Resources 5 min read

How to Plan a Video Surveillance Installation

A video surveillance installation goes wrong in predictable places, and nearly all of them are decided before anyone climbs a ladder. The sequence that produces a system people use, and the failures that recur without it.

Two cleared professionals in button-down shirts review GIS security mapping software on a laptop with aerial network data

A video surveillance installation goes wrong in predictable places, and almost all of them are decided before anyone climbs a ladder. This is the sequence that produces a system people actually use, and the failures that recur when a step is skipped.

Before you start

Write the purpose list. One line for each area: what you need to be able to see, why, and how long the footage must survive. "Recognize a face at the staff entrance, keep thirty days" is a specification. "Cover the building" is not, and it is the reason so many systems produce footage that is useless at the moment it is needed.

Decide who may look, and who may export. These are separate permissions and they belong to named roles, not to everyone with a login. Settle it now, because retrofitting access control onto a live system is unpopular and usually incomplete.

Check your constraints. If you hold federal contracts or federal grant funding, equipment from specific manufacturers is prohibited by FAR 52.204-25. If you handle patient records, student records or cardholder data, your sector rules affect who may view footage and how it is protected. Establish this before selecting products, not after.

Survey the building, not the floor plan. Ceiling voids, cable routes, power availability, existing switch capacity, lighting at night, where the sun is at 4pm. The gap between a plan drawn from a drawing and a plan drawn from a walk is the most common source of change orders.

The steps

  1. Design against the purpose list. Each camera gets a location, a lens, a target scene and an entry saying which line of the purpose list it satisfies. Cameras that satisfy no line are removed at this stage, which is far cheaper than removing them later.
  2. Design the network and power path. Switch capacity, power budget, cable routes, and where the recorder will live. Deal with the physical layer as its own piece of work rather than as an afterthought to camera selection.
  3. Size storage from retention. Retention is your policy decision, and NIST treats it that way: recordings are retained for an organization-defined period. Storage follows from that number, camera count, resolution and frame rate. Fix retention first and let storage be the consequence.
  4. Harden before you deploy. Change default credentials, disable interfaces and services you do not need, put cameras on their own network segment, and confirm the devices can actually be updated. NIST publishes the baseline to check against: device identification, device configuration, data protection, logical access to interfaces, software update and cybersecurity state awareness. A camera missing several of those is a device you cannot manage.
  5. Install, then aim in daylight and again at night. Aiming is not a formality. Most cameras get one shot at being pointed correctly and then stay that way for years.
  6. Configure the system, not just the cameras. Time synchronization across every device, user accounts and permissions, retention settings, and health alerting so you find out when a camera stops recording.
  7. Commission against the purpose list. Walk each area and confirm the footage does the job the line said it would. Sign it off view by view.
  8. Train the people who will use it. Searching a timeline and exporting a clip in a form somebody else will accept. If nobody has done it before an incident, they will be learning it during one.

What usually goes wrong

  • Coverage was specified, not recognition. Every corner is visible and nobody can be identified. This traces directly back to a missing purpose list.
  • Retention was set by whatever the recorder happened to hold. Then an incident is reported five weeks later and the footage has been overwritten.
  • Clocks drift. Cameras and recorder disagree, and an exported clip carries a timestamp that will be challenged.
  • Nobody owns it. No named administrator means failed cameras go unnoticed. Systems rarely fail loudly; they fail one camera at a time.
  • The network was assumed. Switch ports, power budget or uplink capacity turn out to be short, and the fix arrives as a change order.
  • Default credentials survive. Cameras are installed with the password they shipped with and remain that way, on a flat network, reachable from anywhere in the building.
  • Export was never tested. The first attempt happens under pressure, and the file will not open on the recipient's machine.

What good looks like

A system you can hand to a new employee with a one-page document. Every camera traces to a stated purpose. Retention is a number someone decided and can justify. Time is synchronized. Access is by role and reviewed. Cameras run current firmware and sit on their own network segment. Health alerts arrive when something stops recording rather than being discovered during a search. Someone in the building has exported a clip in the last quarter and knows it works.

That is also the point at which the system stops being a purchase and becomes something you can improve, which is what the roadmap is for. To compare proposals, use the buyer checklist.

If you would like the survey and purpose list done for you before you commit to anything, request a free site security assessment. LABUSA will walk the site and document what each area needs. Our video surveillance solutions page covers what we install and support.

Sources

  • National Institute of Standards and Technology, IR 8259A, IoT Device Cybersecurity Capability Core Baseline. Establishes the six device capabilities used here as the hardening checklist. nvlpubs.nist.gov. Accessed 18 August 2026.
  • National Institute of Standards and Technology, SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations. Establishes that video recordings are retained for an organization-defined period, the basis for fixing retention before sizing storage. nvlpubs.nist.gov. Accessed 18 August 2026.
  • General Services Administration, FAR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. Establishes the federal contracting prohibition referred to under constraints. acquisition.gov. Accessed 18 August 2026.

About LABUSA

LABUSA is a managed service provider that enables organizations to build a robust digital business model. We provide managed services through an open hybrid cloud strategy integrating public, private, and on-premises computing systems with intelligent edge devices. The company is ISO 9001:2015 certified and our solution extends the information technology environment's efficiency, security, reliability, and cost-effectiveness.

For more Information Contact LABUSA at

+1-281-393-8003