Per PAS 1192-5:2015 Security Triage clauses: triage + classify + assess threat. Requirements include (a) operate Security Triage Process to determine whether security-minded approach is required for a built asset + (b) apply Sensitivity Classification of Assets considering asset criticality + national infrastructure + privacy + safety implications + (c) conduct Threat Assessment covering relevant threat actors + capabilities + intent + access vectors + (d) determine security-minded approach scope across BIM information + Common Data Environment + design + construction + asset lifecycle + (e) document triage decisions + classifications + threat assessments + (f) maintain change management for triage + assessment as projects evolve.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.