Cyber Assurance of Physical Security Systems (CAPSS)
The hardening guide explicitly covers servers, clients, devices, and network components together as part of a secure system architecture.
A CAPSS-compliant XProtect deployment requires hardened devices (no default credentials, reduced services, secure access) combined with a controlled and segmented network (firewalls, encryption, and monitored access) where all layers are hardened together.
For CAPSS environments, Milestone recommends using HTTPS/TLS with certificates for all supported components and devices.
Further guidance and details can be found in the following sections, as well as throughout the extended sections in the present Hardening Guide:
1. Identity, authentication, and account control
Remove all default credentials (devices + systems)
Enforce strong password policy
Use dedicated service accounts for system components
Implement role-based access control (RBAC)
Ensure unique identities per user/system.
2. Device hardening
Replace default credentials
Disable unused services (Telnet, FTP, etc.)
Use secure authentication (HTTPS, certificates, SSH keys)
Create dedicated device accounts
Maintain device inventory and ownership
Apply firmware updates and patching
Ensure device logs are enabled and retained
Enforce secure onboarding of devices (controlled addition to VMS).
3. Network security and segmentation
Core controls
Use secure communication by default (HTTPS / VPN / TLS)
Use TLS (latest supported version) with valid certificates
Configure network to support secure sessions only
Access control
Use firewalls to restrict IP access and ports
Open only required ports for XProtect components
Separate inbound (server) vs outbound (client) traffic flows
Network segmentation (VMS isolated from IT network)
Device whitelisting / trusted endpoints
Strict access allow-listing
No direct internet exposure of core servers
Use DMZ for external access services (Mobile/Web)
Restrict management interfaces to trusted admin zones.
4. Secure communication and encryption
Encrypt communication:
Server ↔ Server
Server ↔ Client
Recording server ↔ devices
Use TLS encryption and secure protocols
Disable weak protocols
Enforce minimum TLS versions (e.g., TLS 1.2+)
Use certificates issued by trusted authority
Ensure encryption is applied to:
Video streams
Authentication
API traffic
5. Server and platform hardening
Harden OS (Windows):
Remove unnecessary roles/services
Apply security updates
Harden IIS / services:
Disable insecure headers/methods
Secure database connectivity (SQL hardening)
Disable legacy protocols/remoting
Implement centralized patching process.
6. Access control to system (clients and users)
Restrict user access by role
Use secure authentication methods
Ensure only authorized clients can connect
Multi-factor authentication (where supported). MFA is not configured within XProtect. Instead, it is enforced through the organization's identity provider (IdP) or other authentication mechanism. MFA must be enabled for all administrative accounts.
Limit admin access to dedicated workstations
Restrict management tools to internal networks
Implement lockout sessions after a defined period of inactivity, requiring the user to re-authenticate. The inactivity period must be no longer than 15 minutes for admin roles and up to 120 minutes for operator roles or other roles used in a secure area for passive data review.
Password policy: Check the section Users and Security in the Milestone XProtect Administrator Guide to learn more about XProtect password policy and user authentication.
Password protection of configuration backups and configuration data is mandatory in CAPSS deployments.
Remote access (RDP): Remote Desktop Protocol must be disabled on all XProtect hosts. Physical console access is the preferred administrative method.
7. Logging, audit and monitoring
Enable logging across:
Devices
Servers
Network access
Use logs to track:
Access
Changes
Events
Central log collection (SIEM)
Define log retention policy
Monitor:
Failed logins
Configuration changes
Network anomalies.
Synchronized event timestamps: XProtect requires accurate time synchronization to maintain consistent event timestamps. In disconnected CAPSS deployments, synchronize systems with an approved local NTP source or trusted standalone time appliance if external time synchronization is unavailable.
8. Change management and configuration control
CAPSS-critical (not optional)
Establish baseline hardened configuration
Ensure all changes:
Are approved
Are documented
Practical controls:
Change approval workflow
Configuration backup
Drift detection
9. Operational security
Define:
Maintenance procedures
Update processes
Incident response
Examples:
Regular patching for VMS and devices
Monitoring system health and activity
Controlled remote access policy
Restrictions on physical media
Disable USB storage via Group Policy
Disable AutoRun
Restrict removable media through endpoint security controls
Permit only authorized encrypted media