PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments
Personnel Security

PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments PASONE-3: Personnel Security, Vetting, Awareness, and Training

Per PAS 1192-5:2015 personnel clauses: implement personnel security + awareness. Requirements include (a) implement Personnel Security and Vetting appropriate to sensitivity of information accessed including pre-engagement screening + ongoing review + role-based access + (b) deliver Awareness and Training including security-minded approach + BIM-specific risks + information handling + incident reporting + (c) maintain role-based training including BASM + project teams + supply chain + (d) implement leaver procedures including access revocation + information return + (e) maintain confidentiality undertakings + non-disclosure agreements + (f) measure awareness + training effectiveness.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 98 controls across 46 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • AEO-5 Premises Security
  • P2-S1 Partnership
  • CPG-1.C Unique Credentials
  • CPG-4.C Basic Cybersecurity Training
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • ISO28001-PC-03 Supply Chain Incident Reporting
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO28001-PI-01 Personnel Security Screening
  • ISO28001-PI-02 Security Awareness and Training

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • CJIS-19 Supply Chain Risk Management
  • CJIS-2 Security Awareness Training
  • CJIS-3 Personnel Security

IEC 62443 · 3 controls

  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures
  • ISO-20400-7.3 Supplier selection
  • ISO-20400-7.4 Contract management and review
  • ISO-20400-7.5 Reviewing and learning

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 1800-32 · 3 controls

  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-6.8 Externally provided products and services

ISO 27799:2025 · 2 controls

  • ISO27799-07 Workforce security and clearance procedures
  • ISO27799-09 Security awareness and training program

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-4.2 Understanding the needs and expectations of interested parties
  • ISO27003-8.1 Operational planning and control

ISO/IEC 27010:2015 · 2 controls

  • 27010-15.1 Incident Management
  • 27010-7.1 Information Classification for Sharing

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.6 Supplier relationships and telecom supply chain
  • 27011-6.3 Awareness and Training
  • GT-3 Supply Chain Compromise
  • GT-4 Social Engineering Attacks
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • ASD37-37 Personnel management (Very Good)
  • ACQS-7-3 Worker Screening
  • Clause 3 Suppliers and service providers
  • ACQ.4 Supplier Monitoring
  • Mat 03 Responsible Sourcing of Materials
  • CAT-D1-4 Training and culture
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment

ISO 22316 · 1 control

  • ISO22316-14 Supply chain continuity

ISO 26000:2010 · 1 control

  • ISO-26000-6.6 Fair operating practices
  • ISO-41001-8.4 Control of outsourced processes and services
  • ISO-50001-8.3 Procurement

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.6 AI System Security

ISO/TS 22317:2021 · 1 control

  • ISO22317-14 Supply chain continuity

ISO/TS 22318:2021 · 1 control

  • ISO22318-14 Supply chain continuity
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • 2.7.2 Food Fraud Plan
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 1 control

  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 98 it maps to, and the evidence behind each claim, over MCP and REST.