The new ISO 19650-5:2020 Organization and digitization of information about buildings and civil engineering works, including building information modelling (BIM) – Information management using building information modelling – Part 5: Security-minded approach to information management is a specification for security-minded information management. It provides a framework to assist organizations in understanding the key vulnerability issues and the nature of the controls required to manage the resultant security risks to a level that is tolerable to the relevant parties.
The increasing use of digital technologies, including Building Information Modelling (BIM), in the design, construction, manufacture, operation and management of assets or products, as well as the provision of services, within the built environment is already having a transformative effect on the parties involved, a trend which is likely to continue, and leading to:
- increased levels of collaboration, within and across sectors;
- more transparent, open ways of working;
- capture of real-time information about asset use and condition;
- and sharing and use of digital data an and information.
ISO 19650-5:2020 is a specification for security-minded information management. It provides a framework to assist organizations in understanding the key vulnerability issues and the nature of the controls required to manage the resultant security risks to a level that is tolerable to the relevant parties. Its use should not in any way undermine collaboration or the benefits that BIM other collaborative work methods and digital technologies can generate.
It specifies the principles and requirements for security-minded management of sensitive information that is obtained, created, processed and stored as part of, or in relation to, an initiative, project, asset, product or service. Implementation of the measures outlined in the standard will assist in reducing the risk of the loss, misuse or modification of sensitive information that can impact on the safety, security and resilience of:
- assets;
- products;
- the built environment, or
- the services provided by, from or through them.
The measures can also be applied to protect against the loss, theft or disclosure of valuable commercial information and intellectual property as well as personal data. Further, embedding good security can enhance global positioning and can give competitive advantage to commercial enterprises by building trust with their stakeholders and customers in the services and products they provide.
ISO 19650-5 should be applied by any organization involved in the use of information management and technologies in the creation, design, construction, manufacture, operation, management, modification, improvement, demolition and/or recycling of assets or products, as well as the provision of services, within the built environment. It will also be of interest and relevance to other organizations wishing to protect their commercial information, personal information and intellectual property.
The standard is developed in collaboration with CEN/TC 442, with ISO lead. Project leader is Alex Luck (UK).