Section 82 of 101
81. Network and Functional Segmentation
Stable section ID: S05-CON-006-SECTION-82 · 30 content blocks
The BIOS architecture shall separate networks and functions so that compromise or failure in one area does not provide unrestricted access to the complete building.
Segmentation may separate:
BIOS Core services;
safety systems;
structural monitoring;
utility controls;
building automation;
occupant networks;
guest networks;
cameras and privacy-sensitive sensors;
robotic systems;
manufacturer maintenance access;
cloud and external services;
experimental systems;
- legacy equipment.
- Segmentation may be physical, logical, cryptographic, functional, or a coordinated combination.
Each segment shall define:
permitted entities;
permitted communication paths;
permitted protocols;
command authority;
data sensitivity;
gateway requirements;
monitoring;
failure behavior.
Communication between segments shall pass through controlled gateways that validate identity, authorization, message type, rate, and direction.
An occupant entertainment device shall not obtain direct access to structural, safety, utility, or BIOS Core services merely because it shares building infrastructure.
Experimental and legacy devices shall be isolated from trusted BIOS functions unless their behavior and access have been specifically controlled.
Safety-relevant local functions should remain operational during compromise or failure of noncritical network segments.
Network diagrams and functional authority maps shall remain synchronized with the active Configuration Baseline.