PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments
Technical Controls

PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments PASONE-4: Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

Per PAS 1192-5:2015 technical clauses: implement technical security across BIM + CDE + tooling. Requirements include (a) implement Common Data Environment (CDE) Security Configuration including access control + audit + encryption + version control + integrity + (b) implement Technical Security Measures and Encryption appropriate to classification including encryption at rest + in transit + key management + (c) manage Information Aggregation Risk including aggregation that increases sensitivity + handling escalation + (d) implement Mobile and Remote Working Security including device security + secure connectivity + data handling + (e) implement BIM Tool and Software Security including supply chain risk + integrity verification + secure configuration + (f) integrate technical controls with broader information security baseline.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 229 controls across 67 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 11 controls

ISO/IEC 27043:2015 · 9 controls

  • ISO27043-11 Access control policy and enforcement
  • ISO27043-13 Authentication and password management
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification
  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management
  • ISO27043-24 Logging and monitoring

ISO/SAE 21434 · 9 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-13 Authentication and password management
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management
  • ISO21434-24 Logging and monitoring

BSI IT-Grundschutz · 7 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

ISO 27799:2025 · 7 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-05 Audit trail for ePHI access
  • ISO27799-08 Information access management
  • ISO27799-12 Unique user identification and authentication
  • ISO27799-16 Transmission security and encryption
  • ISO27799-17 Facility access controls
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-2.4 Physical Access Controls
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AWWA-4.4 Audit Logging and Monitoring

NIST SP 800-190 · 5 controls

South Korea ISMS-P · 5 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-03 Authentication Mechanisms
  • ISMSP-AC-04 Network Access Control
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-03 Security Monitoring and Log Management

ISO/IEC 23837:2023 · 4 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements
  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27011:2024 · 4 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices
  • 27011-8.3 Cryptography and key management
  • 27011-8.4 Logging and monitoring
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • OB-CX.3 Strong Customer Authentication
  • OB-DIR.1 Open Banking Directory
  • OB-SEC.2 Transport Layer Security
  • OB-SEC.4 Certificate Management

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • DIQ-1 Data Integration and Interoperability
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CJIS-16 Cloud Computing
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • CAT-D3-1 Preventative controls
  • CAT-D3-2 Detective controls
  • CAT-D4-3 Third-party access controls

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity
  • 62351-14 Cyber security event logging
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO/IEC 27010:2015 · 3 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

NIST SP 1800-32 · 3 controls

APPI · 2 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 2 controls

  • CA-ITSG33-SC-01 Security Control Catalogue
  • CA-ITSG33-SC-03 Cloud Security
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

ISO/IEC 27400:2022 · 2 controls

  • 27400-6.1 Secure Device Design
  • 27400-6.2 Device Identity and Authentication
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

OWASP SAMM · 2 controls

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • IM8-CLD.2 Cloud Security Controls
  • IM8-SEC.2 Access Control
  • AMLCTF-35 Identity Verification Standard
  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services
  • ISO-25012-4.11 Traceability

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • EHDSREG-6 Phased Application and Enforcement
  • RUSPD-2 Lawful Basis, Consent, Notice

SWIFT CSCF · 1 control

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 229 it maps to, and the evidence behind each claim, over MCP and REST.