VideoASM Framework v1.0 ยท draft for comment

Video Attack Surface Management

The practice of continuously discovering, assessing and reducing the cyber attack surface created by cameras, recorders, video-management platforms and the services they depend on.

A large organisation's video estate is frequently its least-inventoried set of networked computers. The devices are bought on a capital budget, installed by a contractor, commissioned once, and then run for a decade. They hold credentials, they speak several protocols, many of them reach outbound to a vendor cloud, and almost none of them appear in the asset register that the security team actually uses.

Video ASM names the gap and gives it a shape: six stages, a maturity ladder, and a set of questions that can be answered with evidence rather than assertion. It is written to be argued with. Where the framework asserts something we cannot support, it says so.

Start here

01

What Video ASM is

The definition, its boundaries, and what it deliberately excludes.

02

The framework

Discover, identify, assess, prioritise, remediate, monitor โ€” with the artefact each stage is supposed to produce.

03

The maturity model

Six levels, each with a test you can fail. Levels you cannot evidence do not count.

Where this sits

Video ASM is not a replacement for attack surface management, IoT security or vulnerability management. It is the application of those disciplines to a class of asset that generally escapes them. The boundary pages set out the differences explicitly, including the cases where an existing tool already covers the ground.

For implementation detail on individual technologies, the hardening guides at VideoCybersecurity go deeper than this framework does.