assessment objectives, two of which involve evidence that require the in scope environment to be monitored:
- 3.10.2[c] – the physical facility where organizational systems reside is monitored.
- 3.10.2[d] – the support infrastructure for organizational systems is monitored.
The assessment procedures identify physical access logs, monitoring records, access-log reviews, policies, procedures, and the System Security Plan as potential evidence. They also contemplate testing the mechanisms used to monitor physical access.
Revision 3 restructures this concept.
NIST SP 800-171 Rev. 3 Requirement 03.10.02 – Monitoring Physical Access requires organizations to:
- 03.10.02.a[01] physical access to the facility where the system resides is monitored to detect physical security incidents.
- 03.10.02.b[01] physical access logs are reviewed <at least every 45 days>.
- 03.10.02.b[02] physical access logs are reviewed upon occurrence of <significant, novel incidents, or significant changes to risk>.
NIST specifically identifies video surveillance equipment, guards, and sensor devices as examples of mechanisms that can support physical access monitoring.
Significant Rev. 2 to Rev. 3 Change
Revision 2 broadly required that facilities and supporting infrastructure be “protected and monitored.” Revision 3 makes the expected outcome considerably clearer. Monitoring must support detection and response. This change has direct implications for how a video monitoring program should be designed.
A camera that records continuously but whose footage is never reviewed may provide useful forensic evidence after an incident, but it does not necessarily demonstrate an effective process for detecting and responding to physical security incidents.
What Should Video Monitoring Accomplish?
Before purchasing equipment, an organization should define the purpose of surveillance.
Possible objectives include:
- detecting unauthorized facility entry
- monitoring entrances and exits
- detecting activity in restricted areas
- verifying visitor movement
- investigating suspected physical security incidents
- identifying after-hours access
- correlating video with electronic access-control records
- deterring theft or unauthorized activity
- preserving evidence following an incident. (DFARS-252.204-7012 requirement support)
These purposes directly support Rev. 3 Requirement 03.10.02 when cameras are used as part of the organization’s physical access monitoring capability. Video also supports Rev 3 requirement 03.10.07 – Physical Access Control, which requires organizations to enforce physical access authorizations at entry and exit points, maintain physical access audit logs, escort visitors and control their activity, secure physical access devices, and protect output devices from unauthorized physical access.
Relevant Rev. 3 assessment objectives include:
- A.03.10.07.a.01 – physical access authorizations are enforced at entry and exit points to the facility where the system resides by verifying individual physical access authorizations before granting access.
- A.03.10.07.a.02 – physical access authorizations are enforced at entry and exit points to the facility where the system resides by controlling ingress and egress with physical access control systems, devices, or guards.
- A.03.10.07.b – physical access audit logs for entry or exit points are maintained.
A camera does not replace these controls. Instead, it can provide evidence that access-control processes are operating as intended and can help investigate anomalies identified by those systems.
Continuous Monitoring Versus Periodic Monitoring
One of the most important design questions is how frequently the organization needs to monitor activity. Three concepts should be distinguished:
Continuous recording means the camera records continually.
Continuous live monitoring means personnel or a monitoring service actively observe activity or alerts and can respond quickly. Continuous monitoring provides the greatest opportunity to detect and respond to an incident while it is occurring.
Periodic monitoring means recorded activity, physical access information, or selected events are reviewed according to an established schedule.
These approaches have substantially different costs and security benefits.
Continuous Live Monitoring
Continuous monitoring provides the greatest opportunity to detect and respond to an incident while it is occurring.
It may be justified for:
- highly sensitive facilities
- locations operating around the clock
- areas containing particularly valuable systems or assets
- environments with elevated physical threats
- locations where immediate intervention significantly reduces risk
The primary disadvantage is cost.
A true 24-hour monitoring capability requires more than one employee watching a screen. Organizations must account for shifts, weekends, holidays, leave, supervision, training, and response procedures. A contracted security operations or monitoring service can reduce internal staffing requirements but introduces recurring service costs and third-party considerations.
NIST SP 800-171 does not establish a blanket requirement for someone to continuously watch camera feeds. The organization should therefore determine whether continuous observation is justified by risk.

Continuous Recording With Event-Driven Review
For many organizations, a more efficient model is continuous recording combined with alerts and event-driven review.
Examples of events that might cause investigation include:
- access outside normal business hours
- repeated denied badge attempts
- a forced-open door
- entry into a restricted area
- unusually long presence in a controlled area
- use of an access point inconsistent with normal activity
- a reported physical security incident
These examples align closely with the discussion supporting Rev. 3 Requirement 03.10.02. NIST specifically identifies suspicious activities such as access outside normal work hours, repeated access to unusual areas, unusually long access, and out-of-sequence access as examples of activities relevant to physical access monitoring.
An integrated access-control and camera system can be particularly valuable. If an electronic badge system identifies an unusual access event, the organization can immediately review the corresponding camera recording.
Periodic Monitoring
Periodic review may also be appropriate, particularly for lower-risk environments.
However, “periodic” must mean more than occasionally viewing footage.
Under Rev. 3, an organization adopting periodic monitoring should explicitly define:
Frequency: How often will physical access information be reviewed? DoD has defined the periodicity as “at least every 45 days”.
Scope: Which entrances, records, cameras, or events will be examined?
Responsibility: Who performs the review?
Event triggers: What circumstances require immediate review outside the normal schedule?
Response: What happens when suspicious activity is identified?
Evidence: How will the organization demonstrate that the reviews occurred?
Revision 3 therefore provides organizations flexibility while requiring them to make and document their own risk-informed decisions.
An organization might determine, for example, that physical access activity is reviewed every 30 days, while immediate review occurs following after-hours access, repeated denied access attempts, reported security incidents, or other predefined anomalies.
Local Video Storage or Cloud-Based Services?
Another major decision is where video will be processed and stored.
Locally Managed Video Systems
A locally managed system generally stores recordings on an NVR, server, appliance, or other storage controlled by the organization.
Advantages may include:
- direct organizational control over recordings
- reduced dependence on external service providers
- greater control over network architecture
- the ability to operate during Internet outages
- more direct control over retention and destruction
The tradeoff is that the organization assumes responsibility for maintaining the system.
That may include:
- firmware and software updates
- hardware maintenance
- account administration
- storage capacity
- access control
- vulnerability management
- backup power
- equipment replacement
- security monitoring
Cloud-Based Video Systems
Cloud-managed systems can reduce local infrastructure and simplify centralized management, particularly for organizations with several locations.
Potential advantages include:
- centralized administration
- remote access
- reduced local storage infrastructure
- scalable retention
- provider-managed platform maintenance
- easier multi-site monitoring
The security question becomes more complicated if video leaves organizational control.
Before selecting a cloud-based surveillance solution, organizations should determine:
- where recordings are stored
- whether data is encrypted during transmission and storage
- who can access recordings
- whether multifactor authentication is supported
- whether administrative activity is logged
- how recordings are deleted
- what happens to recordings after termination of the service
- whether the provider uses subcontractors
- whether recordings can be exported
- whether the service could receive CUI
That final question is particularly important since this would require the third-party to be FedRAMP Moderate (or higher) Authorized/or equivalent, or CMMC Level 2 certified.
Could the Camera Record CUI?
Security cameras can capture much more information than the organization intends.
A camera intended to observe a doorway may also capture:
- computer displays
- engineering drawings
- whiteboards
- printed documents
- production processes
- shipping information
- identification badges
- sensitive conversations if audio is enabled
If CUI is visible within the recording, the video itself may contain CUI.
This significantly changes the architecture decision.
NIST SP 800-171 requirements apply to system components processing, storing, or transmitting CUI and components providing security protection for them.
Therefore, sending surveillance footage containing CUI to an externally hosted platform should not be treated merely as a convenient video-storage decision.
The organization should first determine whether the service is authorized to receive and protect that information and whether using the service changes the system boundary or security responsibilities.
A practical design principle is simple:
Camera placement, privacy masking, restricted fields of view, and disabling unnecessary audio can prevent a physical security tool from becoming an unnecessary repository of sensitive information.
Camera Placement Matters
A camera is useful only if it captures evidence appropriate to the intended security objective.
A wide field of view may show that someone entered a large room but provide insufficient detail to identify the individual.
Conversely, a strategically positioned camera at an entry point may capture much more useful information.
Camera placement should consider whether the objective is:
Detection
Is someone present in an area where they should not be?
Recognition
Can personnel determine whether the individual appears to be an employee, visitor, or unknown person?
Identification
Does the image provide sufficient detail to determine who the individual is?
Important placement considerations include:
- camera height
- viewing angle
- distance from the expected subject
- image resolution
- lighting
- backlighting
- nighttime performance
- doors or equipment that may obstruct the view
- expected direction of travel
- potential camera tampering
- overlapping coverage
- privacy considerations
A camera mounted high in the corner of a room may provide excellent situational awareness while producing poor identification evidence.
Similarly, a camera facing an exterior entrance may capture only a silhouette when bright sunlight is behind the individual entering the building.
For NIST SP 800-171 purposes, these are not simply camera-performance issues.
If the organization claims that surveillance supports Revision 3, 03.10.02.a[01], the monitoring mechanism should be capable of detecting the physical security incidents the organization says it is intended to detect.
The assessment procedure specifically allows assessors to test mechanisms supporting or implementing physical access monitoring.
A camera that technically operates but cannot provide usable monitoring of the intended area may therefore provide considerably weaker evidence of effective implementation.
Protect the Surveillance System Itself
Modern video surveillance systems are information systems.
IP cameras, management consoles, NVRs, cloud applications, switches, and storage devices may all create attack surfaces.
Organizations should consider:
- unique administrative credentials
- elimination of default passwords
- multifactor authentication where supported
- network segmentation
- restricted administrative access
- encrypted communications
- firmware and software updates
- logging of administrative activity
- disabling unnecessary services
- restricting unnecessary Internet exposure
- lifecycle and vendor-support status
Where a surveillance system is part of the CUI environment or provides protection for that environment, other NIST SP 800-171 requirements may apply based on the architecture. The camera should therefore not be viewed only as physical security equipment. It may also be an in-scope network device.
Physical Access Records Matter as Much as Video
Video is most effective when combined with other physical security records. Revision 2 Requirement 3.10.4 requires organizations to maintain audit logs of physical access. Revision 3 consolidates several Rev. 2 physical protection concepts into 03.10.07 – Physical Access Control, which requires organizations to maintain physical access audit logs for entry and exit points. Rev. 3 explicitly notes that these logs may be procedural, automated, or a combination of both.
Significant Rev. 2 to Rev. 3 Change
In Revision 2, several physical protection concepts existed as separate requirements:
- 3.10.2 – protect and monitor facilities and support infrastructure
- 3.10.4 – maintain physical access audit logs
- 3.10.5 – control and manage physical access devices
Revision 3 reorganizes and expands these concepts. Requirements 03.10.03 through 03.10.05 are withdrawn and incorporated into 03.10.07, while monitoring becomes the more detailed 03.10.02. This restructuring encourages organizations to think of physical access control, logging, monitoring, and response as interconnected processes rather than independent activities.
For example:
Badge record: Employee credential entered Door 3 at 10:43 p.m.
Video record: Camera confirms who entered and whether anyone accompanied the authorized employee.
Monitoring process: After-hours entry is a predefined event requiring review.
Response process: Security personnel investigate and document whether the activity was authorized.
That combination creates much stronger evidence of effective physical security than any single mechanism alone.
Retention Should Support the Monitoring Strategy
NIST SP 800-171 does not directly prescribe a universal number of days that security video must be retained (separate from DFARS 252.204-7012 incident log retention requirements), but an assumption of 45 days exists since that is the maximum number of days for periodic review requirements. A longer retention requirement should support the organization’s security objectives and other applicable legal, contractual, or regulatory requirements.
Factors include:
- how quickly incidents are normally discovered
- how frequently access information is reviewed
- available storage
- investigative needs
- contractual requirements
- legal requirements
- sensitivity of recorded information
Keeping video indefinitely is not automatically more secure. Long retention increases storage cost and expands the amount of information potentially exposed if the surveillance system is compromised. The organization should establish and document a retention period appropriate to its requirements and risk.
Evidence That Monitoring Is Actually Occurring
A recurring implementation problem is demonstrating that the documented monitoring process actually occurs. An organization performing weekly reviews should consider retaining evidence that those reviews occurred.
Evidence might include:
- review records
- tickets
- checklists
- workflow approvals
- security reports
- documented investigations
- electronic system logs
The objective is not to create unnecessary paperwork. It is to establish a repeatable security process and retain sufficient evidence to demonstrate that the process is operating.
Document the Design in the System Security Plan
The surveillance system should also be considered when documenting how the organization protects its CUI environment. Under Rev. 2, Requirement 3.12.4 requires development, documentation, and periodic updating of a System Security Plan that describes system boundaries, operating environments, implementation of security requirements, and relationships with or connections to other systems. Revision 3 moves system security planning into the new Planning family under 03.15.02 – System Security Plan. Rev. 3 also emphasizes the system boundary, operating environment, security requirements and their implementation, and connections to other systems. Where cameras materially support physical access monitoring, the SSP or associated documentation should make the implementation understandable.
That may include:
- which facilities are monitored;
- what surveillance capability is used;
- where recordings are stored;
- whether cloud services are involved;
- how long recordings are retained;
- who can access them;
- how access activity is reviewed;
- what events trigger additional review;
- how physical security incidents are escalated.
Additional Factors That Are Easy to Overlook
A well-designed video monitoring program should also consider several operational issues.
System health monitoring.
Personnel should know when a camera stops recording, storage fills, or an NVR fails.
Time synchronization.
Camera timestamps should align with access-control, security, and system logs so events can be accurately correlated.
Power resilience.
Organizations should determine whether cameras, switches, recording equipment, and access-control systems need backup power.
Tamper resistance.
Cameras and recording infrastructure should not be easily disconnected, redirected, covered, or physically accessed.
Administrative access.
Not everyone with IT privileges necessarily requires unrestricted access to surveillance footage. The organization should have a defined policy for who and why surveillance footage access may be granted.
Testing.
Organizations should periodically verify that recordings remain usable, views have not become obstructed, and nighttime or unusual lighting conditions do not undermine monitoring.
Incident response.
Personnel should understand who investigates an alert and when incidents are escalated.
Evidence preservation.
Procedures should exist for preserving footage associated with investigations.
Audio.
Audio recording should be enabled only when there is a defined requirement and applicable legal and privacy implications have been considered.
Vendor access.
Organizations should understand whether installers, managed service providers, or cloud vendors retain administrative access after deployment.
Design the Monitoring Process Before Selecting the Technology
Organizations implementing NIST SP 800-171 should resist the temptation to begin with a camera catalog. Begin instead with the security requirement.
Determine:
- Which CUI environments require physical monitoring?
- What activity needs to be detected?
- What constitutes a physical security incident?
- Which events require immediate investigation?
- How frequently will physical access information be reviewed?
- Who is responsible for the review?
- What evidence demonstrates that the review occurred?
- How quickly must the organization respond?
- What information could cameras inadvertently capture?
- Where will recordings be stored?
- Does the surveillance system become part of the CUI system boundary?
- How will the organization know if the monitoring system fails?
Revision 2 establishes the fundamental obligation to protect and monitor the physical environment. Revision 3 retains that objective but makes the expected monitoring process substantially more explicit by connecting monitoring to detection, response, defined review frequency, and defined event-driven review. That distinction should influence how organizations design their surveillance systems. For one organization, an appropriate implementation may consist of local video storage, electronic access control, weekly documented review, and event-driven investigation. Another organization may justify cloud-managed cameras, automated alerts, centralized access records, and real-time monitoring. A higher-risk environment may require continuous observation and immediate security response.
All three models can begin with the same principle:
Effective physical security monitoring is not defined by how many cameras an organization installs. It is defined by whether the organization can detect relevant physical activity, investigate anomalies, respond to incidents, protect the information collected, and demonstrate that the monitoring process operates as intended.