PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments
Triage and Classification

PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments PASONE-1: Security Triage Process, Asset Sensitivity Classification, and Threat Assessment

Per PAS 1192-5:2015 Security Triage clauses: triage + classify + assess threat. Requirements include (a) operate Security Triage Process to determine whether security-minded approach is required for a built asset + (b) apply Sensitivity Classification of Assets considering asset criticality + national infrastructure + privacy + safety implications + (c) conduct Threat Assessment covering relevant threat actors + capabilities + intent + access vectors + (d) determine security-minded approach scope across BIM information + Common Data Environment + design + construction + asset lifecycle + (e) document triage decisions + classifications + threat assessments + (f) maintain change management for triage + assessment as projects evolve.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 23 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

API 1164 · 1 control

  • API1164-02 Risk Management Framework

BSI IT-Grundschutz · 1 control

  • BSI-15 Security categorization
  • QMSR-820.45 Device labelling and packaging controls (§820.45)
  • 60601-1.7.1 Equipment identification and marking

IEC 62443 · 1 control

  • IEC62443-02 System security categorization
  • ISO-14064-1-5.4 Categorization of indirect GHG emissions

ISO/IEC 27010:2015 · 1 control

  • 27010-8.2 Membership Termination

ISO/IEC 27019:2024 · 1 control

  • ISO27019-02 System security categorization

ISO/IEC 27043:2015 · 1 control

  • ISO27043-08 Information classification and labeling

ISO/SAE 21434 · 1 control

  • ISO21434-08 Information classification and labeling

NIST SP 1800-32 · 1 control

NIST SP 800-190 · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 23 it maps to, and the evidence behind each claim, over MCP and REST.