
Milind Borkar
Strategic Consultant, VICON
For the modern Nation-State, being able to protect its critical infrastructure is essential for public safety and private commerce – and even for survival. As Figure 1 illustrates, transportation is a key element of the national critical infrastructure.

Figure 1
Protecting transportation networks requires that security planning and system design at all levels with a country be able to:
- Prevent and deter acts of terrorism using or against the transportation system;
- Enhance the resilience of the transportation system; and
- Improve the cost-effective use of resources for transportation security.
Transportation risk is a function of threat, vulnerability, and consequence. Analysis of risk and the evaluation of countermeasures must consider all three variables. Disruptions in the transportation network can often have non-linear effects; what may initially appear as an isolated disturbance in the network can have a much greater, sector-wide impact.
A Nation’s transportation network consists of:
- Aviation includes aircraft, airports, air traffic control systems used for passenger traffic, cargo movement, general aviation, and government functions including military activities.
- Maritime includes a wide range of water-faring vessels and consists of coastline, seaports, and navigable waterways which allow the various modes of transportation to move people and goods to, from, and on the water.
- Mass Transit includes multiple-occupancy vehicles, such as transit buses, trolleybuses, vanpools, ferryboats, monorails, heavy (subway) and light rail, passenger rail (including both commuter rail and long-distance rail), automated guideway transit, and cable cars, designed to transport customers on regional and local routes.
- Highway includes national, regional, and local roadways and their supporting infrastructure used by automobiles, buses, motorcycles, bicycles, and all types of trucks, trailers, and recreational vehicles.
- Freight Rail consists railroads and rail roadbeds, passenger and freight cars, locomotives, and freight depots and warehouses.
- Pipeline includes networks of pipeline which carry most of a country’s natural gas, petroleum products for automobiles and trucks, and hazardous liquids and various chemicals.
The disruption of any of these modes will impact the public health, safety, and economic well-being of the Nation. Each mode has its unique characteristics, operating models, responsibilities, and stakeholders – but all are inter-dependent. Indeed, this interdependency is a defining characteristic of a national transportation system.
One of the critical challenges facing transportation security is understanding the downstream implications of potential disruptions. Resources available for protecting critical transportation assets are limited, being able to prioritize systems is key leveraging available resources and developing security countermeasures. For example, following the September 11 attacks in the United States, the aviation system was shut down and borders were closed, causing supply chain disruptions across multiple industries.
There are many dependencies and interdependencies between the various transportation modes. Non-transportation sectors depend on, and can be significantly impacted by, a major disruption in one or more of the transportation modes, For example:
- A Nation’s air, maritime, rail, and highway networks move people and materiel used by all other sectors.
- The Energy Sector requires coal, crude oil, petroleum products, and natural gas that are transported by ship, barge, pipeline, rail, and truck.
- Banking and Finance Sector and Government Facilities Sector rely on mass transit systems in large urban areas for employees to access the workplace.
- Telecommunication carriers frequently co-locate much of their networking equipment (routers, fiber optic cable etc.,) along existing transportation routes (rail lines, highway tunnels, and bridges), the destruction of which may impact service availability in wide geographic areas.
- Manufacturing and commercial sectors move goods and services across the entire transportation network utilizing all transportation modes.
The integrity of the Transportation Systems Sector is also directly dependent on the efforts of other sectors.
- The Energy Sector produces fuels to power transportation systems.
- The Information Technology Sector is essential in the transmission of information necessary for the efficient operation of the transportation network.
The involvement of many diverse stakeholders is vital to prevent, protect against, respond to, and recover from potential terrorist attacks and other incidents. High levels of communication and coordinated action are required, often within very short periods of time.

Global Context
For the modern nation-state, these issues need to be addressed in a global context. United States, for example, is an important trading partner with numerous foreign countries. Large numbers of passengers and volumes of merchandise enter the United States daily on ships and airplanes from across the world and by trucks and rail from multiple points along the Canadian and Mexican borders. The attacks of 11 September 2001, highlighted the security vulnerabilities inherent in the global transportation network and the need to devise solutions with international partners to: (1) identify and understand threats, assess vulnerabilities, and determine potential impacts to the global transportation system; (2) exchange and share effective practices to deter, understand, and prevent future attacks; and (3) promote measures that safeguard the movement of people, goods, and services through international transportation systems.
The U.S. Transportation Security Administration (TSA) does this through international organizations including the International Civil Aviation Organization, (ICAO, the International Maritime Organization (IMO), and regional groups such as the Group of 8 Countries and the Asia-Pacific Economic Cooperation Forum (APEC). TSA security activities include: (1) assisting the ICAO in compliance and enforcement to ensure that aviation security vulnerabilities are identified through the Universal Security Audit Program; (2) increasing international focus on the need for security standards and/or best practices for all modes of transportation; (3) training international partners in identifying terrorists and/ or the instruments of terrorism and developing appropriate countermeasures using new technologies; (4) strengthening international security standards by participating in standardsetting organizations; (5) providing mechanisms for sharing and reporting information to foreign authorities and stakeholders; and (6) minimizing disruptions to passengers and commerce through regular consultations with international partners regarding security policies and programs.
National Transportation Security Planning
In developing modal security, collaborate efforts are required by all stakeholders in developing implementation plans that achieve the goals and objectives for each level of activity. Planning must address cost-effective security programs and initiatives; current effective public and private security practices; security guidelines, requirements, and compliance/assessment processes; areas for security improvement; and a process to establish metrics for determining security effectiveness and progress toward achieving modal security goals and objectives. Technology is an enabler throughout this process.
The strategy should focus on implementing multiple layers of security to defeat and deter the more plausible and dangerous forms of attack against the Nation’s transportation network.
Complicating this approach are:
- Infrastructure interdependencies.
- Business and economic impediments.
- Legal impediments.
- Cross-border dependencies.
- The globalization of business.
- The rise of “stateless” adversaries.
Each mode of transportation presents unique security and operating requirements and environments. Each requires unique security planning, regulations, and approaches.
A National security protection plan should be risk-based and be developed as shown in Figures 2.

Figure 2: Risk-Based Security Planning from PDF
The elements of this approach include:
- Defining a risk management framework.
- Emphasizing coordination with National, regional, and local and private sector security stakeholders.
- Enabling critical infrastructure protection planning activities and resource allocation decisions across and within critical infrastructure elements.
- Setting security goals at every level of the transportation network.
- Assessing risks, threats, vulnerabilities, and consequences realistic and practically.
- Prioritizing and allocating security assets – systems, people, and funding – based on vulnerabilities and consequences.
- Describing and providing for linkages to a National Response Plan to cope with incidents of National significance.
- Providing the means for periodically testing security plans and programs and measuring their effectiveness.
A possible management structure for this process is illustrated in Figure 4.

Figure 4: Management Approach for Implementing Transportation Security
Integrated Security System
For this article, international airports will be used as the models for security system planning, development, design, and implementation.
The model airport security system design must address regulatory requirements, airport operational requirements, infrastructure dependencies and incident management.
The security system design process begins with the identification and assessment of National, regional, and local regulations that govern airport security operations. In the United States, at the Federal level security requirements for commercially-certified airports are set forth in 49 CFR Part 1542, a set of regulations which govern secured areas, air operations areas, security identification display areas (SIDAs), and perimeter and access controls. The regulations also contain requirements for fingerprint-based criminal history record checks of specified individuals. Internationally, civil aviation security follows the programs and procedural guidelines of the International Civil Aviation Organization (ICAO) and particularly its Annex 17, which defines security requirements and practices for aerodromes in the context of a National aviation security program.
The requirements definition process begins with detecting and analyzing anomalies, based on data gathered from a broad array of sensor applications and locations, so that alerts and alarms become meaningful and worth the necessary effort and resources to react. Detection coupled with assessment provides the airport with the means to understand and manage escalating events, and to maintain situational and domain awareness as event conditions evolve (these terms are described below). Significant events are rarely onedimensional, and most will have post-event requirements for record-keeping, redeploying resources, and reestablishing normal operational status.
An airport security Concept of Operations (ConOps) document is a primary vehicle for expressing security operational requirements in sufficient scope and detail for the security system designer to develop a technology-based security system solution. The elements of a ConOps and their relationships are shown in Figure 5.

Figure 5: ConOps Architecture and Development Process
To be effective, a ConOps document should:
- Identify threats and vulnerabilities, and develop a risk-based prioritized set of operational security requirements.
- Assess and recommend security technologies to be implemented for the identified operational security requirements.
- Establish a structure for systematic, coordinated response to security-related incidents and address dynamic security responsibilities by airport Public Safety and Operations departments.
- Provide the means for information sharing among airport these groups and also with other airport stakeholders, to enhancing their cooperation as needed during incident management.
For international airports, the security system should be conceptualized as an information system having inputs from a variety of from both sensors and operating personnel, and delivering context-related information to responders, airport management, and other stakeholders. This “information centric” approach integrates the airport security system with the airport information technology (IT) network and with other airport special systems, in the manner shown in Figure 6.

Figure 6: Security System Integration
In the context of a ConOps, the following terms have special significance and implications for the security system designer:
- Detection is the ability to “see” what is happening in real time, whether by visual cues, electronic signals from sensors, or any other means of data collection and convergence that can identify events of potential significance for airport security. Detection is the necessary first step toward prevention, mitigation, and response.
- Situational awareness focuses on anomalies, which may or may not be threats, and the means to evaluate them in a dynamic environment on the airport, and relate them to the functions of parties responsible for airport security.
- Domain awareness focuses on the airport’s entire environment, both security and non-security events such as natural disasters, external to the airport and including the functions of government agencies at the local, regional and National levels.
The requirements phase translates the operational desires and needs expressed in the ConOps into technical requirements which can be used to design, implement and commission an airport security system.
The Security Operations Center (SOC)
The heart of the security system is the Security Operations Center (SOC). This is where information from security system components must be processed by human operators aided, where applicable, by software which automates routine monitoring functions, assesses the relevance and consequences of events, and aids security personnel in responding to actionable events – the process of “situational awareness”. The functions and inter-relationships of the SOC are diagramed in Figure 7.
Figure 7: SOC Functions and Inter-Relationships
SOC layouts differ widely, as Figure 8 illustrates, to accommodate local conditions and local operating preferences.
Figure 8: Representative SOC Layouts
The configuration and functionality of the SOC depend on its role and relationship with responder dispatch and incident management functions. All of these functions may be performed in the SOC, but at many airports and particularly when security is assigned municipal or county Police Departments, dispatch and incident management are performed in a separate Dispatch Center. Either arrangement is workable with the proper information flow, and that should be a primary objective of the IASS system design.
Networked Communications Infrastructure
To assure proper information sharing, security system elements should be interconnected by and share a common communications infrastructure. For most airports, as well as for other transportation nodes, this will mean integrating security components, such as video surveillance cameras, with a Local Area Network (LAN) and using its cable plant and network equipment for transporting, storing, securing, and presenting security video, voice, and data.
Airport IT networks generally are segmented, using VLANs, and firewalled to isolate and protect sensitive and stakeholder proprietary information from both external and internal unauthorized access and exploitation. The IT networks also provide secured data storage and backup power for continued operation in the event of an electrical power failure. The scope and adequacy of these measures should be verified, assessed for adequacy for both wired and wireless transmissions, and augmented if necessary during the IASS design phase. If remote or off site access to security information is a requirement of the airport security system, the means to accomplish this should be reviewed and evaluated during the design process.
IT networks should be able to support mobile responders over secured wireless links which provide video, voice, and data services as well as location services for mobile responders on foot or in vehicles. Both wired and wireless links will typically be involved, with the cable plant typically supporting distributed access points for wireless delivery. Secured wireless extensions of the wired LAN will be especially important for mobile responders.
Physical Access Control System (PACS)
The PACS is the core of any access control system. It consists of physical hardware and barriers such as doors and door locks, personnel turnstiles, vehicle gates, and other physical means of controlling entrance of persons and vehicles into secured areas of the airport. These PACS elements should be integrated with card access control readers which interface with field control panels, security management servers, security client workstations, Dispatch Center client workstations, and other workstations that have a need for the information generated by the access control readers, e.g., card user identifier, date and time of access, etc. These devices should also be integrated with various command and control servers, video surveillance servers, and biometric and/or credential specific host servers and services.
The PACS will use personnel badges issued for access to secured areas of the area. Validating the identity of individuals applying for such badges to access secured areas of an airport is the responsibility of the airport.
Historically, many airport access control systems used credentials in the form of magnetic stripe cards, with many then upgrading to contactless proximity cards which employ Radio Frequency (RF) transmission or to so-called “smart cards” which use both contact and RF capabilities (contactless) and incorporate a microprocessor chip for authentication functions. These access control measures, however, do not positively link a badge with the badged person – only a biometric can do this. Biometrically-enabled access control smart cards are the next step in this evolutionary process.
The key issue for controlling access to secured areas of an airport is validating the identity of an individual who seeks such access. A validated credential-based and biometricallyenabled smartcard will do this. An ID Management System (IDMS), composed of the applications, databases and services to manage the lifecycle of individual credentials, is the preferred context for making that happen at an airport, scaled to local needs and to the availability of resources, including trained staff.
An IDMS serves two core functions:
- Identity Assurance – Workflow and records management tools enabling adjudication of identities and the maintenance of those identities over time (e.g., name changes, revocation, and termination). These services typically include sponsorship, enrollment, adjudication and approval for issuance.
- Credential Management – Workflow, records and card application management tools to issue a credential and to maintain that credential through its lifecycle for the individual.
The IDMS provides the basis of credentialing including workflow, integrity, and security around records that establish who an individual is and the credentials that represent that individual. The term “credential” means any type of token, badge, pass, digital certificate etc., which can be used to establish a person’s identity when used at an access point. Once authenticated, the credential can be used to assert a claim of existence or a local privilege, such as being able to obtain an access control card.
The preferred method of authentication is Public Key Infrastructure (PKI) which uses both public keys and private keys in the authentication process. How the public and private keys are implemented, and how the private keys are managed and distributed for updating remote readers, are major PACS design considerations.
A portal to a secured area has both a public side and a secured side. Equipment installed on the public side is potentially vulnerable to tampering and electronic intercept. To avoid these problems, authentication should be performed on in a secured environment either at the portal, on its secured side, or by transmitting a person’s biometric data to a secured central facility over a secured IT network.
It is also possible to perform match-on-card, in which the individual’s biometric data are stored on the individual’s smart card along with the PKI private key. The reader contains the biometric scanner and holds the PKI public key. When the smart card is presented and the individual places his/her finger on the scanner, authentication is performed on the smart card when it is inserted into the reader – no biometric information is stored in the reader and no biometric or private key information is transmitted over radio links, minimizing the risks of the authentication process being compromised.
Intrusion Detection System (IDS)
Both ICAO and the U.S. TSA require that an airport secure its perimeter against unauthorized access. That is the function of an IDS; how it is accomplished is the joint responsibility of the airport owner and the security system designer.
Every airport perimeter is unique in terms of its physical characteristics – topography, length, urban or rural setting, forested or open land, etc. and each IDS must take these factors into consideration in evaluating how to counter threats and vulnerabilities identified in the security ConOps.
The airport perimeter is not necessarily the boundary of the secured area of the airport or the air operations area (AOA), particularly at large facilities, where a fenced perimeter may be a significant distance from secured areas. The security system designer must understand these areas and their individual and particular security requirements as stated in the airport’s ConOps and the Airport Security Program (ASP) documents.
In addition to any physical barriers such as fences and buildings (or procedural boundaries), detection of intrusions through the perimeter can be enabled by using a variety of different sensors, which when combined become the Perimeter Intrusion Detection System (PIDS).
In some cases, IDS coverage may have to be extended beyond the airport perimeter in order to provide “early warning” of suspicious persons or vehicles approaching the airport perimeter, especially when the perimeter is in close proximity to secured areas.
Perimeter security should be treated in terms of areas and zones for which functional security requirements should be established. This includes portals such as doors and vehicle gates, which should be integrated with the functional requirements of their surroundings rather than be treated as individual sites.
For assessment purposes, the IDS should interface with video surveillance devices, with geo-referenced software in the SOC which communicates wirelessly with security personnel and responders, and with a variety of sensors used for detecting perimeter intrusions.
In addition to monitoring the airport perimeter, an IDS will often include capabilities to track targets which are detected breaching the perimeter, to integrate information from the entry of authorized personnel and vehicles through portals at the perimeter, and to track vehicle movements on the property when vehicles are fitted with appropriate transponders and/or geo-location devices. An IDS could also provide intruder presence detection within the secure area (using surveillance techniques).
Video Surveillance and Management System
Video surveillance supports PACS, IDS and SOC functions. When video imagery is integrated with the IDS, and displayed in the SOC, it provides essential information for perimeter monitoring, target assessments, and incident management.
For most airports, CCTV cameras will be the primary means of imaging targets because of their relatively low cost and high reliability. Airport monitoring is usually a 24×7 operation. Exterior monitoring requires that the imaging sensors be able to perform detection and assessment functions at night and in poor weather conditions. Night performance may require image intensification devices, which are costly, but for airports near major cites the available sky glow at night plus any perimeter lighting that exists may suffice provided the video cameras are fitted with optics designed for low-light conditions. The IASS designer should validate the performance of candidate cameras at night by tests conducted under actual operating conditions, when appropriate, to determine the most cost-effective solution.
Exterior camera spacing is also dependent on local lighting and weather conditions at the site. Closer spacing is required to meet performance objectives in these conditions, and thus cost is impacted.
In the absence of ambient lighting, and for conditions of fog and smoke, the selective use of more expensive thermal imaging cameras may be appropriate. Additional guards may also be necessary during such conditions.
Video management deals with how video imagery is processed, stored, and integrated with other functions such as PACS alarms and situational awareness software in the SOC. In the case of the SOC, video management applications can be used to manage operator displays and video wall displays, to call up specific sensors and manage their functions, to retrieve and plan back recorded video etc.
When feasible, video imaging devices could be coupled to analytic and situational awareness software in the SOC in order to automate routine surveillance monitoring functions.
Video storage warrants particular attention during security system design, especially video storage which is often a major cost element as well as a management challenge. Video storage is fundamental to video management system design. Digital video storage is enables image enhancement, frame compression, integration with analytical functions such as tripwire detection, rapid access to important video streams, and security measures such ad frame encryption and operator access permissions.
Imaging Sensor Selection and Performance
For airport security, a key issue in establishing surveillance requirements is resolution, i.e., the ability to resolve operationally-significant details at a specified distance. These requirements depend on being able to define various levels of target discrimination, each requiring a different amount of “information”, for example:
- Detection – an object is present,
- Orientation – the longitudinal axis of the target can be sensed,
- Recognition – the class of target can be discerned,
- Identification – target types within a class can be determined.
The imaging performance criteria shown in Table 1 are adapted from the TSA “Recommended Security Guidelines for Airport Planning, Design, and Construction.”
Table 1: Imaging Performance Criteria
| Observer’s Resolution Requirements | Observer’s Confidence Level (probability) | Minimum Horizontal Image Size (in line pairs/millimeter on the display, where 1 lp/mm = 2 pixels) Vehicle Target Truck or SUV | Minimum Horizontal Image Size (in line pairs/millimeter on the display, where 1 lp/mm = 2 pixels) Human Target Standing |
| Detection | 50% 95% | 0.90 2.00 | 1.50 3.20 |
| Orientation | 50% 50% | 1.25 3.00 | 1.80 3.80 |
| Recognition | 50% 95% | 4.50 8.00 | 3.60 7.60 |
| Identification | 50% 95% | 8.00 13.00 | 8.00 26 for security, up to 40 for legal evidence |
The design of video surveillance and video management systems must address a number of factors, of which the following will often drive how these functions are implemented:
- Imaging sensor performance requirements, sensor placements, and environmental constraints, especially for performance under low-light conditions and in conditions of poor visibility.
- Imaging sensor functions, e.g., detection and/or assessment.
- The system architecture for interfacing imaging sensors to the networked communications infrastructure (e.g., at the edge of the networked communications infrastructure), and for implementing the associated video compression, video analytic functions, and video storage.
- The distribution of sensor imagery to stakeholders.
- Airport policies and requirements for the storage and archiving of video imagery.
Video cameras are, and will continue to be, a primary means of detecting and assessing targets approaching an airport perimeter and intruding into the secured area of the airport.
In the context of a modern, networked security system architecture, in addition to standard CCTV technology the following video technologies also merit consideration in designing an integrated airport security system:
- Exterior cameras which can operate at moonlight-equivalent scene illumination in monochrome mode using low numerical aperture lenses (f/1/4 to f/1.8) without requiring image intensifiers.
- Exterior cameras which have wide dynamic range capability to operate in daylight as well as in the presence of point light sources, including headlights, at night.
- Megapixel cameras which can be zoomed electronically and still provide VGAquality resolution. Whether and how such cameras can be employed with video analytics must be part of the evaluation.
- Advanced video compression deployed in devices at or close to the edge of the network in order to minimize transmission bandwidth.
- Video analytics applied to automate detection and assessment functions in the SOC. Many video analytic functions are available, and the technology is maturing rapidly. The issue is to select the functions which will perform under real-world situations with acceptable false alerts.
- Video management software which the SOC operator can use to present those CCTV and Forward Looking InfraRed (FLIR) images which are needed for surveillance and response to a particular event.
- System integration, so that the elements of the enhanced security system function seamlessly and distribute relevant information to the parties who need the information, principally the mobile responders.
Video surveillance camera requirements depend on target characteristics, scene visibility, scene lighting and other factors.
Video camera operation at night is operationally more demanding than in daytime. Camera detector performance is non-linear, dropping as the quantity of photons delivered by the objective lens drops. Camera and lens selection must deal with these issues for night surveillance to be successful, especially if video analytic functions are used because they require clear, sharp images in most instances.
Thermal Imaging Sensors
Thermal imaging sensors, also known as Forward-looking InfraRed (FLIR) sensors, sense radiated heat and do not depend on visible illumination. This means that day and night performance can be nearly the same, and that targets can be imaged in modest fog and in the presence of most smoke.
FLIR/ Vicon can provide target assessments at night and in bad weather, both of which are essential for airport perimeter coverage. They can do this without regard for variations in visible light including strong point light sources which may be employed on the airside and along terminal roadways at night.
Compared to visible CCTV imagers, FLIR/ Vicon have less resolution because of their longer wavelengths; the resolution of a midwave 3 to 5 micron they will be approximately onequarter (1/4) that of a visible camera and a long wave 8-10 micron FLIR will have approximately one-tenth (1/10) the resolution of a visible camera.
FLIR detectors, even if uncooled, are significantly more expensive than CCD and CMOS video detectors. FLIR optics, which use germanium or other types of crystals, are similarly more expensive than video camera lenses and the selection of focal lengths is more limited. It may not be affordable to realize comparable range performance with FLIRs and video cameras, and this must be evaluated when considering the use of FLIR sensors.
Video Management
Video management encompasses video routing, video storage, and the integration of sensor inputs including video analytics. Video management is also integral to the design of the SOC including situational awareness programs, operator displays and video wall displays.
The specification of video management functions should be based on ease of use, flexibility, scalability, and integration with video components including video analytics and video storage. For example, pairing remote-surveillance with intrusion-detection systems results in event-triggered surveillance, which may be particularly useful for vulnerable areas that might not otherwise require constant observation, such as employee gates or power substations.
Airports should be aware of limitations of human operators to watch banks of video monitors for extended periods of time. In routine situations, event triggered surveillance and other video analytic functions can reduce the propensity for human error and also reduce the need for, and cost of, employing human operators on multiple shifts.
Enabling information sharing – video, voice, and data – among airport security and law enforcement units should be a main design objective for the video management system. This capability should extend to mobile security personnel and mobile responders, on foot and in vehicles, over secured wireless links provided by the networked communications infrastructure of the airport.
Edge Architecture, Transmission Bandwidth, and Digital Video Storage
IP-based video systems are able deliver high-quality, low latency, digital video with better image quality and with significant savings in cabling and cable pathway costs, network transmission bandwidth, and video storage costs.
Transmitting uncompressed video over an IT network is not a practical solution. Video compression is normally done using one of the ITU standard MPEG codecs, the most recent being the MPEG-4 AVC which is also an ITU standard, H264.
Considering that video storage costs can exceed video camera costs, the security system design process should assess the video storage required by the operational requirements identified in the ConOps and ways to minimize resulting video storage. Some of the options to be considered are:
- Resolution: The available options include CIF, 2CIF, and 4CIF, the latter being considered full video.
- Frame Rate: The standard video frame rates are 25 frames per second (fps) for PAL and 30 fps for NTSC. For many camera installations, motion is either infrequent or can be observed, and stored, at 15, 7, and even 1 fps.
- Flow Control: Storage volume can be reduced if, during periods of little activity, the frame rate of transmitted video is reduced so long as when activity is detected, based on changes to as few as 2 to 4 pixels, normal video operation can be instantly resumed to ensure that important information is not lost.
- Event-Only Video: Recording only activity in specified regions of interest (ROIs) can significantly reduce the volume of stored video imagery.
- Storage Duration: It is common to store surveillance camera video for a period of 30 days, but this is neither a standard nor a regulatory requirement. Duration should be determined by studying the requirements of departments within the airport which have a stake in how and for what period video is stored, and how these requirements should be implemented across different surveillance sites.

