Controllers, inputs and alarms: how the system decides and reports
How access control systems are built from a server, controllers and door devices, what happens when the network fails, supervised inputs and relay outputs, the main alarm types and a sound response procedure, log review for suspicious activity (NIST SP 800-53 PE-6), ONVIF access control profiles, and hardening controllers as network devices.
- Level
- Intermediate
- Length
- About 60 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 3 Oct 2026
Skills you'll practise
- Describe what the server, controllers and door devices each do, and predict how a controller behaves when its network link fails
- Explain what a supervised input reports for normal, alarm, open-circuit and short-circuit conditions
- Identify forced-open, held-open, tamper and communication alarms and follow a response procedure that ends with root cause, not suppression
- Review access logs for the suspicious patterns NIST SP 800-53 PE-6 describes
- Apply basic hardening to controllers and servers: credentials, firmware, network segmentation, remote access and time sync
Course outline
- 1.Controllers, inputs and alarmsVideo · 2 min
- 2.Architecture, inputs and outputsLesson · 20 min
- 3.Alarms and how to respondLesson · 20 min
- 4.Controllers on the networkLesson · 18 min
- 5.Controllers, inputs and alarms: how the system decides and reports: knowledge checkKnowledge check · 18 questions
- 6.Final exam9 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- NIST SP 800-53 Rev. 5: PE-2 Physical access authorizations, PE-3 Physical access control, PE-6 Monitoring physical access, PE-8 Visitor access records, PS-4 Personnel termination, PS-5 Personnel transfer
- GSA idmanagement.gov: PACS 101 (credential readers, control panels, access control servers, cardholder data repositories; use legacy credentials only as part of a migration strategy)
- ONVIF Profile A: configuring access rules, credentials and schedules; retrieving access control events
- ONVIF Profile C: site information and configuration, event and alarm management, door access control
- ONVIF Profile D: access control peripherals (token and biometric readers, keypads, door and lock status sensors, locks, displays); complements Profiles A and C and works with Profiles M and T for integrated video and access
- CISA: Insider threat mitigation (an insider is anyone who has or had authorized access; combine physical security, personnel awareness and information-centric measures)
- General access control installation and administration practice (starter content; needs subject review)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.