Skip to content

Security-Minded Approach to Digital Engineering

  • Knowledge Level: Introductory
  • Protection Stage: All Stages
  • Time to read:

Guidance on how to take a security-minded approach to Digital Engineering, Technologies, Projects and Initiatives

Last Updated: 21 September 2026
Share this article:

The increasing use of digital technologies in the built environment is already having a transformative effect. This is leading to:

  • increased levels of collaboration, within and across sectors.
  • more transparent, open ways of working.
  • capture of real-time information about asset use and condition.
  • sharing and use of digital data and information.

Digital built assets and environments will need to deliver more demanding fiscal, functional, sustainability and growth objectives. This will promote changes in procurement, delivery and operational processes.

Off-site, factory-based fabrication and on-site automation will be used in the creation of new built assets. The use of sophisticated cyber-physical systems, combining sensors and actuators to increase energy efficiency and better asset lifecycle management, will become commonplace. This technology is already used in transportation, utilities, infrastructure, buildings, manufacturing, health care and defence leading to the creation of smart cities.

The types of mitigation measures used to manage these security risks can also be applied to protect against the loss, theft or disclosure of valuable commercial information and intellectual property as well as personal data.

Embedding good security can enhance global positioning and give a competitive advantage to commercial enterprises by building trust with their stakeholders and customers.

BS EN ISO 19650-5

BS EN ISO 19650-5:2020 is a specification for security-minded information management. It provides a framework for organisations to understand key vulnerabilities and the controls needed to manage their security risks. 

The ISO replaces PAS 1192-5, as well as absorbing the key concepts from PAS 185 and PAS 1085. The scope of the ISO is broader than PAS 1192-5, recognising that the organisations generating, processing and storing digital information face similar challenges.

The ISO specifies the principles and requirements for security-minded management of sensitive information. It can be applied by any organisation involved in the use of information management and technologies in the creation, design, construction, manufacture, operation, management, modification, improvement, demolition and/or recycling of assets or products within the built environment.

Securing Underground Asset Data

To reduce the risk of unauthorised access to, or interference with, underground infrastructure it is important to adopt a security-minded information management approach. Such an approach should consider the use cases for which such access is required and adopt appropriate and proportionate measures to limit access on a need-to-know basis. The linked guidance outlines the security principles and some of the security measures adopted by the National Underground Asset Register (NUAR). Owners of underground assets (i.e., pipes, cables ducts, etc.), and organisations processing underground asset data are encouraged to adopt a similar approach to the protection of their asset information when made accessible via the Internet.

Securing Underground Asset Data

Further Information

See further information on specific types of digital engineering, technologies, projects, initiatives and specialisms:

Additional information for surveyors undertaking utilities surveys, from desktop utility records searches and site reconnaissance to utility detection and verification, which has been produced by the Chartered Institution of Civil Engineering Surveyors. 

Guidance This guidance document is intended for use by managers leading and teams delivering digitalisation initiatives. It sets out a process to determine high-level information need and any associated security and management requirements
Guidance An introductory guide for built asset owners and facilities managers
Guidance This guidance provides the questions which an organisation needs to ask of itself and its supply chain, including its professional advisers, in order to gain an understanding of what information it, or others, holds in relation to its built assets
Did you find this page useful?
helpfulness rating