Building cybersecurity into the connected video product lifecycle
As video security systems become more connected, cybersecurity can no longer be treated as a feature added at the end of product development.
Network cameras, video management platforms, recorders and other connected security devices may operate across enterprise networks, industrial sites and increasingly complex digital environments. This makes security throughout the product lifecycle an important consideration for manufacturers, system integrators and end users.
IEC 62443 provides a structured framework for approaching this challenge.
Rather than focusing on a single security technology, the IEC 62443 series addresses cybersecurity through a combination of processes, technical capabilities and lifecycle responsibilities.
What Is IEC 62443?
IEC 62443 is a series of international standards developed for the cybersecurity of industrial automation and control systems, commonly referred to as IACS.
The series addresses cybersecurity from several perspectives, including:
security programs and organizational processes;
system-level security requirements;
secure product development;
component-level technical security capabilities;
system integration and lifecycle management.
For connected video security technologies deployed within industrial or OT-connected environments, the principles behind IEC 62443 can provide a useful framework for evaluating how cybersecurity is designed, implemented and maintained.
Importantly, IEC 62443 should not be understood as a single product feature or a universal certification label.
Different parts of the standard address different stakeholders, processes and technical scopes.
IEC 62443-4-1: Secure Product Development Lifecycle
For product manufacturers, IEC 62443-4-1 is particularly relevant because it focuses on the secure development lifecycle.
Its scope covers processes used to develop and maintain products, including areas such as:
security requirements;
secure architecture and design;
secure implementation;
security verification and validation;
vulnerability and defect management;
security update management;
product maintenance and end-of-life processes.
This lifecycle approach is important because cybersecurity risks can originate long before a device is deployed.
Security therefore needs to be considered during requirements definition, software and firmware development, testing, maintenance and vulnerability response.
For manufacturers of connected security products, this means cybersecurity is increasingly becoming an engineering process rather than simply a collection of individual security functions.
IEC 62443-4-2: Technical Security Capabilities
IEC 62443-4-2 addresses technical security requirements for IACS components.
The standard organizes requirements around several foundational security areas, including:
identification and authentication;
use control;
system integrity;
data confidentiality;
restricted data flow;
timely response to security events;
resource availability.
These principles are highly relevant when evaluating connected devices.
For example, a network-connected security product may need appropriate mechanisms for authentication, authorization, communications protection, configuration management, logging, software integrity and secure updating.
The exact implementation, however, depends on the product architecture, intended use and required security level.
This is why cybersecurity capability should normally be evaluated at the level of the actual product, firmware version, configuration and deployment environment.
Security Is a Shared Responsibility
One of the important principles behind IEC 62443 is shared responsibility.
Cybersecurity does not depend on the device manufacturer alone.
Product suppliers, system integrators, service providers and asset owners all influence the final security posture of a deployed system.
A product can provide security capabilities, but those capabilities must still be configured and operated appropriately.
For video security deployments, this may include:
changing default credentials;
applying appropriate password and account policies;
limiting unnecessary services;
segmenting networks;
controlling remote access;
maintaining approved firmware versions;
monitoring security events;
managing updates throughout the product lifecycle.
A secure product therefore forms only one part of a secure system.
From Individual Features to Security by Design
Traditional cybersecurity discussions often focus on individual functions such as encryption or passwords.
Modern cybersecurity frameworks increasingly take a broader view.
Security by design asks a different question:
How is security incorporated throughout the way a product is specified, developed, tested, maintained and supported?
This approach can include technical controls, but it also considers engineering processes and operational responsibilities.
For connected video security products, a mature cybersecurity approach may involve areas such as:
secure development practices;
authentication and access control;
protected communications;
configuration hardening;
software and firmware integrity;
vulnerability handling;
security update mechanisms;
coordinated vulnerability disclosure;
security documentation.
No single mechanism provides complete protection.
The objective is to create multiple complementary controls appropriate to the identified risks.
What Should Security Buyers Ask?
When evaluating cybersecurity for connected security products, buyers should look beyond broad statements such as “secure” or “cybersecure.”
More useful questions include:
How are vulnerabilities handled?
There should be a defined mechanism for receiving, assessing and addressing reported vulnerabilities.
How are security updates delivered?
Products should have an appropriate process for maintaining software and firmware during their supported lifecycle.
How is access controlled?
Authentication, authorization and account-management capabilities should be appropriate for the intended deployment.
How is communication protected?
Available protocols and security mechanisms should be evaluated for the specific system configuration.
What documentation is available?
Security capabilities, supported configurations and applicable limitations should be documented clearly enough for integrators and end users to make informed decisions.
A Product-Specific Approach Matters
Cybersecurity requirements vary significantly between deployments.
A camera installed on a small isolated network does not necessarily have the same security requirements as a device connected to an industrial production environment or critical operational network.
For this reason, standards, security capabilities and compliance evidence should be evaluated against the specific product and use case.
At Sunell, cybersecurity-related information is approached on a product- and configuration-specific basis. Applicable security features and supporting documentation should be confirmed for the exact model, software version, configuration and intended deployment.
A reference to a cybersecurity standard should not be interpreted as a blanket certification claim for every product or configuration.
Looking Ahead
Cybersecurity requirements for connected products are continuing to evolve.
IEC 62443 provides manufacturers, integrators and operators with a structured way to think about secure product development, technical security capabilities and lifecycle responsibility.
For the video security industry, the most important change may not be one individual security function.
It is the transition toward cybersecurity as a continuous engineering and lifecycle process.
Need product-specific cybersecurity information?
Contact Sunell for applicable product security documentation and supporting information.
This article is provided for general informational purposes only and does not constitute legal, regulatory or certification advice.
