Section 99 of 105
96. Cyber-Physical Security and Access Control
Stable section ID: S05-CON-014-SECTION-99 · 22 content blocks
System05 cyber-physical systems shall protect both digital integrity and physical safety.
Security architecture shall include, as applicable:
- Strong asset and user identity.
- Authentication.
- Least-privilege authorization.
- Role separation.
- Secure communication.
- Software and firmware authenticity.
- Protected Building BIOS changes.
- Network segmentation.
- Secure key management.
- Logging and audit.
- Supply-chain security.
- Vulnerability management.
- Secure update and rollback.
- Incident detection.
- Recovery capability.
Authority to view information shall remain distinct from authority to command equipment, modify configuration, approve engineering decisions, or release robotic work.
Compromise of an application, AI service, sensor, user account, or external network shall not provide unrestricted authority over the building.
Essential physical safety functions shall remain effective during loss or compromise of digital systems wherever practical.
Security controls shall not create hidden emergency hazards or prevent authorized local safety action.
Suspected compromise shall trigger containment, preservation of evidence, affected-function restriction, credential review, configuration reconciliation, and verified recovery.