# Privacy and Security Checklist

To help make transparency, privacy, and compliance simpler for our customers, you can use a privacy and security checklist, along with the [Privacy and Security disclosure](https://help.verkada.com/command/security/privacy-and-security-disclosure). Using this feature, you can communicate which products and features are being used in their organization.

## Access the Privacy and Security checklist

{% stepper %}
{% step %}
**In Verkada Command, go to All Products > Admin.**
{% endstep %}

{% step %}
**Under Org Settings, select Security & Access.**
{% endstep %}

{% step %}
**Select Security Checklist.**
{% endstep %}
{% endstepper %}

On the **Privacy & Security Checklist** page, you can access the list of actions (see table below) to take to ensure Verkada Command is configured at the highest level of security. Some of the items are automatically selected as complete once the task is complete.

![](https://705858581-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNRq5qDDjsYNxwNzF1bcB%2Fuploads%2Fgit-blob-203d5343f7bedc5d7e89b292d464ba0f8f050b4a%2Fec447fea80e9dd67e235773327f7f52c9c03fb27.png?alt=media)

|                                                                                                                                                                                                                         |                                                                                                                                                                                                                                                                               |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Setting**                                                                                                                                                                                                             | **Action in Command**                                                                                                                                                                                                                                                         |
| [**Enforce 2FA**](https://help.verkada.com/command/security/authentication-overview/two-factor-authentication)                                                                                                          | <p>Requires users in your organization to set up and use 2FA when logging in via a password.</p><p>Toggle on this enforcement in <strong>Admin</strong> > <strong>Privacy & Security</strong> > <strong>Authentication & User Management</strong>.</p>                        |
| **Review Session Duration**                                                                                                                                                                                             | <p>Set the amount of time a user’s session lasts before having to log in again.</p><p>Review the configured session duration in <strong>Admin</strong> > <strong>Privacy & Security</strong> > <strong>Session Timeout</strong>.</p>                                          |
| [**Set Up and Enable SSO**](https://github.com/verkada/Verkada-Support-Docs/blob/main/en/command/single-sign-on-sso/authentication-and-provisioning-overview.md)                                                        | <p>1.</p><p><a href="https://command.verkada.com/admin/privacy-security/saml">Configure SSO</a> as an authentication method for your users.</p><p><br>2.</p><p>Complete the <strong>Run Login Test</strong> step to enable it (for enhanced security, make SSO required).</p> |
| [**Set Up SCIM**](https://help.verkada.com/command/security/identity-providers/scim-token-management)                                                                                                                   | Configure SCIM to provision and manage your users and groups through Okta or Microsoft Entra ID identity management.                                                                                                                                                          |
| [**Add Primary Key Contact**](https://help.verkada.com/command/organization-settings/manage-your-admin-page-settings/manage-contacts)                                                                                   | Add a [primary contact](https://command.verkada.com/admin/org-settings/org-details) who serves as the designated point of contact for general communications.                                                                                                                 |
| [**Add Billing Key Contact**](https://help.verkada.com/command/organization-settings/manage-your-admin-page-settings/manage-contacts)                                                                                   | Add a [billing contact](https://command.verkada.com/admin/org-settings/org-details) who serves as the designated point of contact for billing-related communications.                                                                                                         |
| [**Add Security Key Contact**](https://help.verkada.com/command/organization-settings/manage-your-admin-page-settings/manage-contacts)                                                                                  | Add a [security contact](https://command.verkada.com/admin/org-settings/org-details) who serves as the designated point of contact for security-related communications.                                                                                                       |
| **Review Users**                                                                                                                                                                                                        | Ensure your [users list](https://command.verkada.com/admin/users) and user roles are up to date and remove any users if necessary.                                                                                                                                            |
| [**Review Groups**](https://help.verkada.com/command/users-and-permissions/manage-users-in-your-organization/manage-command-groups)                                                                                     | Ensure each user is added to the [group(s)](https://command.verkada.com/admin/groups) that grants the correct permissions.                                                                                                                                                    |
| [**Review Default Image and Video Data Location**](https://help.verkada.com/command/security/privacy-and-security-disclosure/set-a-default-or-camera-specific-location-for-image-and-video-data-storage-and-processing) | <p>1.</p><p>Set the default geographic region where camera video and image data will be stored.</p><p><br>2.</p><p>Review the configured location in <strong>Admin</strong> > <strong>Privacy & Security</strong> > <strong>Data Residency</strong>.</p>                      |
| **Confirm Appropriate Notice**                                                                                                                                                                                          | <p>Confirm that:</p><p>All physical sites have appropriate signage with regard to camera recordings.</p><p>The company receives appropriate consent from employees and guests.</p>                                                                                            |
| **Review People Analytics Notice**                                                                                                                                                                                      | Review and accept the Analytics Terms and Conditions, found in the **Admin > Cameras > Analytics**.                                                                                                                                                                           |
| [**Review Audit Logs**](https://help.verkada.com/command/organization-settings/manage-your-admin-page-settings/manage-and-view-audit-logs)                                                                              | Review the [logged actions](https://command.verkada.com/admin/privacy-security/audit-log) of Command users in your organization to check for irregular activity.                                                                                                              |

## Dismiss an action from the checklist

If a specific action does not pertain to your organization, you can dismiss it from the list.

Next to the action item, click the checkmark and select **Complete** or **Dismiss**. If it has a dropdown arrow next to the item name, it does not count toward your completion percentage.

![](https://705858581-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FNRq5qDDjsYNxwNzF1bcB%2Fuploads%2Fgit-blob-663c9d502482f6b1033607eb071e3ea35cc9a4ce%2Fb7be680e6b9b764e61b1b7e87e2d9f74384236ec.png?alt=media)

***

{% hint style="info" %}
**Prefer to see it in action?** Check out the [video tutorial](https://www.youtube.com/watch?v=vme3YdOdhsE).
{% endhint %}
