ISO 19650-5:2020
Organization and digitization of information about buildings and civil engineering works, including building information modelling (BIM) — Information management using building information modelling — Part 5: Security-minded approach to information management
Organization and digitization of information about buildings and civil engineering works, including building information modelling (BIM) — Information management using building information modelling — Part 5: Security-minded approach to information management
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 28
- Дата публикации:
- 10 июня 2020 г.
- Издание:
- ISO IS 19650 edition 1 version 1
- ICS:
- 35.240.67
This document specifies the principles and requirements for security-minded information management at a stage of maturity described as "building information modelling (BIM) according to the ISO 19650 series", and as defined in ISO 19650-1, as well as the security-minded management of sensitive information that is obtained, created, processed and stored as part of, or in relation to, any other initiative, project, asset, product or service. It addresses the steps required to create and cultivate an appropriate and proportionate security mindset and culture across organizations with access to sensitive information, including the need to monitor and audit compliance. The approach outlined is applicable throughout the lifecycle of an initiative, project, asset, product or service, whether planned or existing, where sensitive information is obtained, created, processed and/or stored. This document is intended for use by any organization involved in the use of information management and technologies in the creation, design, construction, manufacture, operation, management, modification, improvement, demolition and/or recycling of assets or products, as well as the provision of services, within the built environment. It will also be of interest and relevance to those organizations wishing to protect their commercial information, personal information and intellectual property.
Abstract
Overview
ISO 19650-5:2020 specifies a security-minded approach to information management for building information modelling (BIM) and other digitally enabled practices across the built environment. It defines principles and requirements for identifying, protecting and monitoring sensitive information created, held or shared during the lifecycle of projects, assets, products and services - from design and construction through operation, modification and demolition. The standard is part of the ISO 19650 series and complements broader information-security frameworks without replacing organizational standards such as ISO/IEC 27001.
Key topics and technical requirements
- Sensitivity assessment and security triage - establish whether a security-minded approach is required by assessing organizational and third‑party sensitivities and recording outcomes.
- Governance, accountability and responsibilities - assign roles to ensure security requirements are implemented across collaborative delivery teams.
- Security strategy development - assess security risks, define mitigation measures, and document residual/tolerated risks.
- Security management plan - translate strategy into policies, processes and controls including security information requirements, logistical security and provision of information to third parties.
- Security breach / incident management - prepare detection, containment, recovery and review procedures for security incidents involving BIM or asset information.
- Working with appointed parties - embed security measures in appointments, manage out-of-contract collaboration and define information‑sharing agreements.
- Monitoring, auditing and review - continuous compliance checks and periodic reassessment when changes occur.
Practical applications and users
ISO 19650-5 is practical for any organization using BIM or digital information management in the built environment:
- Owners and asset managers integrating digital asset data into operations and maintenance.
- Project and BIM managers responsible for collaborative data environments and information exchanges.
- Contractors and consultants who must protect commercial and intellectual property when sharing models and data.
- Security and IT teams implementing risk-based controls for cyber-physical systems and sensitive datasets.
- Small and medium enterprises (SMEs) participating in delivery teams, as the standard advocates proportionate measures suitable for all sizes.
Benefits include clearer responsibilities for information security in BIM workflows, reduced risk of data breaches, and consistent handling of sensitive project and personal information across multi‑party collaborations.
Related standards
- ISO 19650-1 and ISO 19650-2 - foundational concepts and delivery-phase information requirements within the ISO 19650 series.
- ISO/IEC 27001 - organizational information security management (complementary for internal systems).
- ISO 55000 - strategic asset management links where asset lifecycle and security intersect.
Keywords: ISO 19650-5, BIM security, security-minded approach, information management, building information modelling, security management plan, sensitivity assessment, information sharing agreements.
Технические детали
- Технический комитет
- ISO/TC 59/SC 13 - Organization and digitization of information about buildings and civil engineering works, including building information modelling (BIM)
- SKU
- ISO 19650-5:2020
Похожие стандарты
Стандарты, упомянутые в описании
BS EN ISO 19650-4:2022
ДействующийOrganization and digitization of information about buildings and civil engineering works, including building…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
BS EN ISO 19650-5:2020
ДействующийOrganization and digitization of information about buildings and civil engineering works, including building…
BS EN ISO 19650-1:2018
ДействующийOrganization and digitization of information about buildings and civil engineering works, including building…
ISO 19650-2:2018
ДействующийOrganization and digitization of information about buildings and civil engineering works, including building…
Overview ISO 19650-2:2018 defines requirements for information management using Building Information Modelling (BIM) during the delivery phase of assets (projects, buildings, infrastructure). It spec…