Most organizations do not need a new surveillance system so much as a plan for the one they have. A roadmap is the document that turns "we should do something about the cameras" into a sequence somebody can fund, and it is useful precisely because it survives the person who wrote it.
What the artifact contains
A surveillance roadmap worth the name is short, and it contains six things.
- An inventory. Every camera, where it is, what model, what firmware, what it records, where that recording goes and for how long. Most organizations discover during this step that they do not know how many cameras they own.
- A purpose list. One line per area, saying what you need to be able to see and how long you need to keep it. This is the standard the current system is judged against, and it is the part that requires a decision rather than a survey.
- A gap list. Where the current system fails the purpose list. Coverage gaps, recognition failures, retention shortfalls, unsupported devices, unowned administration.
- A risk position. Devices that cannot be updated, prohibited equipment, flat network segments, footage nobody controls access to.
- A sequence. What gets fixed in what order, with the reasoning. Order matters more than completeness, because the budget usually arrives in pieces.
- An owner and a review date. A roadmap without a named owner becomes a document rather than a plan.
It is worth borrowing structure rather than inventing it. The NIST Cybersecurity Framework 2.0 organizes outcomes under six Functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. Grouping your gaps that way makes two things visible immediately. Almost every surveillance roadmap is heavy on PROTECT and DETECT, and almost every one is thin on GOVERN, which is where ownership, policy and supplier expectations live.
How it is produced
- Inventory what exists. Physically. Camera by camera, with model, firmware and recording destination. Include the cameras nobody claims, because those are usually the unsupported ones.
- Write the purpose list with the people who use the building. Facilities, operations and whoever handles incidents. Not the installer, and not IT alone. This is a business decision expressed in camera terms.
- Test the current system against it. Look at real footage from real cameras at the times of day that matter. Try a search. Try an export. This step generates most of the gap list, and it usually takes an afternoon.
- Assess the risk position. Firmware status, supported life, network segmentation, credentials, access permissions, and whether any equipment is prohibited for your organization. Video surveillance security and risk sets out what to look for.
- Sequence the work. Fix what is cheap and reduces the most risk first, which is nearly always credentials, segmentation, access permissions and health alerting. Retention and coverage changes follow. Replacement of unsupported hardware is usually the largest item and belongs where it can be funded, not where it feels urgent.
- Cost the sequence in bands. Not to the dollar. Enough for someone to decide what fits this year. What drives the cost explains what moves each band.
How it is used afterwards
The roadmap earns its keep in three ways after it is written, and none of them involve reading it end to end again.
It makes budget requests concrete. "Cameras at the loading dock cannot identify anyone after dark, and three incidents in the last year involved that door" is a fundable sentence. "The camera system is old" is not.
It makes quotes comparable. Hand the purpose list to every supplier and the proposals arrive priced against the same requirement. Without it, each supplier prices a different assumption and the cheapest quote is simply the one that assumed least. This is the input the buyer checklist depends on.
It gives you something to measure against. The gap list is a baseline, and closing items on it is progress you can report. Measuring the value of video surveillance covers what to track once work begins.
Review it annually, and after any incident where footage was needed. An incident tells you more about the gaps in ten minutes than a survey does in a day. Revisit the sequence when the review changes the gap list, not on a fixed schedule for its own sake.
If producing the inventory and the gap list is the part you would rather not do from scratch, that is essentially what a site assessment delivers. Request a free site security assessment and LABUSA will document what you have, what each area needs and where the two do not meet. When the sequence reaches installation, how to plan an installation covers the delivery, and our video surveillance solutions page covers what we install. For multi site estates, the standards worth setting before the second site are in scaling a security platform across sites.
Sources
- National Institute of Standards and Technology, Cybersecurity Framework 2.0 (NIST CSWP 29). Establishes the six CSF Core Functions used here as the grouping for a gap list. nvlpubs.nist.gov. Accessed 18 August 2026.
- National Institute of Standards and Technology, SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations. Establishes that retention periods and review frequencies are organization-defined, which is why a roadmap has to state them rather than inherit them. nvlpubs.nist.gov. Accessed 18 August 2026.