Section 87 of 102
86. Cybersecurity Architecture
Stable section ID: S05-CON-010-SECTION-87 · 18 content blocks
System05 cybersecurity shall protect the confidentiality, integrity, availability, authenticity, and recoverability of building systems and information.
The architecture should include:
- Network segmentation.
- Secure identity management.
- Encrypted communications.
- Secure credential storage.
- Signed software and configurations.
- Device authentication.
- Access monitoring.
- Vulnerability management.
- Secure update mechanisms.
- Backup and recovery.
- Intrusion detection.
- Incident containment.
- Local safe operation.
Building networks should separate safety-critical controls, operational technology, occupant services, guest devices, external services, and maintenance access according to risk.
Cybersecurity controls shall consider the long service life of buildings. Components that cannot be updated securely shall be isolated, monitored, replaced, or restricted.
AI convenience shall not justify exposing unrestricted building-control interfaces to public networks or general-purpose applications.