What is CAPSS and why does it matter to your organisation?
Our NPSA article looked at the difference between AACS (Automatic Access Control Systems) and CAPSS (Cyber Assurance of Physical Security Systems), and where the National Protective Security Authority (NPSA) fits in as the umbrella authority behind both.
Kris Simons
Sales Director, ATEC
“The point CAPSS makes is a simple one. Physical security systems are networked IT systems, and they should carry the same risks as everything else on the network. CCTV recorders, door controllers, intruder panels and perimeter detection all need patching, hardening and monitoring, and somebody has to own that work.”
In this article
Share on:
CAPSS sets out minimum standards for cyber resilience
This article goes deeper into CAPSS specifically:
- Why physical security systems should now be considered an IT risk
- What CAPSS actually covers, including the seven risk areas it assesses
- Why the gap between physical security teams and IT teams is one of the vulnerabilities it’s designed to close
- How to start using the CAPSS supplier questionnaire in your own procurement and reviews
Modern physical security systems are no longer purely physical. They now run on IT infrastructure just like the rest of your network:
- CCTV networks processing and storing footage on servers
- Access control systems communicating across your network
- Perimeter detection connected, in many cases, to the internet
That makes them as vulnerable to cyber attack as any other IT system in your organisation. In some ways, more so.
This is the reality that sits behind CAPSS. Published and maintained by NPSA, CAPSS sets out the minimum standards that physical security systems should meet to be considered cyber resilient.
A technical standard with real operational consequences
CAPSS is a technical standard and certification scheme. It defines the security requirements that physical security system products should meet, covering everything from how devices authenticate users to how software updates are delivered, how networks are segregated, and how system events are logged and monitored. Products that meet the standard can be evaluated and certified for inclusion in NPSA’s Catalogue of Security Equipment (CSE).
The framework is not new. It has been in development since 2019, but the January 2024 update represents the most comprehensive version to date. It covers seven distinct risk areas:
- network security,
- system administration,
- physical protection of devices,
- data protection,
- malware protection,
- product quality, and
- monitoring and logging.
Each area contains specific controls, graded by risk level and by the relative complexity and cost of implementation.
CAPSS is not only relevant to organisations procuring new systems. It applies equally to organisations assessing the security of existing installations, and the picture it paints of legacy physical security infrastructure is, in many cases, uncomfortable reading.
Physical security and IT need to be joined up
The core challenge CAPSS addresses is one that most security professionals will recognise immediately. Physical security teams understand cameras, door controllers and perimeter systems. IT security teams understand networks, patching and access management. The problem is that modern physical security systems require both sets of knowledge, and in most organisations the two teams operate in separate silos with limited visibility of each other’s work.
The consequences of that gap are real. A CCTV network that has never been patched because the physical security team did not know patching was required, and the IT team did not know the system existed. An access control server running on an operating system that went out of support years ago. Default passwords still active on network switches installed during a building fit-out in 2016. These are not hypothetical scenarios; they are documented in the CAPSS guidance itself.
CAPSS identifies this separation of teams as one of the primary structural vulnerabilities in the current landscape, and the guidance is designed specifically to give organisations the framework to close it.
From compliance checkbox to operational tool
Whether or not your organisation is formally required to comply with CAPSS, and for operators of Critical National Infrastructure (CNI) and government sites the expectation is increasingly that they should be, the framework provides a practical tool for assessing the cyber resilience of any physical security installation.
The guidance includes a detailed set of controls with clear actions, along with a supplier questionnaire that can be used in procurement to assess whether the products being specified actually meet the required standards. It also includes a risk overview table mapping each control against its risk level, implementation complexity and relative cost. This makes it genuinely useful as a planning and prioritisation tool, not just a compliance checklist.
For organisations that cannot immediately deploy fully CAPSS-certified products, and given that certification is still relatively new, that covers a significant proportion of the market, the guidance provides a route to address the same risks using existing equipment and updated processes.
The supplier questionnaire you should already be using
CAPSS Appendix B contains a supplier questionnaire that any organisation should consider using when procuring or reviewing physical security systems. The questions are pointed and practical. Can the software in your devices be updated, and within what timeframe? Are there any undocumented developer-installed accounts on your systems? What happens to this device if power is lost, does it fail secure? Has your organisation’s access control server been included in your leaver process, so that former employees cannot retain system access after their other permissions have been revoked?
These are not obscure technical questions. They are the kinds of questions that, if they had been asked earlier, would have prevented a significant number of the incidents the CAPSS document uses to illustrate what poor practice looks like in the real world.
Physical security systems should be held to IT and cybersecurity standards
Physical security systems have long been regarded as a domain apart from mainstream IT, managed by different teams, procured through different processes, and largely invisible to an organisation’s wider cybersecurity posture. CAPSS represents a formal, government-backed recognition that this separation is no longer tenable.
For organisations operating in high-security environments, including critical infrastructure, government, aviation, financial services and major public venues, the direction of travel is clear. Cyber resilience in physical security systems is moving from best practice to expected standard. The organisations that get ahead of this shift, rather than responding to it after an incident, will be better positioned both operationally and in terms of their relationships with clients, insurers and regulators.
The CAPSS guidance document is available in full at npsa.gov.uk. For organisations looking to understand what it means for their specific installation, and what steps are most immediately worth taking, ATEC’s team can help.
Final thoughts
The seven risk areas give you a structure for auditing an existing installation: network security, system administration, physical protection of devices, data protection, malware protection, product quality, and monitoring and logging. Go through each one against the systems you have and the gaps tend to surface quickly.
If your physical security team and your IT team are not discussing the same systems, no standard will fix that on your behalf. Agreeing who owns each control, and getting both teams looking at the same asset list, is usually the step that makes everything else possible.
None of this requires a large programme of work to begin. A documented list of every networked security device on your sites, with its firmware version and who is responsible for it, is a realistic first step and more than many organisations currently have.
Read about CCTV
Share on: