16.2 Upgrade Training, System Evaluation & Replacement
Key Takeaways
- After upgrades, train operators, badge staff, and technicians on the new release; manufacturer or vendor certification for maintainers is part of keeping the countermeasure operable.
- Evaluate keep versus replace when as-operated performance no longer meets original metrics, parts are obsolete, or the physical system’s cybersecurity is no longer defensible.
- Total cost of keeping includes scarce labor, last-time-buy spares, nuisance-alarm handling, downtime, and cyber exposure—not only the avoided capital purchase.
- Decommissioning sanitizes NVR and backup media, collects and disables badges and tokens, closes vendor remote and cloud accounts, and updates drawings to as-operated.
- Nuisance alarm rate, door-forced events, and mean time to restore are how you test whether Domain 1 residual-risk treatments still match the current threat.
Upgrade Training, System Evaluation & Replacement
Independent OpenExamPrep teaching for published PSP Domain 3 Task 5 knowledge is that hardware that is still powered is not automatically still the treatment Domain 1 selected. After every upgrade you retrain the people who operate and repair it. On a cycle you evaluate whether to keep, upgrade in place, or replace. When you replace, you decommission so the old plant cannot become a back door. Metrics tell you whether residual risk still matches the current threat.
Exam focus: Upgrade training is role-specific and includes manufacturer certification for technicians. Evaluation compares as-operated performance to original metrics, plus end-of-life, parts obsolescence, and cybersecurity of physical systems. Replacement includes wipe, badge collection, and drawing updates. Nuisance alarms, door-forced events, and mean time to restore are program health, not IT trivia.
Ongoing training after upgrades
Chapter 14 training turned the accepted system over. Upgrade training is the sequel. A VMS major-version jump, a new access-control appliance, or a change from PINs to mobile credentials changes how the SOC acknowledges alarms, how a technician restores a database, and how the badge office issues a credential. The doors may not have moved. The workflow did.
Train by role, not by cafeteria briefing.
SOC operators need the new alarm queue, video client, bookmarking, privacy-mask rules, and escalation tree. If analytic labels changed, the old “Camera 12 motion” muscle memory will miss the event. Use a recorded drill against the SAT script, not a slide deck that says the cutover was a success. If the new client hides acknowledged alarms after 15 seconds, operators who learned the old client will think the event vanished.
Maintaining technicians need manufacturer or vendor certification on the release they will patch, back up, and restore. Certification is not a framed poster in the shop. It is evidence that the person who will recover the panel at 02:00 has used that version’s backup tool, certificate store, and rollback path. After a major release, require recertification or a documented skills check. Integrator technicians turn over; the contract should name certified individuals or a certified bench, not a company logo. A technician certified on the previous appliance who has never restored this appliance is not certified for tonight’s failure.
Badging and escort staff need the new credential types, visitor workflows, printer drivers, and what to do when a reader rejects a still-valid card during cutover. Dual-running two card formats without training the badge desk is how you create a queue of angry employees and a propped staff door.
Security management needs the new exception reports: who is issuing after-hours credentials, which doors are in maintenance bypass, which cameras are in privacy mask, which firmware is off the approved list. If management cannot see bypasses, bypass becomes the unofficial operating mode.
Repeat training when the vendor ships a release that changes workflow, not only when a new hire starts. Keep attendance, the version trained, and a short competency check. A lunch-and-learn that the upgrade “went fine” is not training. Neither is an email with a link to a 90-minute marketing webinar.
The evaluation and replacement process
Evaluation is a planned comparison, not a panic when a camera family is discontinued. Build a file a successor can audit: original requirements, SAT numbers, current retest numbers, OEM support status, cyber findings, and a keep-versus-replace TCO. The program that cannot produce that file is guessing.
Performance versus original metrics
Pull the Chapter 7 performance requirements and the Chapter 14 SAT numbers. Retest a sample: detection probability, read range, nuisance rate, acknowledge time, recording completeness (not merely device ping). If Dock-3 detection has fallen from 95 percent to 45 percent, you do not have a mature system. You have a failed treatment. Maturity language is how vendors sell inertia. Numbers are how PSP candidates decide.
Sample on a cycle. You do not need to re-SAT the entire campus every quarter. You do need a documented sample that includes the assets Domain 1 called critical: the dock, the pharmacy anteroom, the cash room, the data-hall doors. A lobby camera that still looks pretty does not excuse a dead analytic on the trailer kingpin.
End of life and parts obsolescence
Manufacturers publish end-of-sale, end-of-support, and last-time-buy notices. A panel that still boots can be unsupportable: no firmware, no encryption updates, no replacement mainboards. Stockpiling last-time-buy boards is a keep strategy only if firmware and cyber patches still exist. If the OEM cannot patch a known remote exploit, obsolescence has become a security finding, not a procurement inconvenience.
Track substitute parts honestly. A “compatible” reader that speaks a different bit format, or a camera that cannot hold the same analytic license, is not a spare. It is a mini-replacement project hiding inside a work order. If the only remaining boards are gray-market units with unknown firmware, you are already in replacement territory.
Cybersecurity of physical systems
Physical security systems are computers on your network: NVRs, controllers, Windows VMS hosts, cloud camera accounts, badge printers, and the jump box in the SOC. Evaluation must include default or shared passwords that survived turnover, unpatched operating systems, deprecated protocols (unencrypted reader data, Telnet, ancient TLS), vendor remote-access tools left enabled, accounts of departed integrators, and cameras that phone home to a cloud tenant nobody owns. A supposedly isolated DVR that staff bridged with a cheap Wi-Fi adapter is in scope. Domain 1 already admitted cyber-physical hazard. Lifecycle evaluation is where that hazard is re-measured on the installed plant.
Ask the ugly questions. Who can still VPN to the panel? When was the last OEM firmware that still installs? Are backups encrypted, tested, and stored off the same VLAN as the NVR? If ransomware encrypts the VMS host, is video loss a Domain 1 residual you accepted, or a surprise? Physical security programs that treat cyber as “the IT people’s problem” discover during an incident that IT never listed the NVR as an asset.
Total cost of keeping versus replacing
Keep costs are not zero: premium labor for scarce technicians, last-time-buy inventory that may never be used, rising nuisance-alarm labor, downtime at the dock, cyber-incident potential, and the cost of a workaround (extra officers) when electronics no longer detect. Replace costs include design, procurement, installation, commissioning, upgrade training, dual-running, and decommissioning. A five-year spreadsheet that ignores officer overtime and theft leakage will always prefer keep. An honest total cost of ownership will not.
Leadership will ask for a simple capital number. Give the simple number and the operating number. “Keeping this NVR family costs $40,000 in last-time-buy boards plus an unpatchable remote-access finding plus 12 extra officer-hours a week because operators no longer trust the alarm queue.” That sentence is evaluation. “The replacement is expensive” is not.
| Keep (5-year view) | Replace (5-year view) |
|---|---|
| Last-time-buy spares and scarce labor | Capital, installation, SAT, training |
| Rising MTTR and nuisance-alarm handling | Dual-run and cutover risk (time-bounded) |
| Unpatchable controllers or NVR operating systems | New patch cadence and vendor support term |
| Extra posts when detection is no longer honest | Decommission labor (wipe, badges, drawings) |
| Residual risk written back toward untreated | Residual risk retested against the current threat |
Decide in writing. If you keep: fund PM, training, and cyber patching as operating cost, not as heroics. If you replace: run the Chapter 12–14 process again at the right scale. Do not “swap boxes” without requirements, commissioning, and a new SAT sample. A forklift full of new cameras with the old analytic thresholds and the old dirty-power closet is a purchase, not a replacement program.
Decommissioning
Decommissioning is part of replacement, not a dumpster afterthought. The retired plant still holds video, cardholder data, credentials, network paths, and drawings that responders will believe.
Wipe NVRs and other media. Treat recorded video, cardholder databases, and backup drives as sensitive media. Follow a documented sanitization method: cryptographic erase where the device supports it, purge, or physical destruction per the owner’s standard. Powering off a RAID and leaving disks on a surplus pallet is how last year’s visitors become this year’s leak. Confirm cloud recorder tenants and vendor remote gateways are closed, not merely forgotten. Export what retention policy still requires before you wipe, then store the export under the same access rules as live video.
Collect badges and credentials. Recover proximity cards, fobs, mobile-credential enrollments, and vendor or technician tokens. Disable them in the live database and in any still-powered legacy panel if you are dual-running. A box of souvenir cards in a desk is an access-control vulnerability. Cores and keys from retired cylinders belong in the same recovery, with the key-control register updated. Temporary “we will collect them at the holiday party” plans are how contractor cards live forever.
Update drawings and configuration records. As-builts, device schedules, IP tables, and cable identifiers must show the as-operated replacement. If Camera 12 moved three poles west, the emergency binder that still shows the old pole is a response failure. Asset tags and the CMMS should retire the old identifiers so work orders stop dispatching to ghosts. Configuration management from Chapter 14 does not end at acceptance. Replacement is a configuration event.
Other decommission items: recycle e-waste through a chain-of-custody vendor, remove old UPS batteries as hazardous waste, recover wall-wart power supplies that still energize forgotten switches in ceilings, and brief the SOC on which views are gone so operators do not watch a black tile that used to be the yard.
Metrics that show the program still works
Pick measures that describe protection, not busyness. Hours of technician time and the number of tickets closed can look healthy while Dock-3 goes blind.
Nuisance alarm rate. Nuisance and false alarms train operators to ignore the queue. Track per device-day or per 1,000 alarm points, with a baseline from SAT. A PIR that triples after landscaping is a sensor or environment problem, not a staffing problem. If the rate is high, detection is no longer a trustworthy treatment. Operators who disable zones to survive a shift have already rewritten residual risk without telling Domain 1.
Door-forced and door-held events. Compared with the commissioning baseline, a spike can mean door hardware sag, contact gap change, wind, a closer failure, or actual force. Either way, the residual pairing for that opening has changed. Investigate. Do not silence. A nightly cluster of door-forced events with no work order is a program that has stopped looking.
Mean time to restore. MTTR from ticket open to verified restore—including the retest, not merely “camera pings”—shows whether the SLA and spare stock are real. An MTTR of 18 hours on a P1 dock camera means Domain 1 assumed a treatment that is missing for most of a night shift. Close tickets only when the SAT-style check, or a documented equivalent, has passed.
Companion metrics worth pairing: recording completeness versus advertised retention, credentialing lag for new hires, percent of devices on approved firmware, and periodic SAT-sample detection percentage. Together they answer whether the system you bought is the system you still have.
| Metric | Healthy pattern | Program failing while “online” |
|---|---|---|
| Nuisance alarm rate | Near SAT baseline; explained spikes | Steady climb; operators disable zones |
| Door-forced events | Rare and investigated | Nightly cluster with no work order |
| MTTR (P1) | Inside SLA; spare used; retest logged | Days of “on order”; ping-only closeout |
| Detection retest | Within original requirement | Green mosaic; failed walk test |
| Firmware currency | Approved list and rollback image | Mixed versions; unknown community builds |
Tie-back: Domain 1 residual risk
Chapter 6 residual risk is what remains after selected treatments are in place and operating. Lifecycle evaluation is the operating proof. Threats move: a new neighboring occupancy, a cargo-theft crew working the industrial park, a published exploit against your NVR family. Countermeasures move too: dirty domes, obsolete panels, untrained operators on a new graphical interface. Evaluation asks a single honest question: does this treatment still match this threat at this site, as operated this quarter?
If the answer is no, you do not live with it silently. You restore PM, retrain, replace, or write residual risk back up so leadership is buying the risk with their eyes open. That loop—assess, treat, implement, maintain, evaluate—is the physical security program. Domain 3 Task 5 is how you know the loop is still closed.
The diagram is the keep-or-replace path back to residual risk. The chart compares SAT-era program health with a site that still shows every device online.
An NVR and a badge printer are being replaced. Which decommissioning package most directly reduces residual risk from the retired plant?
After a major access-control software upgrade, which training approach best keeps the countermeasure operating as designed?
Which metric set best shows whether Domain 1 residual-risk treatments still match the current threat as the system is actually operated?
You've completed this section
Continue exploring other exams