Frameworks / PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments / PASONE-4 PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments
Technical Controls
PAS 1192-5:2015 - Security-Minded Approach to BIM and Digital Built Environments PASONE-4: Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working Per PAS 1192-5:2015 technical clauses: implement technical security across BIM + CDE + tooling. Requirements include (a) implement Common Data Environment (CDE) Security Configuration including access control + audit + encryption + version control + integrity + (b) implement Technical Security Measures and Encryption appropriate to classification including encryption at rest + in transit + key management + (c) manage Information Aggregation Risk including aggregation that increases sensitivity + handling escalation + (d) implement Mobile and Remote Working Security including device security + secure connectivity + data handling + (e) implement BIM Tool and Software Security including supply chain risk + integrity verification + secure configuration + (f) integrate technical controls with broader information security baseline.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 229 controls across 67 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ISO27043-11 Access control policy and enforcement ISO27043-13 Authentication and password management ISO27043-14 Privileged access management ISO27043-15 Access review and recertification ISO27043-17 Encryption of data at rest ISO27043-18 Encryption of data in transit ISO27043-19 Certificate management ISO27043-20 Key lifecycle management ISO27043-24 Logging and monitoring ISO21434-12 User access management and provisioning ISO21434-13 Authentication and password management ISO21434-14 Privileged access management ISO21434-15 Access review and recertification ISO21434-16 Cryptographic policy and key management ISO21434-17 Encryption of data at rest ISO21434-18 Encryption of data in transit ISO21434-19 Certificate management ISO21434-24 Logging and monitoring BSI-03 Multi-factor authentication requirements BSI-04 Remote access controls BSI-05 Wireless access restrictions BSI-08 Cryptographic protection of data BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention ISO27799-01 ePHI access controls and authorization ISO27799-02 ePHI encryption at rest and in transit ISO27799-05 Audit trail for ePHI access ISO27799-08 Information access management ISO27799-12 Unique user identification and authentication ISO27799-16 Transmission security and encryption ISO27799-17 Facility access controls AWWA-2.1 User Access Management AWWA-2.2 Authentication Mechanisms AWWA-2.4 Physical Access Controls AWWA-3.2 Remote Access Security AWWA-3.4 Encryption and Data Protection AWWA-4.4 Audit Logging and Monitoring ISMSP-AC-01 Access Control Policy ISMSP-AC-03 Authentication Mechanisms ISMSP-AC-04 Network Access Control ISMSP-SYS-02 Encryption Implementation ISMSP-SYS-03 Security Monitoring and Log Management 23837-1.2 Normative references 23837-1.5.2 Cryptographic module requirements 23837-1.5.3 Network device testing requirements 23837-1.7.3 Authentication and classical post-processing 27011-5.3 Segregation of duties 27011-8.1 User Endpoint Devices 27011-8.3 Cryptography and key management 27011-8.4 Logging and monitoring 29115-11 Mapping other authentication schemes 29115-12.1 Exchanging authentication results 29115-12.2 Controls for mitigating threats 29115-7.4 Level of Assurance 4 (LoA4) OB-CX.3 Strong Customer Authentication OB-DIR.1 Open Banking Directory OB-SEC.2 Transport Layer Security OB-SEC.4 Certificate Management API1164-06 Access Control API1164-07 Remote Access API1164-09 Patch and Vulnerability Management ASD37-17 TLS encryption between email servers (Limited) ASD37-20 Multi-factor authentication (Essential) ASD37-23 Protect authentication credentials (Excellent) DIQ-1 Data Integration and Interoperability DSO-2 Data Security DSO-3 Data Access Management CJIS-16 Cloud Computing CJIS-8 Media Protection CJIS-9 System and Communications Protection CAT-D3-1 Preventative controls CAT-D3-2 Detective controls CAT-D4-3 Third-party access controls FEDRAMP-SC-13 Cryptographic Protection FEDRAMP-SC-28 Protection of Information at Rest FEDRAMP-SC-8 Transmission Confidentiality and Integrity 62351-14 Cyber security event logging 62351-8 Role-based access control (RBAC) 62351-9 Cyber security key management IEC62443-07 Personnel risk assessment IEC62443-08 Electronic access perimeter management IEC62443-10 Revocation of access procedures 27010-10.1 Cryptographic Protection 27010-9.1 Access Control to Shared Information 27010-9.2 Authentication of Sources ISO27019-07 Personnel risk assessment ISO27019-08 Electronic access perimeter management ISO27019-10 Revocation of access procedures APPI-A26 Report of Leakage to the Commission and Notification to the Person APPI-A34 Request for Correction, Addition or Deletion CA-ITSG33-SC-01 Security Control Catalogue CA-ITSG33-SC-03 Cloud Security UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735) 27400-6.1 Secure Device Design 27400-6.2 Device Identity and Authentication BIPA-SEC5-1 Biometric Identifier Definition BIPA-SEC5-2 Biometric Information Definition NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight PSPF24-4 Physical Security IM8-CLD.2 Cloud Security Controls IM8-SEC.2 Access Control AMLCTF-35 Identity Verification Standard FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ISO28001-PS-01 Facility Security ISO20000-15 Access management for services ISO-25012-4.11 Traceability ITIL4-15 Access management for services STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control AUPRV-4 APP 10-11 Quality, Security of Personal Information NZPRV-2 IPP 5 Storage and Security of Personal Information EHDSREG-6 Phased Application and Enforcement RUSPD-2 Lawful Basis, Consent, Notice PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021 TEFCAREC-1 Common Agreement Conformance and Onboarding TURKEYKVKK-2 Information Notice and Data Subject Rights CPSC-CS.2 Authentication and Access Controls USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-2 Account Security Measures USMCADIGITAL-2 Personal Information Protection and Consumer Protection VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 229 it maps to, and the evidence behind each claim, over MCP and REST.