Per PAS 1192-5:2015 lifecycle clauses: incident + audit + lifecycle management. Requirements include (a) operate Security Incident Management for BIM and built asset information including detection + triage + containment + recovery + lessons learned + (b) operate Audit and Assurance of the Security Minded Approach including periodic review + internal/external assurance + (c) maintain Security in Handover and Operational Phase including transition of security controls from construction to operations + asset management integration + (d) maintain Security in Decommissioning and Disposal including secure information disposal + media sanitisation + records management + (e) maintain governance + lifecycle management + continuous improvement + (f) integrate with organisational ISMS and asset management.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.