{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/make-edge-storage-encryption-recoverable-before-enabling-it/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/",
        "slug": "make-edge-storage-encryption-recoverable-before-enabling-it",
        "url": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/make-edge-storage-encryption-recoverable-before-enabling-it/"
        },
        "title": "Make edge-storage encryption recoverable before enabling it",
        "summary": "Encrypting a camera card can protect removed media, but initialization and recovery actions can erase recordings. Establish passphrase custody and recovery tests first.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "video-surveillance",
                "name": "Video Surveillance",
                "url": "https://update.dsesecurity.com/topic/video-surveillance/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:35:55+00:00",
        "modified_at": "2026-08-25T21:36:17+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 2,
        "word_count": 437,
        "potentially_affected": "Axis cameras using encrypted SD-card storage for primary, distributed, or failover recording.",
        "dse_recommendation": "Before enabling encryption, approve key custody, preserve any required footage, test supported recovery on non-evidence media, and document destructive format or decrypt steps.",
        "primary_source": {
            "name": "AXIS OS Web Interface Help - LTS 2026",
            "url": "https://help.axis.com/en-us/axis-os-web-interface-help-lts-2026",
            "published_on": null,
            "authority": "Axis Communications"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> storage encryption can reduce disclosure from removed media, but a lost passphrase or misunderstood format/decrypt action can make authorized recovery impossible or erase the recording. Design recovery before changing the card.</p>\n<h2>Source fact: encryption and decryption workflows can format storage</h2>\n<p>The <a href=\"https://help.axis.com/en-us/axis-os-web-interface-help-lts-2026\" target=\"_blank\" rel=\"noopener noreferrer\">AXIS OS Web Interface Help for LTS 2026</a> documents encrypted SD-card controls. It states that encrypting a card formats and erases it and that decrypting it also formats and erases it. The interface documentation distinguishes changing the encryption password from those destructive operations. Related Axis guidance states that the original passphrase is required for supported reuse or decryption scenarios.</p>\n<p>The safe sequence is therefore evidence first, configuration second. A technician should never discover the destructive effect while handling the only copy of relevant video.</p>\n<h2>Source boundary and applicability</h2>\n<p>The help applies to supported Axis products and software. Exact controls, recovery tools, passphrase behavior, and compatibility can differ by release and card state. Encryption does not by itself secure camera credentials, live streams, recorder copies, exports, backups, or authorized misuse. Organizational key-management and evidence rules remain necessary.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>What threat is encryption addressing: theft, removed media, service handling, or disposal?</li>\n<li>Is the card the only copy, failover copy, or a synchronized recording?</li>\n<li>Who creates, stores, retrieves, rotates, and audits the passphrase?</li>\n<li>Can recovery occur if the camera fails and the card must be handled elsewhere?</li>\n<li>Which actions format or erase the media on the deployed AXIS OS version?</li>\n</ul>\n<h2>DSE recommendation: use a two-person encryption runbook</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<p>Inventory the exact camera, firmware, card, purpose, and existing footage. Place any required recording under the appropriate hold or export workflow before initialization. Generate and escrow the passphrase in an approved secrets system with role separation, recovery access, and audit logging. Do not place it in a ticket, camera name, drawing, or unsecured installer note.</p>\n<p>Rehearse enablement, authorized access, password change, camera replacement, and recovery using disposable test media and the supported tools. Mark every destructive step explicitly and require confirmation of card identity and evidence status. Define what occurs if the secret is unavailable or a device fails.</p>\n<p>Set a recurring escrow-recovery check that proves an authorized alternate can retrieve the correct secret without displaying it to the tester or altering production media.</p>\n<h2>Verification and evidence</h2>\n<p>Retain the approved threat decision, device/card inventory, non-evidence test record, screenshots or exports that avoid secret disclosure, escrow-access test, role review, before-and-after recording check, and change ticket. Never attach the passphrase to the evidence package or verification artifact.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://help.axis.com/en-us/axis-os-web-interface-help-lts-2026\" target=\"_blank\" rel=\"noopener noreferrer\">AXIS OS Web Interface Help &#8211; LTS 2026</a> &#8211; Axis Communications</li>\n</ul>",
        "content_text": "Bottom line: storage encryption can reduce disclosure from removed media, but a lost passphrase or misunderstood format/decrypt action can make authorized recovery impossible or erase the recording. Design recovery before changing the card.\nSource fact: encryption and decryption workflows can format storage\nThe AXIS OS Web Interface Help for LTS 2026 documents encrypted SD-card controls. It states that encrypting a card formats and erases it and that decrypting it also formats and erases it. The interface documentation distinguishes changing the encryption password from those destructive operations. Related Axis guidance states that the original passphrase is required for supported reuse or decryption scenarios.\nThe safe sequence is therefore evidence first, configuration second. A technician should never discover the destructive effect while handling the only copy of relevant video.\nSource boundary and applicability\nThe help applies to supported Axis products and software. Exact controls, recovery tools, passphrase behavior, and compatibility can differ by release and card state. Encryption does not by itself secure camera credentials, live streams, recorder copies, exports, backups, or authorized misuse. Organizational key-management and evidence rules remain necessary.\nApplicability questions\n\nWhat threat is encryption addressing: theft, removed media, service handling, or disposal?\nIs the card the only copy, failover copy, or a synchronized recording?\nWho creates, stores, retrieves, rotates, and audits the passphrase?\nCan recovery occur if the camera fails and the card must be handled elsewhere?\nWhich actions format or erase the media on the deployed AXIS OS version?\n\nDSE recommendation: use a two-person encryption runbook\nThe following steps are DSE recommendations based on the cited source.\nInventory the exact camera, firmware, card, purpose, and existing footage. Place any required recording under the appropriate hold or export workflow before initialization. Generate and escrow the passphrase in an approved secrets system with role separation, recovery access, and audit logging. Do not place it in a ticket, camera name, drawing, or unsecured installer note.\nRehearse enablement, authorized access, password change, camera replacement, and recovery using disposable test media and the supported tools. Mark every destructive step explicitly and require confirmation of card identity and evidence status. Define what occurs if the secret is unavailable or a device fails.\nSet a recurring escrow-recovery check that proves an authorized alternate can retrieve the correct secret without displaying it to the tester or altering production media.\nVerification and evidence\nRetain the approved threat decision, device/card inventory, non-evidence test record, screenshots or exports that avoid secret disclosure, escrow-access test, role review, before-and-after recording check, and change ticket. Never attach the passphrase to the evidence package or verification artifact.\nOfficial references\n\nAXIS OS Web Interface Help – LTS 2026 – Axis Communications",
        "content_markdown": "Bottom line: storage encryption can reduce disclosure from removed media, but a lost passphrase or misunderstood format/decrypt action can make authorized recovery impossible or erase the recording. Design recovery before changing the card.\n\n## Source fact: encryption and decryption workflows can format storage\n\nThe [AXIS OS Web Interface Help for LTS 2026](https://help.axis.com/en-us/axis-os-web-interface-help-lts-2026) documents encrypted SD-card controls. It states that encrypting a card formats and erases it and that decrypting it also formats and erases it. The interface documentation distinguishes changing the encryption password from those destructive operations. Related Axis guidance states that the original passphrase is required for supported reuse or decryption scenarios.\n\nThe safe sequence is therefore evidence first, configuration second. A technician should never discover the destructive effect while handling the only copy of relevant video.\n\n## Source boundary and applicability\n\nThe help applies to supported Axis products and software. Exact controls, recovery tools, passphrase behavior, and compatibility can differ by release and card state. Encryption does not by itself secure camera credentials, live streams, recorder copies, exports, backups, or authorized misuse. Organizational key-management and evidence rules remain necessary.\n\n## Applicability questions\n\n- What threat is encryption addressing: theft, removed media, service handling, or disposal?\n\n- Is the card the only copy, failover copy, or a synchronized recording?\n\n- Who creates, stores, retrieves, rotates, and audits the passphrase?\n\n- Can recovery occur if the camera fails and the card must be handled elsewhere?\n\n- Which actions format or erase the media on the deployed AXIS OS version?\n\n## DSE recommendation: use a two-person encryption runbook\n\nThe following steps are DSE recommendations based on the cited source.\n\nInventory the exact camera, firmware, card, purpose, and existing footage. Place any required recording under the appropriate hold or export workflow before initialization. Generate and escrow the passphrase in an approved secrets system with role separation, recovery access, and audit logging. Do not place it in a ticket, camera name, drawing, or unsecured installer note.\n\nRehearse enablement, authorized access, password change, camera replacement, and recovery using disposable test media and the supported tools. Mark every destructive step explicitly and require confirmation of card identity and evidence status. Define what occurs if the secret is unavailable or a device fails.\n\nSet a recurring escrow-recovery check that proves an authorized alternate can retrieve the correct secret without displaying it to the tester or altering production media.\n\n## Verification and evidence\n\nRetain the approved threat decision, device/card inventory, non-evidence test record, screenshots or exports that avoid secret disclosure, escrow-access test, role review, before-and-after recording check, and change ticket. Never attach the passphrase to the evidence package or verification artifact.\n\n## Official references\n\n- [AXIS OS Web Interface Help – LTS 2026](https://help.axis.com/en-us/axis-os-web-interface-help-lts-2026) – Axis Communications"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/",
                "url": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Make edge-storage encryption recoverable before enabling it",
                        "item": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/#article",
                "identifier": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/",
                "url": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/",
                "headline": "Make edge-storage encryption recoverable before enabling it",
                "description": "Encrypting a camera card can protect removed media, but initialization and recovery actions can erase recordings. Establish passphrase custody and…",
                "abstract": "Encrypting a camera card can protect removed media, but initialization and recovery actions can erase recordings. Establish passphrase custody and recovery tests first.",
                "articleBody": "Bottom line: storage encryption can reduce disclosure from removed media, but a lost passphrase or misunderstood format/decrypt action can make authorized recovery impossible or erase the recording. Design recovery before changing the card.\nSource fact: encryption and decryption workflows can format storage\nThe AXIS OS Web Interface Help for LTS 2026 documents encrypted SD-card controls. It states that encrypting a card formats and erases it and that decrypting it also formats and erases it. The interface documentation distinguishes changing the encryption password from those destructive operations. Related Axis guidance states that the original passphrase is required for supported reuse or decryption scenarios.\nThe safe sequence is therefore evidence first, configuration second. A technician should never discover the destructive effect while handling the only copy of relevant video.\nSource boundary and applicability\nThe help applies to supported Axis products and software. Exact controls, recovery tools, passphrase behavior, and compatibility can differ by release and card state. Encryption does not by itself secure camera credentials, live streams, recorder copies, exports, backups, or authorized misuse. Organizational key-management and evidence rules remain necessary.\nApplicability questions\n\nWhat threat is encryption addressing: theft, removed media, service handling, or disposal?\nIs the card the only copy, failover copy, or a synchronized recording?\nWho creates, stores, retrieves, rotates, and audits the passphrase?\nCan recovery occur if the camera fails and the card must be handled elsewhere?\nWhich actions format or erase the media on the deployed AXIS OS version?\n\nDSE recommendation: use a two-person encryption runbook\nThe following steps are DSE recommendations based on the cited source.\nInventory the exact camera, firmware, card, purpose, and existing footage. Place any required recording under the appropriate hold or export workflow before initialization. Generate and escrow the passphrase in an approved secrets system with role separation, recovery access, and audit logging. Do not place it in a ticket, camera name, drawing, or unsecured installer note.\nRehearse enablement, authorized access, password change, camera replacement, and recovery using disposable test media and the supported tools. Mark every destructive step explicitly and require confirmation of card identity and evidence status. Define what occurs if the secret is unavailable or a device fails.\nSet a recurring escrow-recovery check that proves an authorized alternate can retrieve the correct secret without displaying it to the tester or altering production media.\nVerification and evidence\nRetain the approved threat decision, device/card inventory, non-evidence test record, screenshots or exports that avoid secret disclosure, escrow-access test, role review, before-and-after recording check, and change ticket. Never attach the passphrase to the evidence package or verification artifact.\nOfficial references\n\nAXIS OS Web Interface Help – LTS 2026 – Axis Communications",
                "datePublished": "2026-08-25T21:35:55+00:00",
                "dateModified": "2026-08-25T21:36:17+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/make-edge-storage-encryption-recoverable-before-enabling-it/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Make edge-storage encryption recoverable before enabling it"
                },
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity",
                    "Video Surveillance"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "Video Surveillance",
                    "Playbook",
                    "Important priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Video Surveillance",
                        "url": "https://update.dsesecurity.com/topic/video-surveillance/"
                    }
                ],
                "wordCount": 437,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "AXIS OS Web Interface Help - LTS 2026",
                    "url": "https://help.axis.com/en-us/axis-os-web-interface-help-lts-2026"
                }
            }
        ]
    }
}