PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments
PAS 1192-5:2015 (now superseded by ISO 19650-5:2020 but still widely referenced) specifies a security-minded approach to Building Information Modelling (BIM), digitally built environments, and smart asset management. Developed by BSI in partnership with the UK Centre for the Protection of National Infrastructure (CPNI). Addresses the security risks of sharing sensitive building data digitally — particularly for critical national infrastructure and government buildings. Covers security triage, information classification, and breach management.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Assurance
| Code | Title |
|---|---|
| PAS1192-5-17 | Audit and Assurance of the Security Minded Approach |
CDE Security
| Code | Title |
|---|---|
| PAS1192-5-7 | Common Data Environment Security Configuration |
Incident Response
| Code | Title |
|---|---|
| PAS1192-5-14 | Security Incident Management |
Information Requirements
| Code | Title |
|---|---|
| PAS1192-5-6 | Built Asset Security Information Requirements |
Information Security
| Code | Title |
|---|---|
| PAS1192-5-18 | Sensitive Asset Information Sharing with External Parties |
| PAS1192-5-8 | Information Aggregation Risk Management |
Lifecycle Management
| Code | Title |
|---|---|
| PAS1192-5-15 | Security in Handover and Operational Phase |
| PAS1192-5-16 | Security in Decommissioning and Disposal |
Personnel Security
| Code | Title |
|---|---|
| PAS1192-5-20 | Awareness and Training |
| PAS1192-5-9 | Personnel Security and Vetting |
Physical Security
| Code | Title |
|---|---|
| PAS1192-5-10 | Physical Security of Project and Asset Sites |
Roles and Responsibilities
| Code | Title |
|---|---|
| PAS1192-5-3 | Appointment of Built Asset Security Manager |
Security Controls
Information protection and breach management
| Code | Title |
|---|---|
| CA-ITSG33-SC-01 | Security Control Catalogue |
| CA-ITSG33-SC-02 | Security Profiles |
| CA-ITSG33-SC-03 | Cloud Security |
| KR-CSAP-SC-01 | Information Security Management |
| KR-CSAP-SC-02 | Infrastructure and Network Security |
| KR-CSAP-SC-03 | Virtual Environment Security |
| MARSE-SC-01 | NIST 800-53 Moderate Baseline |
| MARSE-SC-02 | Federal Tax Information Protection |
| MARSE-SC-03 | Identity Verification |
| NRC73-CTL-01 | Access Control for CDAs |
| NRC73-CTL-02 | Network Isolation and Segmentation |
| NRC73-CTL-03 | Configuration Management |
| NRC73-CTL-04 | Monitoring and Incident Response |
| NRC73-CTL-05 | Supply Chain Security for CDAs |
| NRC73-CTL-06 | Training and Awareness |
| NZ-NZISM-SC-01 | Governance and Risk Management |
| NZ-NZISM-SC-02 | ICT Security Controls |
| NZ-NZISM-SC-03 | Cryptography and Cloud |
| PAS1192-5-SC-01 | Technical Controls |
| PAS1192-5-SC-02 | Personnel Security |
| PAS1192-5-SC-03 | Breach Management |
Security Triage
| Code | Title |
|---|---|
| PAS1192-5-1 | Security Triage Process |
| PAS1192-5-2 | Sensitivity Classification of Assets |
| PAS1192-5-ST-01 | Security Triage Process |
| PAS1192-5-ST-02 | Information Classification |
| PAS1192-5-ST-03 | Threat Assessment |
Security Triage
Information sensitivity assessment
| Code | Title |
|---|---|
| PAS1192-5-1 | Security Triage Process |
| PAS1192-5-2 | Sensitivity Classification of Assets |
| PAS1192-5-ST-01 | Security Triage Process |
| PAS1192-5-ST-02 | Information Classification |
| PAS1192-5-ST-03 | Threat Assessment |
Strategy and Policy
| Code | Title |
|---|---|
| PAS1192-5-4 | Built Asset Security Strategy |
| PAS1192-5-5 | Built Asset Security Management Plan |
Supply Chain
| Code | Title |
|---|---|
| PAS1192-5-12 | Supply Chain Security |
Technical Security
| Code | Title |
|---|---|
| PAS1192-5-11 | Technical Security Measures and Encryption |
| PAS1192-5-13 | Mobile and Remote Working Security |
| PAS1192-5-19 | BIM Tool and Software Security |
Your Compliance Coverage
If you comply with PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments, you already cover:
FAA Cybersecurity Framework for Aviation
39%
17 controls mapped
Compare →CSA CCM v4
39%
17 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
39%
17 controls mapped
Compare →+ 663 more: Azure Security Benchmark (36%), NIS2 Directive (36%)
See all 666 mapped frameworks ↓Maps to 666 other frameworks
Frequently Asked Questions
What is PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments?
PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments is a compliance framework from United Kingdom (BSI/CPNI) with 15 domains and 44 controls. PAS 1192-5:2015 (now superseded by ISO 19650-5:2020 but still widely referenced) specifies a security-minded approach to Building Information Modelling (BIM), digitally built environments, and smart asset management. Developed by BSI in partnership with the UK Centre for the Protection of National Infrastructure (CPNI). Addresses the security risks of sharing sensitive building data digitally — particularly for critical national infrastructure and government buildings. Covers security triage, information classification, and breach management. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments have?
PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments has 44 controls organised across 15 domains. The largest domains are Security Controls (21 controls), Security Triage (3 controls), Technical Security (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments map to?
PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments maps to 666 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (39% coverage), CSA CCM v4 (39% coverage), TISAX — Trusted Information Security Assessment Exchange (39% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments compliance?
Start your PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PAS 1192-5:2015 — Security-Minded Approach to BIM and Digital Built Environments requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 44 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required