Change log
What changed, when, and why. A framework that quietly rewrites itself is not citable.
A document meant to be cited has to be stable enough to cite and honest about when it is not. Substantive changes to the definition, the six stages, or the maturity levels are recorded here. Typographic and wording fixes are not.
Section numbering is generated from document order, so a clause number is not a stable reference. Cite by heading text and version.
Revisions#
- 1.0 · 2026-09-05First publication. Definition, six-stage framework, six-level maturity model, attack-surface enumeration and four boundary pages. Published as a draft for comment: no part of it has been validated against a body of real implementations, and the maturity model's level spacing in particular is asserted rather than measured.
What we expect to change#
Stated in advance, so that revisions read as intended rather than as quiet corrections:
- The maturity model's evidence tests. These are written to be answerable in practice. If a test turns out to be unanswerable, or answerable only by organisations with a specific tool, it is wrong and will be replaced.
- The discovery source list. The discover stage ranks VMS exports and switch data above active scanning. That ordering reflects how video estates are usually built; if it does not hold for a class of deployment we have not seen, we would like to know.
- Scope of access control and intercoms. Currently in scope, on the argument that they share an owner and a contract with video. This is the boundary decision we are least sure about.
Disagreement is more useful than agreement: framework@videoasm.com.