# NCSA CCTV and AI CCTV Security Guidelines 2026

Locale: `en`

Source: `/en/compliance/ncsa-cctv-security-guidelines/`

On this page

1. [Overview](/en/compliance/ncsa-cctv-security-guidelines/#topic-overview)
2. [Four-layer architecture and system lifecycle](/en/compliance/ncsa-cctv-security-guidelines/#cctv-defense-in-depth-architecture)
3. [Risk assessment and B, E and H control levels](/en/compliance/ncsa-cctv-security-guidelines/#cctv-impact-levels-framework)
4. [Technical acceptance and system testing](/en/compliance/ncsa-cctv-security-guidelines/#cctv-technical-acceptance-testing)
5. [Requirements Matrix](/en/compliance/ncsa-cctv-security-guidelines/#compliance-matrix)
6. [Readiness Assessment](/en/compliance/ncsa-cctv-security-guidelines/#compliance-readiness-checklist)
7. [Frequently Asked Questions](/en/compliance/ncsa-cctv-security-guidelines/#compliance-faq)
8. [Related Frameworks](/en/compliance/ncsa-cctv-security-guidelines/#related-compliance-frameworks)

# NCSA CCTV and AI CCTV Security Guidelines 2026

A technical guide to TCSG and TCSG AI by NCSA and iCA, covering four-layer defense in depth, risk-based B, E and H control levels, technical acceptance, and context-appropriate assurance evidence.

Guideline Implementation Overview

Target Audience

Government agencies, Critical Information Infrastructure (CII) operators, enterprise CCTV administrators, and organizations deploying AI video analytics

Acceptance and Review

Acceptance before operation, followed by reviews based on mission criticality, data and AI impact, system change, and incident history, with additional review after significant events or changes.

System Scope

IP cameras, edge analytics devices, network switches, VMS, NVRs, video storage repositories, AI vision models, analytics APIs, and management consoles

Risks to Manage

Unauthorized video stream interception, device hijacking into DDoS botnets, PDPA non-compliance, adversarial AI evasion attacks, and technical acceptance audit failures

## Four-layer architecture and system lifecycle

TCSG presents a four-layer defense-in-depth framework and a ten-phase lifecycle. Select measures proportionately to system purpose, criticality, and risk. The following are examples for each layer.

[![CCTV and AI CCTV: four defence layers: Device, Network, Platform, Management](/assets/generated/compliance-refresh/cctv-defence-layers-en-v1.webp)](/assets/generated/compliance-refresh/cctv-defence-layers-en-v1.webp)

**CCTV and AI CCTV: four defence layers**

An explanatory overview. Read the article for scope, applicability and supporting evidence.

- **Device** — Cameras, firmware and physical access
- **Network** — Segmentation and controlled connectivity
- **Platform** — VMS, access and storage
- **Management** — Accountability, data and providers

- Device and Field Layer: protect equipment against unauthorized access, replace default credentials, disable unnecessary services, and verify firmware version and integrity.
- Network and Connectivity Layer: define network boundaries and remote-management paths. Select segmentation, access controls, and encrypted transport according to risk, avoiding uncontrolled public port forwarding.
- Platform Layer: protect VMS, NVR, and video storage; apply least privilege, retain useful logs, and select controls for stored and transmitted data according to risk.
- Users and Management Layer: define policies, accountable roles, and provider controls. For cloud services, assess data and processing location, jurisdiction, administrative access, subprocessors, key control, and an exit strategy according to risk.

## Risk assessment and B, E and H control levels

Assess overall system impact together with the use of AI to select a proportionate control level. B, E, and H are cumulative levels, not labels assigned solely by technology or location type.

[![CCTV: assess impact before choosing a tier: Assess context, Consider AI factors, Select B / E / H, Record the rationale](/assets/generated/compliance-refresh/cctv-impact-assurance-en-v1.webp)](/assets/generated/compliance-refresh/cctv-impact-assurance-en-v1.webp)

**CCTV: assess impact before choosing a tier**

An explanatory overview. Read the article for scope, applicability and supporting evidence.

- **Assess context** — Mission, data, exposure and impact
- **Consider AI factors** — Automation and affected people
- **Select B / E / H** — Cumulative controls based on impact and risk
- **Record the rationale** — Review when systems or context change

- Four dimensions: system or mission criticality, data impact, connectivity and exposure, and the operational and security impact of failure or attack.
- AI impact: consider capability, consequences of error, human review, affected population, reversibility, and the authority of outputs from informing through automated action.
- Amplification factors: consider APIs, workflows, access-control or command systems, connected systems, impact scale and propagation speed, reversibility, and human oversight.
- B provides baseline measures; E adds enhanced measures to B; H adds higher-assurance measures to B and E. Overall impact and risk determine the level. Camera count, cloud use, biometrics, or CII status alone does not automatically determine a tier.

## Technical acceptance and system testing

TCSG Clause 3.3.5 and Appendix A, together with TCSG AI Clauses 4.4.7 and 5.2, recommend acceptance against the approved design and use case, with testing scope and assurance evidence selected according to impact and risk.

[![CCTV: acceptance, testing and review: Prepare the system, Technical acceptance, Risk-based testing, Follow up and review](/assets/generated/compliance-refresh/cctv-acceptance-review-en-v1.webp)](/assets/generated/compliance-refresh/cctv-acceptance-review-en-v1.webp)

**CCTV: acceptance, testing and review**

Pentesting is not prescribed for every CCTV system. Tier H systems may consider independent VA or pentest evidence, while AI assurance methods depend on the use case and risk.

- **Prepare the system** — Check versions, configuration and scope
- **Technical acceptance** — Image quality, time, access and logs
- **Risk-based testing** — Select VA, pentest and AI assurance methods
- **Follow up and review** — Remediate, retest and retain evidence

- Acceptance checks: camera position and view, DORI image quality, day and night performance, privacy masks, time, retention, segmentation, ports and services, firmware and software versions, logs and alerts, backup and recovery, and as-built documentation.
- For Tier H systems, independent and clearly scoped evidence, such as a VA or penetration test, may be considered according to risk. It is not automatic for every Tier H deployment.
- AI testing should cover the use case, error patterns, action boundaries, human oversight, degraded mode, and fail-safe behavior. Select adversarial-robustness testing according to system characteristics and risk.
- Handover should provide sufficient operational evidence, including as-built information, versions and configuration, test results, vulnerability-management support, lifecycle status, and decommissioning information.

## Guidance and Risk-Based Assessment Scope

Recommendations and illustrative scope selected for the context and risk, not mandatory testing for every system.

| Guideline Reference | Guidance Topic | Illustrative Scope | Review Timing |
| --- | --- | --- | --- |
| **TCSG Clauses 3.2.1 to 3.2.4** | Architectural design and device security baselines | VLAN segmentation, disabling insecure ports and protocols, default credential elimination, encryption, and physical security | During architectural design and installation prior to production |
| **TCSG Clause 3.3.5 & Appendix A** | Post-installation technical acceptance testing | Verification of port configurations, firmware baselines, network isolation, privacy masking, secure NTP sync, and audit logging | Pre-handover verification against the approved requirements |
| **TCSG Clause 3.2.5.5** | Assurance evidence for Tier H systems | Independent, clearly scoped VA or penetration-test evidence may be considered according to risk | As justified by risk, events, and significant change |
| **TCSG AI Clauses 3.2.5, 4.4.7 and 5.2** | AI performance, trustworthiness, and security testing | Use cases, error patterns, action boundaries, human oversight, degraded mode, fail-safe behavior, and risk-relevant robustness | Before operation and after changes that may alter impact or risk |

### Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Maintain an exhaustive inventory of all IP cameras, NVRs, VMS servers, and AI analytics nodes
          
          
            
            Conduct a 4-dimension impact assessment with AI amplification factors to establish control tier (B, E, or H)
          
          
            
            Define segmentation and external exposure according to tier and risk, avoiding uncontrolled public port forwarding
          
          
            
            Replace default credentials, restrict privileges, and use MFA for relevant administrative accounts or channels according to tier and risk
          
          
            
            Perform acceptance under Clause 3.3.5 and Appendix A, including DORI, privacy masks, time, retention, segmentation, logging, backup, and as-built evidence
          
          
            
            For Tier H systems, consider independent VA or penetration-test evidence and select AI testing according to the use case and risk

Assessment Status

Check items above to view assessment result.

[Request Pentest Quote](/en/#contact)

## Frequently Asked Questions (FAQ)

Key answers and practical guidance addressing common compliance questions.

### What is the legal status of NCSA TCSG and TCSG AI guidelines?

Both documents are non-binding recommendations. They do not replace applicable laws, regulations, contractual duties, or other requirements; each organization must assess its separate legal and regulatory obligations.

### Is penetration testing mandatory for all CCTV systems?

The guidelines do not require penetration testing for every CCTV system. For Tier H systems, independent and clearly scoped VA or penetration-test evidence may be considered according to risk. CII status, public-area use, or biometric processing alone does not determine the tier.

### How do cybersecurity risks in AI-enabled CCTV systems differ from conventional CCTV?

AI CCTV systems expand the threat surface through sensitive biometric processing, vulnerabilities to computer vision adversarial perturbations (evasion patches disrupting facial or license recognition), external API interconnections, and automated decision-making workflows, requiring dedicated evaluation under the TCSG AI framework.

## Related Compliance Frameworks and Security Standards

- [
                Thailand Cybersecurity Act 2019 and penetration testing
                
              ](/en/compliance/cybersecurity-act/)
- [
                NCSA AI Security Guidelines: lifecycle and governance
                
              ](/en/compliance/ncsa-ai-security-guidelines/)
- [
                NCSA Zero Trust Guidelines
                
              ](/en/compliance/ncsa-zero-trust-guidelines/)
- [
                ISA/IEC 62443 OT cybersecurity and OT pentest guide
                
              ](/en/compliance/iec-62443/)

Open full-size image to zoom

## Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

[
            
              
              
              ![First-page preview of Thailand CCTV Security Guidelines (TCSG)](/assets/process/compliance-sources/sth-source-ncsa-cctv-security-guidelines-2569.webp)
            
          ](/assets/documents/sth-source-ncsa-cctv-security-guidelines-2569.pdf)

### Thailand CCTV Security Guidelines (TCSG)

By NCSA & iCA

[Open document (PDF) ](/assets/documents/sth-source-ncsa-cctv-security-guidelines-2569.pdf)
              [Download ](/assets/documents/sth-source-ncsa-cctv-security-guidelines-2569.pdf)
              
              [Source ](https://www.ncsa.or.th/standards)
              [NCSA Standards Portal ](https://www.ncsa.or.th/standards)

[
            
              
              
              ![First-page preview of Thailand AI-Enabled CCTV Security Guidelines (TCSG AI)](/assets/process/compliance-sources/sth-source-ncsa-ai-cctv-security-guidelines-2569.webp)
            
          ](/assets/documents/sth-source-ncsa-ai-cctv-security-guidelines-2569.pdf)

### Thailand AI-Enabled CCTV Security Guidelines (TCSG AI)

By NCSA & iCA

[Open document (PDF) ](/assets/documents/sth-source-ncsa-ai-cctv-security-guidelines-2569.pdf)
              [Download ](/assets/documents/sth-source-ncsa-ai-cctv-security-guidelines-2569.pdf)
              
              [Source ](https://www.ncsa.or.th/standards)
              [NCSA Standards Portal ](https://www.ncsa.or.th/standards)

## Need a risk-based CCTV security assessment?

Describe your system and risks to select appropriate assessment scope and evidence.

[Request a Pentest quote](/en/#contact)

## PDF document

[Open in new tab ](/en/compliance/ncsa-cctv-security-guidelines/)
              [Download](/en/compliance/ncsa-cctv-security-guidelines/)

Last updated 6 October 2026
