– STUDY KNOWLEDGE BASE

Study Knowledge Base

A reference library covering physical security standards, network infrastructure guidance, OT and ICS frameworks, compliance frameworks, and the installation, configuration, and design work that depends on them. Maintained by Hans Study. Updated as the underlying standards evolve and as field experience surfaces gaps.

37 entries · 14 standalone · 23 chapters across 1 multi-chapter reference · being built out actively

If you arrived from securitystandards.ca, this is the destination. The redirect was configured because the standards reference work and the consulting practice are the same person.

Multi-Chapter References

1 reference

Physical Security

6 entries
Chapter 12 · Canadian Security Install Reference

Access control head-end

Access control head-end design for Canadian institutional installs. Platform selection, server sizing, Mercury hardware, HID Aero, Software House C-CURE, Genetec Synergis, Hirsch Velocity for high-security, database and high-availability, integration with directory and identity systems.

UL 294CAN/ULC-S319
Chapter 13 · Canadian Security Install Reference

Access control at the door

Access control hardware at the door for Canadian institutional installs. Reader selection, OSDP vs Wiegand, electric strikes, maglocks, exit devices, door operators, REX devices, door position switches, fire alarm release, wiring topology, mounting heights, ADA compliance.

UL 294CAN/ULC-S319NFPA 101
Chapter 14 · Canadian Security Install Reference

CCTV and video

Video surveillance for Canadian institutional installs. Camera type by application, resolution and PPF/PPM, lens selection, mounting heights and angles, VMS platforms, storage sizing, retention, privacy and regulatory compliance, banned manufacturers, network design.

IEC 62676
Chapter 15 · Canadian Security Install Reference

Intrusion detection

Intrusion detection for Canadian institutional installs. ULC-S304 / S319 compliance, panel selection, sensor types (PIR, glassbreak, contact, beam, LiDAR), zone design, supervised wiring, central station monitoring, false alarm reduction, EOL resistor supervision.

CAN/ULC-S302CAN/ULC-S303UL 681
Chapter 16 · Canadian Security Install Reference

Detention and high-security

Detention and high-security installs for Canadian institutional work. Anti-ligature hardware, pick-proof sealants, RGS-only pathway, sallyport interlocks, holding cell coverage, evidence room access, courtrooms, secure document handling, federal compliance, Hirsch ScramblePad for high-security PIN entry.

ASTM F1577ASTM F1592NIC standards

Security Controls for CCTV and Access Control Networks

Ten practical security controls every physical security network needs. Hardening, VPN, segmentation, logging, credentials, MFA, and more.

NIST SP 800-53UL 294IEC 62676

Structured Cabling

5 entries
Chapter 07 · Canadian Security Install Reference

Cable selection by environment

Cable selection by environment for Canadian institutional security installs. Cat 6A, Cat 6, plenum (CMP), riser (CMR), general purpose (CM), outside plant (OSP), shielded vs unshielded, alien crosstalk, indoor-to-outdoor transition splice, 15 m rule.

ANSI/TIA-568.2-DCSA T529CSA C22.2 No. 214
Chapter 08 · Canadian Security Install Reference

Fiber optic cabling

Fiber optic cabling for Canadian institutional security installs. OS2 single-mode, OM4/OM5 multimode, fiber count planning, loose-tube vs tight-buffered, LC/SC connectors, UPC vs APC, splice trays, splice enclosures, pigtail-and-splice termination, Sumitomo splicers, Corning and CommScope cable.

ANSI/TIA-568.3-EIEC 61753
Chapter 09 · Canadian Security Install Reference

Termination procedures

Termination procedures for Canadian institutional security installs. Cat 6A keystone and patch panel terminations, T568A/B wiring, wire-to-wire junction connections, DIN-rail terminal blocks at panels, fiber pigtail-and-splice, service slack and strain relief, dressing and labelling at termination.

ANSI/TIA-568
Chapter 10 · Canadian Security Install Reference

Cable testing and certification

Cable testing and certification for Canadian institutional security installs. ANSI/TIA-568.2-D parameters, permanent link vs channel test, autotest, Tier 1 OLTS fiber test, Tier 2 OTDR, manufacturer warranty programs, Fluke DSX-8000 series, certification report format.

ANSI/TIA-568IEC 61935-1

TIA-568 Structured Cabling: Reference for Security Networks

What TIA-568 actually requires for the cabling that physical security systems run on, and where integrators commonly fall short of it.

TIA-568.0-ETIA-568.1-ETIA-568.2-ETIA-568.3-E

Switch Configuration

6 entries
Chapter 11 · Canadian Security Install Reference

Network devices for security

Network device selection and configuration for Canadian institutional security installs. Managed switches, PoE budget management, VLAN segmentation, configuration baseline, Cisco Catalyst, Aruba CX, industrial DIN-rail switches, distribution and core layers.

IEEE 802.1QIEEE 802.3bt

Juniper EX Series Base Configuration for CCTV and Security Networks

Juniper EX series (Junos OS) configuration template: VLANs, SSH, AAA, Virtual Chassis, port security, BPDU guard, aggregated Ethernet, QoS, and syslog for physical security networks.

IEEE 802.1QIEEE 802.3btJunos

ALE OmniSwitch 6360 and 6560 Base Configuration for CCTV and Security Networks

Alcatel-Lucent Enterprise OmniSwitch 6360/6560 (AOS 8) configuration template: VLANs, SSH, AAA, Virtual Chassis, port security, BPDU guard, link aggregation, QoS, and syslog for physical security networks.

IEEE 802.1QIEEE 802.3btAOS 8

Aruba CX 6200 and 6300 Base Configuration for CCTV and Security Networks

Aruba CX 6200/6300 (AOS-CX) configuration template: VLANs, SSH, AAA, VSF, port security, BPDU guard, LACP LAG, QoS, and syslog for physical security networks.

IEEE 802.1QIEEE 802.3btAOS-CX

Cisco Catalyst 9200 and 9300 Base Configuration for CCTV and Security Networks

Complete Cisco Catalyst 9200/9300 configuration template: VLANs, SSH, AAA, port security, DHCP snooping, DAI, QoS, and syslog for physical security networks.

IEEE 802.1QIEEE 802.3btIOS XE

VLAN Segmentation for Physical Security Networks

The segmentation conversation is one I have had hundreds of times. Usually after something has already gone wrong. A workstation on the same network as the...

IEEE 802.1Q

Standards Reference

2 entries

Compliance Frameworks

0 entries

No entries published in this category yet. In progress.

Installation Guidance

13 entries

Security System Hardening Guide

End-to-end hardening reference for physical security network infrastructure. Switches, servers, workstations, cameras, access control panels, RADIUS via NPS, vulnerability assessment, and checklists.

NIST CSFCIS BenchmarksDISA STIGNIST SP 800-171
Chapter 02 · Canadian Security Install Reference

Pathways and conduit

Conduit, raceway, and supports for Canadian institutional security installs. Conduit type by environment, support spacing, fittings, pull boxes, backboxes, fill, expansion, sealing, mounting heights, surface raceway, cable tray, J-hooks, underground pathway, detention envelope.

CEC Section 12CSA T530
Chapter 03 · Canadian Security Install Reference

Power, UPS, and redundancy

Power and UPS design for security systems in Canadian institutional installs. Branch circuits, dual-cord PDUs, surge protection, UPS sizing, runtime calculation, voltage drop tables, PoE budgets, generator coordination, breaker locks, identification.

CSA-Z32CEC
Chapter 04 · Canadian Security Install Reference

Grounding and bonding

Grounding and bonding for Canadian institutional security installs. CEC Section 10, CSA T607 / ANSI-J-STD-607-A, TMGB and TGB sizing, telecommunications bonding backbone (TBB), rack bonding, cable tray bonding, equipment bonding, ground resistance measurement.

CEC Section 10CSA T527ANSI/TIA-607-D
Chapter 05 · Canadian Security Install Reference

Firestopping

Firestopping for Canadian institutional security installs. ULC-S115 systems, fire-rated wall and floor penetrations, smoke barriers, 3M and Hilti firestop products, putty pads, intumescent sealants, foam, identification labels.

CAN/ULC-S115NBC
Chapter 06 · Canadian Security Install Reference

Identification and labelling

Identification and labelling for Canadian institutional security installs. ANSI/TIA-606-B, cable label format, patch panel labelling, conduit colour banding, rack and equipment lamacoid plates, panel directories, asset tagging.

CSA T528ANSI/TIA-606-C
Chapter 20 · Canadian Security Install Reference

Rack and cabinet hardware

Rack and cabinet hardware for Canadian institutional security installs. 19-inch rack standards, U-space planning, floor and wall-mount racks, cable management, airflow, PDUs, ground bonding hardware, environmental cabinets, lockable doors and access control.

ANSI/EIA-310CSA T530
Chapter 21 · Canadian Security Install Reference

Tools of the trade

Tools for Canadian institutional security install work. Hand tools, power tools, cable installation and termination tools, test instruments, software platforms, truck stock, calibration and maintenance schedule.

Chapter 22 · Canadian Security Install Reference

Commissioning and acceptance

Commissioning and acceptance for Canadian institutional security installs. Pre-commissioning verification, CAN/ULC-S1001 integrated systems testing, per-system commissioning, final acceptance walkdown, training, post-substantial-completion follow-up, documentation handover.

ANSI/TIA-568CSA T528

Hardening Windows Server 2016, 2019, and 2022: Audit Logging

Advanced Audit Policy, domain controller GPO, event log sizing, Windows Event Forwarding, Sysmon, key event IDs, and log retention for Windows Server.

DISA STIGNIST SP 800-92NIST SP 800-171

Hardening Windows Server 2016, 2019, and 2022: Hardening with Group Policy

GPO structure, password policy, Kerberos, NTLM restriction, Advanced Audit Policy, Defender, SMBv1 removal, and LAPS via Group Policy.

DISA STIGCIS BenchmarkMicrosoft Security Compliance Toolkit

Hardening Windows Server 2016, 2019, and 2022: Getting Started

Baseline Windows Server hardening: update management, roles audit, local accounts, Windows Firewall, services, NTP, PowerShell logging, and TLS.

DISA STIGCIS Benchmark

Hardening Windows Server 2016, 2019, and 2022: Other Considerations

TLS 1.2 enforcement, legacy exceptions, Remote Desktop hardening, SMB signing, LAPS, and certificate management for Windows Server.

DISA STIGCIS BenchmarkNIST SP 800-171

OT and ICS

1 entry

Network Design

4 entries