Skip to content

The access check: how NIS2 and ISO-ready is your camera system?

Written and reviewed by Koen, senior adviser at CameraInstallatie.nl · updated 8 oktober 2026

Fifteen questions about how access to your camera, alarm and intercom systems is managed. Who can get in, can you take that access away, can you see who did what? In three minutes you know where you stand and what to tackle first. You don’t need to leave any details to see the result.

  • 3 minutes
  • Result straight away
  • Based on NIS2, ISO 27001 and GDPR

Most NIS2 checks are about your IT. This one covers the part they skip: the cameras, recorders, intercoms and alarm panels at your sites. It is not an audit and not a verdict on whether your organisation complies with the law.

The check

How well is access to your camera system managed?

Pick the answer that fits best for each question. Not sure? Choose ‘don’t know’. It counts as no, because what you don’t know, you can’t demonstrate.

  1. Does everyone who views footage have their own account, rather than a shared login?

    Why it matters: with a shared login you cannot show who watched. NIS2 Art. 21 (access control), ISO 27001 Annex A 5.16.

    With a shared login you cannot take access away from one person. How we solve it: everyone gets their own account, on their own email address or through your Active Directory, and the shared login disappears.

  2. Has everyone stopped logging in as ‘admin’ for daily use?

    Why it matters: the admin account can do anything, including switching off the audit trail. ISO 27001 Annex A 8.2 (privileged access rights).

    How we solve it: the admin account is used for administration only, with a strong unique password. Daily work runs through personal accounts with only the rights they need.

  3. Can you remove someone who leaves in one action, at every site?

    Why it matters: revoking identities and authorisations is part of access control. NIS2 Art. 21, ISO 27001 Annex A 5.18 and 6.5.

    Visiting every recorder gets forgotten. How we solve it: we bring the sites under one way of managing, so removing someone is one action in one place.

  4. Are the users of the camera system linked to your Active Directory or LDAP?

    Why it matters: a leaver in HR and IT then automatically leaves the camera system too. ISO 27001 Annex A 5.16.

    How we solve it: we connect the system to your Active Directory. Anyone removed there loses access to the cameras within about ten minutes.

  5. Do people logging in remotely or with admin rights use two-factor authentication?

    Why it matters: NIS2 lists multi-factor authentication where appropriate. NIS2 Art. 21(2)(j).

    How we solve it: we switch on mandatory two-factor login for accounts used remotely, and explain where it can and cannot be used.

  6. Can you see who watched which footage live or played back, and who exported something?

    Why it matters: without an audit trail you cannot assess an incident or a possible data breach. ISO 27001 Annex A 8.15, GDPR Art. 5(2).

    How we solve it: we switch on the audit trail and make sure you can read and export it when you need it.

  7. Do you know how long that audit trail is kept, and is that period documented?

    Why it matters: logs should be kept for a defined period and protected against changes. ISO 27001 Annex A 8.15.

    How we solve it: we set the retention period that fits your policy and document it.

  8. At how many sites is there a separate recorder with its own login?

    Why it matters: every separate recorder is an island with its own accounts. NIS2 Art. 21 (asset management), ISO 27001 Annex A 5.9.

    How we solve it: we map everything and bring the sites under one way of managing, reusing what still works.

  9. Is there an up-to-date list of all cameras, recorders, intercoms and alarm panels, with their firmware?

    Why it matters: you need a complete and current inventory of your assets. ISO 27001 Annex A 5.9.

    How we solve it: we inventory every device per site and deliver a list you can copy into your own asset register.

  10. Has the firmware of cameras and recorders been updated in the past year?

    Why it matters: NIS2 includes vulnerability handling as a measure. NIS2 Art. 21(2)(e).

    How we solve it: we bring firmware up to date and include it in regular maintenance. A device that no longer gets updates, we replace selectively.

  11. Are the cameras on their own, separated part of the network?

    Why it matters: a camera among the office PCs is a door into your network. Network separation is a common security measure.

    How we solve it: we put the cameras on their own VLAN, with only the connections that are really needed.

  12. Is it written down who may view which footage, and why?

    Why it matters: access control should be a written, demonstrable policy, and the GDPR asks you to be able to demonstrate how you protect personal data. GDPR Art. 5(2) and 32.

    How we solve it: we deliver a permissions overview per role and site that you can include in your own policy.

  13. Are accounts and permissions reviewed at least once a year?

    Why it matters: identities and authorisations should be checked periodically. ISO 27001 Annex A 5.18.

    How we solve it: we review accounts and permissions with you every year, with a short report for your records.

  14. Do you get an alert when a camera drops out or recording stops?

    Why it matters: otherwise you only find out after an incident that camera 23 recorded nothing for three weeks. NIS2 Art. 21(2)(c) (business continuity).

    How we solve it: we switch on alerts for a camera, a disk or recording failing.

  15. Do you know who installed the system, and can you still reach them?

    Why it matters: NIS2 asks for attention to supply chain security. NIS2 Art. 21(2)(d).

    How we solve it: we take the system over, even if it wasn’t ours. First we establish that it is yours.

Background

Why is this check about cameras and not about your IT?

Because that is the part almost everyone forgets. NIS2 checks ask about your firewall, your backups and your laptops. Nobody asks about the recorder in the meter cupboard at site three.

Yet that recorder sits on your network, and people watch through it, sometimes with the same login for years. NIS2 asks for access control and asset management as part of your risk-management measures. If your camera system sits on your network, or watches the room where your servers are, it belongs in that.

How to bring it under control across all your sites is on access management for cameras, alarms and intercoms.

Questions about the check

Does this check tell me whether I comply with NIS2?

No. NIS2 is about your whole organisation, and whether it applies to you depends on your sector, size and member state. This check only looks at how access to your camera, alarm and intercom systems is managed. It shows where to improve, not whether you comply.

What happens to my answers?

Nothing. The result is calculated in your own browser and not stored. Only if you click ‘Discuss the result with us’ and send the form do we see your answers.

Why does ‘don’t know’ count as no?

Because the rules are about demonstrating. If you don’t know whether something is arranged, you can’t show it either. That is exactly the improvement.

I am a consultant. Can I use these questions?

Please do. Use them in your own assessment or specification. If you want to know how to turn the answers into a design, we are happy to help.

Koen, Senior adviseur

A quick word

Questions about your situation? Call Koen.

Takes the time, draws it out, and does not steer towards a number. I do not sell, I advise. Describe your situation and you will hear straight away what we would do — with no obligation.

Koen · Senior adviser

Want to talk it through?

Tell us what you have and what you want to be able to do

You will hear within one working day what is possible, what it costs and what we would do — including if that turns out to be less than you expected.

  • Reply within 1 working day
  • Advice is free
  • No obligation whatsoever

Rather speak to someone now?
036 52 90 007 or send us a WhatsApp message

Leave your details

We will call or email you back with a concrete answer.

We only use your details to get in touch. privacy policy.