Dahua’s cybersecurity approach

CCTV Handbook 2021 Information Security

In the AIoT era, the world is getting smarter. Everything is going to have an online ID and then connect into a vast network of IoT devices, like a laptop computer, a mobile phone, a connected thermostat or a network security camera.

Cybersecurity to watch in the AIoT era

According to a Marketsandmarkets report, IoT devices are extensively used by smart cars, smart manufacturing, connected homes and building automation solutions. However, there are currently no unified global technical standards for IoT, especially in terms of communications. This results in inefficient

data management and reduced interoperability and ultimately may cause reduced security in the IoT network. The global IoT security market is expected to grow from USD 12,5 billion in 2020 to USD 36,6 billion by 2025, at a compound annual growth rate (CAGR) of 23,9%.

Dahua Technology believes cybersecurity is of vital strategic importance in the age of AIoT. In various vertical industries, such as traffic, banking and finance, healthcare and critical infrastructure, organisations collect, process and store unprecedented amounts of data on devices like IP cameras and NVRs. A significant portion of that data can be sensitive or private information, which can be prone to cyber-attacks and the situation is getting worse. As a security solution provider, Dahua Technology continuously invests in cybersecurity and actively addresses network security issues.

Continuous investment

Committed to becoming a leader in cybersecurity and privacy protection in the global security industry, Dahua Technology has been developing cybersecurity for nearly 10 years. The company keeps investing about 10% of its annual sales revenue in R&D; every year, including cybersecurity. In addition, the company put together a professional team of nearly 100 people to focus on cybersecurity issues. With rich experience and sufficient resources, Dahua Technology promises to be positive, open, cooperative and responsible when it comes to cybersecurity.

Breaking down Dahua’s approach

Organisational structure

In order to achieve better efficiency and effectivity, Dahua operates a comprehensive system to cope with all cybersecurity-related issues. The system, led by a cybersecurity committee, also contains a cybersecurity and data protection compliance group, a cybersecurity institute and a Product Security Incident Response Team (PSIRT). The cybersecurity committee, above all departments or teams, can call on resources from the whole company, from the R&D; centre, to the legal department, supply chain, overseas business department, etc. when necessary. The cybersecurity institute is in charge of building sSDLC (secure software development lifecycle) processes and implementing them in all Dahua products.

Security development lifecycle

Dahua adopts a bunch of professional sSDLC security applications to improve product security. During the security design phase, STRIDE + Attack Tree + PIA are adapted to improve threat modelling. During the security realisation phase, OWASP (Open Web Application Security Project) top 10 and over 150 CWEs (Common Weakness Enumeration) are used to achieve static code analysis. During the security test phase, over 20 tools within seven fields are applied to complete multiple security testing processes. CompTIA PenTest+/Security+ are used to carry out professional penetration testing, while compliance to ISO 30111, ISO 290147 and MITRE are followed during vulnerability management after the products are sold.

Emergency response system

Cooperation with professionals from across the globe is a great way to improve vulnerability detection. Therefore, the Dahua Cybersecurity Centre (DHCC) was established to solve cybersecurity issues with security vulnerability reporting, announcement/notice and cybersecurity knowledge sharing with its global customer base in order to provide them with more robust and secure products and solutions.

The PSIRT is an integral part of the DHCC. Composed of professionals ranging from marketing, supply chain, service and legal representatives, PSIRT is responsible for receiving, processing and disclosing Dahua product and solution-related security vulnerabilities. Team members are on duty seven days a week and guarantee to respond to an emergency within 48 hours. End users, partners, suppliers, government agencies, industry association and independent researchers are encouraged to report potential risks or vulnerabilities to PSIRT at cybersecurity@dahuatech.com.

Personal data and privacy protection

Dahua also attaches great importance to personal data and privacy protection. Complying with applicable laws and regulations such as the EU’s General Data Protection Regulation (GDPR), the European Data Protection Board’s (EDPB) ETSI EN 303645 as well as the California Consumer Privacy Act, the company established the Personal Data & Privacy Protection Standard.

The standard stipulates that privacy protection methods such as de-identification, data encryption and systematic access control, privacy-friendly settings are fully adapted to the complete data life cycle all the way from collection, transmitting and storage, to sharing, copying and deleting. In addition, working with third-party institutions, Dahua has received the Protected Privacy IoT Product Certification and ETSI Certification from TÜV Rheinland, as well as an ISO 27018 Certification and ISO 27701 Certification from the BSI, which demonstrates its capability in managing personal information and compliance in line with privacy regulations around the world.

Continuously iterating security baseline

Centred on the core principles of security by design and security by default, the Dahua security baseline initiative taps into product safety technology to provide users with adequate safety guarantees. The security baseline builds a security element layout of ‘AAA+CIA+P’, forming a systematic protection framework covering physical security, system security, application security, data security, network security and privacy protection. Seven versions of the baseline and 100+ principles have been developed to adapt authentication, authorisation, audit, confidentiality, integrity, availability and privacy protection deeply into its product quality assurance system, making sure that all Dahua products enjoy factory default security.

Product security centre

In order to help users clearly understand the security status and capabilities of devices, the product security centre assists users to quickly set up the right security configuration to suit their requirements. General security capabilities include privacy protection (face occlusion, information hiding etc.), video encryption, security alarm, trusted protection, CA certification management, key management services, attack defence and so on.

Cybersecurity ecosystem

Adhering to openness and cooperation, Dahua Technology keeps cooperating with international authoritative security institutions to jointly build a security ecosystem. Through in-depth communicating and cooperating with institutions like TÜV Rheinland, BSI, DNV·GL, Intertek EWA-Canada and brightsight security lab, the company stays ahead of the curve in its security capabilities and systems.

In a widely networked world of IoT, cybersecurity challenges are pretty much a universal sore spot for companies. Dahua Technology, in the business of keeping people safe, takes cybersecurity seriously. With a mindset that emphasises cybersecurity and all the resources that it can allocate to establish, carry out and strengthen its cybersecurity approach, Dahua plans to stay positive, open, responsible and improving in all aspects of cybersecurity.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Africa’s largest Zero Trust platform
NEC XON Information Security Commercial (Industry)
Africa has reached a significant cybersecurity milestone with the successful deployment of the continent’s largest Palo Alto Networks Prisma Access and Prisma Access Browser Zero Trust environment, supporting secure remote access for more than 40 000 users for a large enterprise in Africa.

Read more...
Supply chain attacks top threat over 12 months
Information Security
Supply chain attacks have become the most prevalent cyberthreat confronting businesses over the past year, according to a new Kaspersky global study, with nearly one-third of companies worldwide experiencing a supply chain threat in the past year.

Read more...
From vibe hacking to flat-pack malware
Information Security AI & Data Analytics
HP issued its latest Threat Insights Report, with strong indications that attackers are using AI to scale and accelerate campaigns, and that many are prioritising cost, effort, and efficiency over quality.

Read more...
NEC XON secures mobile provider’s hybrid identities
NEC XON Access Control & Identity Management Information Security Commercial (Industry)
For a leading South African telecommunications operator, identity protection has become a strategic priority as identity-centric attacks proliferate across the industry. The company faced mounting pressure to secure both human and non-human identities across complex hybrid environments.

Read more...
Microsoft 365 security is a ticking time bomb
Information Security
Across boardrooms and IT departments, a dangerous assumption persists that because data is stored in Microsoft 365 and Azure, it is automatically secure. This belief is fundamentally flawed and fosters a false sense of protection.

Read more...
Rise in malicious insider threat reports
News & Events Information Security
Mimecast Study finds 46% of SA organisations report a rise in malicious insider threat reports over the past year: reveals disconnect between security awareness and technical controls as AI-powered attacks accelerate.

Read more...
New campaign exploiting Google Tasks notifications
News & Events Information Security
New phishing scheme abuses legitimate Google Tasks notifications to trick corporate users into revealing corporate login credentials, which can then be used to gain unauthorised access to company systems, steal data, or launch further attacks.

Read more...
Making a mesh for security
Information Security Security Services & Risk Management
Credential-based attacks have reached epidemic levels. For African CISOs in particular, the message is clear: identity is now the perimeter, and defences must reflect that reality with coherence and context.

Read more...
What’s in store for PAM and IAM?
Access Control & Identity Management Information Security
Leostream predicts changes in Identity and Access Management (IAM) and Privileged Access Management (PAM) in the coming year, driven by evolving cybersecurity realities, hybridisation, AI, and more.

Read more...
The challenges of cybersecurity in access control
Technews Publishing SMART Security Solutions Access Control & Identity Management Information Security
SMART Security Solutions summarises the key points dealing with modern cyber risks facing access control systems, from Mercury Security’s white paper “Meeting the Challenges of Cybersecurity in Access Control: A Future-Ready Approach.”

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.