VideoASM Draft for comment

Video ASM and VMS health monitoring

Every VMS ships health monitoring, and it holds the best device inventory in the building. It answers a different question — and the difference is worth being precise about, because the two are routinely confused in procurement.

Version
1.0
Status
Draft for comment
First published
5 September 2026
Revised
5 September 2026

This comparison exists because the confusion is common and expensive. An organisation with comprehensive VMS health monitoring frequently believes the video estate is monitored, and in one sense it is. The monitoring answers a question nobody asked about security.

What health monitoring does#

Every serious video-management platform includes system monitoring, and there is a category of third-party tooling that does it in more depth. Between them they cover:

  • Whether each camera is online and recording
  • Whether the video signal is present, and whether the image has changed unexpectedly — a camera that has been moved, defocused, obscured or spray-painted
  • Recording integrity and retention: whether footage exists for the period it should
  • Storage health, disk failures, array status
  • Server and service availability, failover status, licence state
  • Frame rate, bitrate and stream errors
  • Certificate and time synchronisation state, on some platforms

This is genuinely valuable and often better instrumented than anything in the security estate. Camera-verification tooling in particular solves a real problem: a camera that has silently stopped producing usable footage is an operational failure that only shows up when someone needs the footage.

What it does not do#

Health monitoring is built around availability and quality. It does not ask:

  • What firmware each device is running, and whether that firmware has published vulnerabilities
  • Whether the device is using default or shared credentials
  • Which network services the device is exposing
  • Whether the device is reachable from networks it should not be reachable from
  • Whether it maintains an outbound connection to a vendor cloud service
  • Whether the product is still supported by its manufacturer
  • Who is accountable for changing any of the above

A camera can be perfectly healthy by every monitoring metric — online, recording, in focus, correct frame rate — while running four-year-old firmware with a publicly exploited vulnerability, reachable from the office network, with the same administrative password as every other camera on the site.

The monitoring is not wrong. It is answering "is it working", and the answer is yes.

The overlap worth exploiting#

The VMS is the single best inventory source in most organisations, and a Video ASM programme should start there rather than with a network scan.

What it typically holds: every camera it records from, with IP address, manufacturer and model, frequently firmware version, the recording server each device is attached to, and often the physical location as a human-readable name. This is most of the identify stage already assembled, by a system that has been maintaining it accurately because the operation depends on it.

Two caveats.

It holds only devices connected to the VMS. Cameras on a standalone recorder, cameras commissioned and never added, devices from a decommissioned system still powered on — none of these appear. The difference between the VMS list and an independent source (switch PoE status is the usual choice) is the interesting number, and the framework's discover stage treats producing that difference as the completion test.

Its firmware field may be stale. Some platforms record the version seen at commissioning rather than the current one.

The procurement confusion#

The reason this page exists in the document rather than as a footnote: "we monitor our video system" is a sentence that ends security conversations, and the two meanings are not distinguished in most organisations.

A useful test in a procurement or audit conversation is to ask the health-monitoring tool a security question: which of our cameras are running firmware with a known vulnerability? If the tool cannot answer, the estate is monitored for availability and unmonitored for security, and both facts can be true at once.

VMS health monitoringVideo ASM
QuestionIs it working, and is the footage usable?What can be done to it, and by whom?
OwnerPhysical security or operationsSecurity, with physical security
Alerts onOffline, signal loss, storage failure, tamperNew device, firmware drift, new vulnerability, exposure change
Knows firmwareSometimes, sometimes staleMust, or records the gap
Knows credentials postureNoYes
CoverageDevices attached to the VMSThe estate, including what the VMS does not see
Useful to the otherIts inventory is the best starting pointFinds the devices the VMS never knew about

The two are complements, and the sensible arrangement is for the security programme to consume the VMS inventory rather than rebuild it. What it must not do is treat the presence of health monitoring as coverage.