6.4 ROI, Total Cost of Ownership, Privacy, PII & Life Safety
Key Takeaways
- Total cost of ownership includes purchase, install, monitoring, maintenance, power, licensing, and replacement—not camera price alone
- Simple ROI is net benefit divided by TCO; hiding operating cost inflates ROI and fails a Task 5 cost-benefit item
- ACS and VMS databases hold PII such as names, photos, PINs, biometrics, and visitor scans; a leak is a new loss-event profile
- Video does not belong where privacy is expected, including restrooms and locker rooms; notice, purpose, and retention are practitioner controls
- Fail-safe egress and alarm-released delayed egress beat merchandise lock-in; security that traps people in a fire is the wrong answer
ROI, Total Cost of Ownership, Privacy, PII, and Life Safety
A matched measure still fails Task 5 if you cannot defend money, privacy, and whether people can get out alive. Independent OpenExamPrep teaching for published PSP Domain 1 tasks is that cost-benefit is not a vendor ROI slide, and life safety is not a residual you accept in a footnote. Do not invent statute numbers. Speak in practitioner principles and in named document families—ADA, IBC/IFC, NFPA 101—then confirm the edition the authority having jurisdiction adopted, the same lookup method Chapter 2 taught.
Exam focus: Price the whole life of the measure. Protect the PII your ACS and VMS create. Never lock people into a fire.
Total Cost of Ownership, Not Purchase Price
Total cost of ownership (TCO) for a physical security measure includes more than the hardware quote:
- Purchase — cameras, panels, locks, software, credentials.
- Install — labor, conduit, lifts, after-hours premiums, patching, programming.
- Monitoring — SOC share, central-station fees, or a honest zero that means detect is not real.
- Maintenance — preventive work, repairs, calibration, cleaning, firmware.
- Power — PoE budgets, UPS, generator fuel, the electric bill nobody put on the security cost center.
- Licensing — VMS, ACS, analytics, cellular communicators, that “free” app that bills per camera in year two.
- Replacement — useful life. Cameras, NVRs, and credentials are not eternal. A five-year look that ignores a seven-year replacement still needs a reserve note.
If monitoring is $0 because “we will watch it when we can,” residual detect is still inherent. A TCO that omits monitoring is not conservative; it is incomplete.
Worked Numbers: Dock Video, Contacts, and an Attendant Procedure
Use round figures so the arithmetic is checkable. This is a teaching model for one dock pairing, not a market survey.
Assume a five-year look before planned replacement. Capital in year 0 is $20,000 for cameras, NVR, and door contacts plus $10,000 to install and program, or $30,000 capital. Annual operating cost is $5,000 for a monitoring share (SOC or central station) plus $3,000 for licenses, power, and preventive maintenance, or $8,000 per year. Five years of operating cost is $40,000. Five-year TCO is $70,000.
| Cost element | Timing | Amount | Five-year contribution |
|---|---|---|---|
| Equipment purchase | Year 0 | $20,000 | $20,000 |
| Installation and programming | Year 0 | $10,000 | $10,000 |
| Monitoring share | Annual | $5,000 | $25,000 |
| Licenses, power, preventive maintenance | Annual | $3,000 | $15,000 |
| Five-year TCO | $70,000 |
Benefit must attach to the how, not to a brochure percentage. Suppose the site’s last three years show an average $40,000 per year in dock cargo loss. The assessment argues that latching the door, staffing the attendant window, alarming the contact, and watching the apron will cut successful theft by about half because those steps break the tailgate how. That 50 percent is an assumption you document, not a law of cameras. Annual benefit is then $20,000. Five-year gross benefit is $100,000.
| Benefit and return | Amount |
|---|---|
| Three-year average annual dock cargo loss | $40,000 |
| Documented reduction assumption if the tailgate how is broken | About half → $20,000 per year |
| Five-year gross benefit | $100,000 |
| Net benefit (gross benefit minus TCO) | $30,000 |
| Simple ROI (net benefit ÷ TCO) | $30,000 ÷ $70,000 ≈ 43% |
| Simple payback (TCO ÷ annual benefit) | $70,000 ÷ $20,000 = 3.5 years |
Simple ROI here is net benefit divided by TCO. Discounting cash flows is a finance refinement; it is not a license to hide operating cost. PSP items are not CFA items. They will still punish the candidate who reports ROI against the $20,000 purchase only. That fake denominator would make the same $100,000 gross benefit look like a 400 percent “win” and is the cost-benefit trap.
If the same arithmetic produced a negative net, you would not automatically buy the package. You might scale to procedure and an attendant only, accept residual with an owner if appetite allows, or keep the spend because death/injury or a legal duty sits outside the cargo-dollar column. Negative ROI is information. It is not an order to invent a larger benefit.
Privacy and Video
People have a reasonable expectation of privacy in restrooms, locker rooms, and similar spaces. Workplace and public-area video is a different conversation: notice that recording occurs, a purpose limited to security and investigation, and retention that matches that purpose instead of “keep forever because storage is cheap.” Sector rules (healthcare, education, visitors from strict privacy regimes) can add duties. Flag counsel. The PSP candidate still must not place cameras where privacy is expected.
Audio recording, covert cameras, and views into neighboring dwellings create additional privacy risk. If the how you are treating does not need those tools, do not add them to look sophisticated.
PII in ACS and VMS Databases
Personally identifiable information (PII) in security systems commonly includes names, face images, PINs, card numbers, biometrics, visitor identity scans, license plates, and sometimes medical or escort notes. Those records live on ACS and VMS servers, on integrator laptops, and in cloud tenants. A “security” database that leaks visitor passports is a new loss-event profile you created.
Practitioner controls, without fake section cites:
- Collect the minimum that the procedure needs.
- Limit admin access; log who exported a badge photo.
- Set retention and purge visitor scans when the visit purpose ends.
- Protect the server room and the vendor remote-access path as part of the same measure.
- Encrypt and contract-limit integrator copies where the environment requires it.
- Do not use a cheap TCO cut that turns off access control on the database “because encryption licenses cost money.”
| Data | Typical system | Practitioner control |
|---|---|---|
| Face images, license plates | VMS | Purpose, retention, no intimate spaces |
| Names, photos, PINs, biometrics | ACS | Access, logging, encryption, vendor limits |
| Visitor identity scans | Visitor or ACS module | Minimize collection, purge after need |
Life-Safety Overrides: Egress, Delayed Egress, Fail-Safe, Fail-Secure
Security that traps people in a fire is the wrong answer. Adopted IBC/IFC editions, the NFPA 101 (Life Safety Code) family, and ADA accessibility constraints govern required egress. Confirm occupancy and adopted edition with the AHJ. Practitioner principles you can stand behind:
- Required exits must remain usable in fire and panic.
- Delayed egress is a tool in some occupancies when listed hardware, required signage, and automatic release on fire alarm (and often connected detection or sprinkler) are in place. A delay that ignores the alarm is not delayed egress. It is a trap.
- Fail-safe electrified hardware unlocks the protected path on loss of power. Magnetic locks on required egress commonly follow this logic so a power failure does not imprison occupants.
- Fail-secure remains locked on loss of power. That can be correct for a storeroom or for some stair conditions from the unsecured side. It is not a scheme to hold people in a burning sales floor so merchandise cannot walk out.
- Free egress from the occupied side is the default for required paths. “Lock them in for their own protection” fails exam items and real fires.
ADA constraints include operating force, hardware height, and a path a person with a disability can use. A security turnstile that is the only exit is a dual failure: life safety and accessibility.
| Hardware behavior | On power loss | Typical honest use | Exam trap |
|---|---|---|---|
| Fail-safe | Unlocks / opens the protected path | Maglocks on required egress | Calling it “weak security” and replacing it with fail-secure on that same leaf |
| Fail-secure | Stays locked | Storeroom; some electric strikes; stair from the unsecured side | Using it on a required exit so thieves cannot leave with goods |
| Delayed egress (listed) | Still must release on fire alarm | Theft-sensitive occupancies where the code family allows it | A homemade delay that does not drop on alarm |
When security preference and life safety conflict, life safety wins. Document the residual theft risk of a fail-safe maglock and treat it with detect and respond—not by disabling egress. Merchandise is replaceable. Occupants are not.
One Recommendation That Can Survive Task 5
A complete recommendation names the profile, the matched families and 4 D functions, the TCO and simple ROI (or an explicit reason you are spending despite negative ROI, such as injury duty), the PII the system will create and how long you will keep it, and the egress behavior in fire and power loss. A recommendation that lists only a camera model and a purchase price is incomplete even if the model is excellent.
Do not cite a section number you cannot defend. Naming ADA, IBC, and NFPA 101 as constraint families, then sending the reader to the adopted edition, is enough for practitioner exam work. Invented citations are a liability in a report and a wrong answer on a test.
Total cost of ownership for a video system should include which of the following?
A delayed-egress lock on a required exit that cannot be overridden when the fire alarm activates is a problem primarily because of which principle?
Storing badge photos, PINs, and visitor identity scans on an ACS or VMS server without access limits, retention limits, or encryption is primarily which failure?