Investigations & Forensics

Physical Security Integration: How Access Control and Video Surveillance Work Together

Access control and video surveillance are more useful integrated than separate. This guide explains the architecture, the platforms, and what integration actually delivers operationally.

By IPA-IAC · 7 min · 3 September 2024

Access control system integrated with video surveillance in an enterprise security environment

Access control and video surveillance have historically been deployed and managed as separate systems — one managed by the facilities or security team, the other by IT. Integration between them was optional, often manual, and rarely achieved in practice. That is changing, and the operational case for integrated physical security programs is now well established.

The drivers are partly technological and partly organizational. IP-based access control and IP-based camera systems now share common infrastructure. Physical security information management (PSIM) platforms have made integration more tractable. And security teams that have experienced the operational benefits of correlated physical access and video data consistently report that they could not return to managing both systems in isolation.

The investigative payoff of that integration depends on what happens after an incident is flagged — footage and access logs still have to move into a documented evidence workflow, which is the same chain-of-custody discipline that governs digital forensic triage and evidence backlog management more broadly.

What Integration Actually Delivers

Before getting into the technical architecture, it is worth being specific about what integration enables operationally, because the benefits are often described in generalities that obscure the practical value.

Event correlation. An access control event — a door opening at 2:17 AM — becomes operationally useful when it can be immediately linked to camera footage of who used the credential, and whether the person using it matches the photo on file. Without integration, that correlation requires manual work: pull the access log, note the time, navigate to the camera management system, scrub to the timestamp. With integration, the footage is linked directly to the event record.

Tailgating detection. Access control systems log credential use, not the number of people who actually pass through a door. Camera analytics integrated with access control can detect when multiple people pass through a door on a single credential use — a significant exposure in high-security environments that is essentially invisible without video correlation.

Anomaly investigation. When behavioral monitoring surfaces an anomalous access pattern — an employee badging into facilities at unusual hours across multiple locations — integrated video allows investigators to review the footage tied to each event rapidly rather than navigating multiple systems.

Forced entry detection. Door contact sensors detect whether a door is open, not how it was opened. Video correlated with door-forced alerts distinguishes between a propped door and a forced entry, allowing security operations to triage incidents with much higher accuracy.

Credential audit support. Physical access reviews — verifying that credential holders are still authorized, that dormant credentials have been revoked, that access levels match current roles — are significantly more useful when auditors can pull video records alongside access logs.

System Architecture

Integrated physical security programs typically involve three layers of technology:

Access control platform. The system that manages credential enrollment, access policy, and door hardware. Modern platforms — Lenel S2, Software House C-CURE, Gallagher, Genetec Security Center — are IP-based and expose event streams via API or SDK.

Video management system (VMS). The platform that manages camera feeds, recording, and video retrieval. Leading VMS platforms — Milestone XProtect, Hanwha Wisenet WAVE, Genetec Security Center, Avigilon Control Center — also expose event and data APIs.

Integration layer. This is where architectures diverge. Organizations use one of three approaches: a unified platform (Genetec Security Center manages both access control and video natively), an API-based custom integration (access control events trigger VMS bookmarks or clips via API calls), or a PSIM platform that correlates events from both systems.

Unified vs. Best-of-Breed Integration

The make-versus-buy decision in physical security integration is a genuine architectural choice with real tradeoffs.

Unified platforms (Genetec Security Center is the clearest example) manage access control, video, and increasingly other physical security systems — intercom, intrusion detection, perimeter analytics — within a single platform. The operational benefit is significant: operators work in one interface, events are correlated natively, and the data model is consistent. The tradeoff is platform dependency — you accept the access control hardware and camera compatibility constraints that come with the platform, and migration later is expensive.

Best-of-breed with integration preserves the ability to select the best access control platform for your environment, the camera ecosystem that fits your budget and performance requirements, and the VMS that best serves your operational workflows. The integration work is more significant, but the result can be a more capable system in specific performance dimensions.

For most enterprise environments, unified platforms have become the more practical choice. The integration complexity of best-of-breed has been consistently underestimated, and the operational benefits of native correlation outweigh the flexibility advantages in most use cases.

Camera Selection for Integrated Programs

Integration architecture matters more for camera selection decisions than organizations typically realize. Relevant considerations:

ONVIF conformance. The ONVIF standard enables interoperability between IP cameras and VMS platforms. Conformant cameras and VMS platforms can communicate for basic functionality — live viewing, recording, PTZ control — without custom integration work. For integration with access control, however, ONVIF alone is usually insufficient; API-level integration is required for event correlation.

Edge analytics capability. Cameras with on-board analytics — person detection, tailgating detection, license plate recognition — reduce the processing load on central VMS infrastructure and enable real-time alerting rather than retrospective analysis. The quality of edge analytics varies significantly between manufacturers and product lines; testing against actual use cases before deployment is essential.

Resolution and lighting performance. The operational usefulness of integrated access and video depends on the quality of the video record. Credential holders who cannot be identified from footage because cameras are too low-resolution, or because lighting conditions are inadequate, produce video evidence that is operationally useless. Resolution specifications alone are insufficient — evaluate cameras in the actual lighting conditions of the deployment environment.

Access Control Hardware Considerations

Reader technology. The credential technology used for access control affects both the security level and the integration options available. Legacy magnetic stripe and proximity (125 kHz) credentials have well-known vulnerabilities and should be treated as a migration target rather than a deployment standard. Smart card technologies (13.56 MHz, MIFARE DESFire, iCLASS SE) offer significantly better security. Mobile credentials — smartphone-based access using Bluetooth or NFC — are increasingly viable and eliminate the card issuance overhead.

Door hardware reliability. Access control systems depend on door hardware that actually holds doors closed when required and releases when authorized. The gap between specification and operational reliability is significant for electric strikes, magnetic locks, and electrified mortise locks in high-traffic environments. Hardware quality and installation quality both matter; the failure modes are different and require different maintenance approaches.

Controller architecture. Intelligent controllers that hold access policy locally maintain access control functionality during network outages — important in environments where network reliability cannot be guaranteed. IP-connected controllers that depend on central server communication for access decisions are more operationally efficient but introduce a single point of failure that must be accounted for in the resilience design.

Cybersecurity for Physical Security Systems

Physical security systems have become part of the IT security attack surface, and the security community has documented multiple cases of physical security systems being compromised and used as a vector for network intrusion.

The fundamental issues are familiar: default credentials that are never changed, firmware that is rarely updated, and devices deployed on network segments without adequate access controls. Physical security integrators have historically been separate from IT security, and the gap in security practices is real.

A physical security cybersecurity program involves:

  • Placing physical security systems on isolated network segments with firewall-controlled access
  • Enforcing credential hygiene: unique passwords, no default credentials
  • Establishing firmware update procedures and maintaining patch currency
  • Including physical security systems in vulnerability scanning programs
  • Monitoring physical security system network traffic for anomalies

FAQ

Does integration require replacing existing systems? Not necessarily. Many integration projects build API-level connections between existing access control and VMS platforms, adding integration capability without replacing hardware or software. The feasibility depends on the API capabilities of the existing systems — older platforms may lack adequate APIs and require replacement.

How is access control integrated with HR systems? Most enterprise deployments integrate access control with HR information systems (HRIS) to automate credential provisioning and de-provisioning based on employment status. When an employee is terminated in the HRIS, the integration triggers credential revocation in the access control system. The latency on this process — how quickly termination in HRIS translates to access revocation — is a key security metric.

What is the ROI case for physical security integration? The ROI case is typically built around labor reduction (automated correlation reduces manual investigation time), incident detection improvement (integrated systems surface events that would be missed in siloed operation), and compliance support (audit documentation is more complete with integrated records). Quantifying incident detection improvement is methodologically difficult; labor reduction and audit support are more tractable.