Every camera quote arrives with a layer of vocabulary on it. Some of it is genuinely technical. Some of it is doing the job of making a decision look settled so nobody asks about it.
This is a glossary, but not a neutral one. Definitions alone are useless to a building owner. You need to know which words hide a choice made on your behalf, and what sentence to say next — so each entry is short on the definition and long on the consequence. None of it requires you to configure anything. It requires you to tell when an answer is an answer.
IP address, subnet, and DHCP versus static
Every camera has a numeric address, the way every unit in a building has a suite number. A subnet is the block of addresses that can reach each other directly — think of it as a floor; devices on different floors need something to route between them. Addresses are assigned one of two ways: DHCP hands one out automatically at power-on and can hand out a different one later, while static means the address is fixed and written down.
Why you care: a recorder finds cameras by address. If addresses can move, recordings can quietly stop — a power event, three cameras come back on different addresses, the recorder keeps running with a shortened list. Nobody notices until footage is requested.
Ask for: whether cameras are on static addresses or DHCP reservations, and for the address list in the building file. Either approach works; "we'll sort it out on site" is not an approach.
VLAN
A VLAN is a way of splitting one physical network into separate logical networks. Same cables, same switches, but the camera traffic and the office traffic behave as if they were on different systems that cannot see each other.
Why you care: this is the most consequential item in this glossary. Cameras are appliances running software you do not patch and rarely think about. If they sit on the same flat network as your accounting workstation, your point-of-sale terminal or a tenant's laptop, anything that goes wrong on one side has a path to the other. Separating them costs nothing extra at install and is disruptive to retrofit later.
The related item is internet exposure. A camera does not need to be reachable from the public internet for you to view it remotely. The US Cybersecurity and Infrastructure Security Agency's exposure-reduction guidance puts the general point bluntly: "misconfigured systems, default credentials, and outdated software are often publicly accessible through internet-based search and discovery platforms." Its instruction is to determine which assets actually need to be internet-accessible and restrict the rest. Cameras are the textbook example of a device that almost never needs to be on that list.
Ask for: "Are the cameras on their own VLAN, separated from the business network?" and "Is anything here reachable from the public internet, and if so, what?" Both answers should be immediate and specific.
PoE and PoE+
Power over Ethernet sends power and data down the same cable, so a camera needs one run rather than a network cable plus an electrician's circuit. PoE+ is the higher-power tier, needed by some cameras with heaters, motorized zoom, pan-tilt movement or strong infrared illuminators.
Why you care: power budget is where installations get quietly under-specified. A switch has a total power budget shared across all its ports, and filling every port with higher-tier cameras can exceed what it delivers. The symptom is not a clean failure — it is cameras rebooting intermittently, usually the ones running heaters, usually in the cold, which is precisely when you wanted them.
Ask for: the power draw per camera model, the switch's total budget, and the arithmetic showing the second comfortably exceeds the sum of the first. Someone who has done this will produce it without pausing.
Switch, injector, port and uplink
A switch is the box cameras plug into; it moves traffic and, on a PoE switch, supplies power. An injector is a single-device adapter that adds power to one cable. A port is one socket on a switch. The uplink is the connection carrying traffic from that switch onward, to another switch or to wherever the recorder lives.
Why you care, on injectors: they are a legitimate tool for one awkward camera far from everything else, and a warning sign when they are the design. A row of injectors on a shelf means no central power budget and small power supplies failing one at a time in places nobody looks.
Why you care, on uplinks: individual camera ports are rarely the constraint. The uplink is, because every camera on that switch shares it. An undersized uplink produces a system that works perfectly at commissioning, when one person checks one camera at a time, and degrades when several streams are pulled at once — which is the day of the incident.
Ask for: a single-line drawing showing which cameras land on which switch and port, plus each uplink speed with a plain statement that it exceeds the combined stream rate behind it. If "where does this camera connect" requires someone to go and look, you do not have documentation.
Bitrate, and bandwidth versus storage
Bitrate is how much data a camera produces per second, and it is the master variable here because it drives two things at once. Bandwidth is how much of your network that data occupies in transit; storage is how much disk it consumes once it lands. Bandwidth is an instantaneous problem, storage a cumulative one. Double the bitrate and you double both — twice the network to carry it, half the time to fill the disks.
Why you care: "retention" is the word that matters to you, and it is not a setting somebody types in. It is the arithmetic result of bitrate, camera count and disk capacity, so a promised retention period is a claim about all three. Raise image quality after handover, or add cameras, and retention falls silently. Nothing announces it.
We are not printing sample numbers, because a number attached to somebody else's scene is worse than none: a camera watching a still corridor and one watching a windy parking lot produce very different data from identical settings.
Ask for: the retention period in writing, the bitrate assumption behind it, what happens to retention if a camera is added later, and how you would notice if it had drifted.
CBR versus VBR
Constant bitrate means the camera produces the same data rate regardless of what it sees. Variable bitrate means it produces less when the scene is still and more when it is busy.
Why you care: this is a genuine trade-off, not a right answer. Constant bitrate makes retention calculable, at the cost of spending data on empty scenes and capping quality during the busy moments you care about. Variable bitrate puts the data where the detail is, but makes retention a forecast rather than a calculation. Many systems run variable with a ceiling, which is the sensible middle. The thing to avoid is not knowing which you are on.
Ask for: which mode each camera runs, and if variable, the ceiling and whether quoted retention was calculated at the average or at the ceiling. Calculated at the average, your retention is shortest during your busiest periods.
H.264 versus H.265
These are compression methods — the maths that turns what the sensor sees into a manageable stream. H.265 is the newer one and generally produces a similar-looking image for less data than H.264.
Why you care: less data means either longer retention on the same disks or better image quality for the same retention. The catch is compatibility — camera, recorder, viewing software and any system you later export to all have to understand it. Vendors also ship proprietary variants under their own marketing names, and those are the ones most likely to strand you when you change one component.
Ask for: the compression method by its standard name, confirmation the recorder and viewing software support it, and an explicit answer on whether any camera is using a manufacturer-specific variant.
RTSP
RTSP is the common protocol for pulling a live stream from a camera — how a recorder or third-party system asks for the feed.
Why you care: it is a practical escape hatch. If a camera can hand its stream to something other than its manufacturer's own recorder, you have options when that recorder dies or that software moves to a subscription you dislike. If it cannot, you are buying a closed set.
Ask for: confirmation that cameras expose a standard stream a third-party system can consume, and that the credentials are documented and held by you — not only by the installer.
ONVIF
ONVIF is the interoperability framework for video and access-control devices. It is not one thing a device either complies with or does not: it is a set of profiles identified by letters, and a device conforms to specific ones. ONVIF states that video systems use profiles D, G, M, S and T, and access control uses A, C, D and M.
Why you care: "ONVIF compliant" with no letter attached tells you nothing. A device conforming to a profile your recorder does not use is, for your purposes, a device that does not interoperate. There is a history lesson attached too. ONVIF deprecated Profile Q on 1 April 2022, in its own words, "because its specification requires a Profile Q conformant device to allow anonymous access to all ONVIF commands during the setup process in the factory default state. This does not follow current cybersecurity best practices." A convenience feature meant to make installation painless became the reason the profile was retired.
Ask for: the specific profile letters on both sides of the connection — cameras and recorder. And treat "every default credential is changed at commissioning" as a written line item, not a courtesy.
NVR, VMS, and where recording lives
An NVR is a box that records the cameras. A VMS is software doing the same job on a server, and cloud services do it off-site. What matters is not the acronym but where recording physically happens and who can reach it.
Why you care: this determines what survives a bad day — a recorder in an unlocked cupboard beside the front door records faithfully until someone takes it. It also sets your exit costs, since footage locked inside a proprietary appliance can be awkward to export in a form anyone else will accept.
Ask for: where the recorder sits and how it is secured, how footage is exported and in what format, and who holds the administrator credentials.
Latency, and multicast versus unicast
Latency is the delay between something happening and it appearing on screen. It matters for live monitoring and anything where a person watches in order to act — an intercom, a gate, a door release — and much less for recorded review. It is also a fair diagnostic of network health: a system that used to be responsive and now lags is telling you something changed. Ask for the live-view delay measured at handover, so you hold a baseline.
Unicast means the camera sends a separate copy of its stream to each viewer; multicast means it sends one copy that viewers share. With a few cameras and one viewer this never comes up. It matters when many people view many cameras at once, because under unicast the load grows with viewers multiplied by cameras — and the uplink is where it lands. If you expect simultaneous viewers, ask before purchase how the design handles it.
What this glossary is really for
You are not being asked to design a network. You are being asked to notice when a word is standing in for a decision.
The pattern repeats across every entry above. There is a number nobody calculated — power budget, uplink capacity, retention. There is a separation nobody made — VLAN, internet exposure. There is a claim with no content in it — "ONVIF compliant," "supports remote viewing." These are the ordinary result of a system being installed rather than designed, and every one is visible from a question you can now ask in a sentence.
If the answers come easily, you are dealing with someone who works this way as a matter of course. If they get vague around VLANs, retention arithmetic or profile letters, you have learned something more useful than any definition on this page.
