Skip to content

Connected Places - Specification for Establishing and Implementing a Security-Minded approach

  • Knowledge Level: All Levels
  • Protection Stage: All Stages
  • Time to read:

PAS 185:2023 is a specification for establishing and implementing a placewide, strategic-level, security-minded approach as part of both its development and operation

Last Updated: 17 September 2026
Share this article:

Introduction

PAS 185:2023 is a specification for establishing and implementing a place-wide, strategic-level, security-minded approach as part of both its development and operation. It details the approach for applying holistic measures that are appropriate and proportionate to the risks and that do not prevent the delivery of a place’s aims.

The underlying premise of connected places is that greater availability of data and information, integration of services and systems, and outcome-based contracting can:

  • increase the capacity, efficiency, reliability and resilience, and thereby availability, of existing assets to enable enhanced service provision; and
  • improve efficiency in design, delivery, and operation of built assets through a better understanding of the whole-life performance of those already implemented.

A key purpose of a connected place is to join up specific vertical sectors (e.g. utilities, transport, health, etc.) across organisational boundaries into a whole-space approach for the creation, delivery and use of place spaces and services. PAS 185 specifies the types of policies and processes that need to be in place across place-based service delivery organisations in order for the place to respond to the new or enhanced vulnerabilities created by these changes to existing ways of working that could:

  1. compromise the value, longevity and ongoing use of a place’s built assets and services;
  2. compromise a place’s citizens;
  3. cause harm, damage or distress to individuals or vulnerable groups, including injury, death or social unrest;
  4. disrupt or corrupt data, information and/or systems;
  5. cause reputational damage; and/or
  6. enable acquisition of personal data, intellectual property or commercially sensitive data or information.

PAS 185:2023 was commissioned by the National Protective Security Authority (NPSA), who provided the technical authors for its development. The British Standards Institution (BSI) facilitated its production with input from a panel of industry experts.

Purpose of this guidance

This booklet provides a high-level overview of the key components of PAS 185. The full version of the PAS is available to download.

Who is this for?

PAS 185 is applicable where a service applies to multiple assets and/or data and information is shared or processed by more than one organisation. While specifically written for connected place decision-makers and data officers, whether from the public, private or third sectors, it is also of relevance to those who are interested in utilising data and information to deliver connected place objectives effectively.

Summary of the PAS 185 process

Summary of the PAS 185 process

 

  • Create governance structure and appoint connected place decision-makers (Dark blue banner at the top).
  • Understand new and/or enhanced security risks to the connected place (Dark rectangular box).
  • Expands via a yellow bar labeled "Security risks arise through:" into three light blue circles: 
    • "Greater availability of data and information;", 
    • "Integration of services and systems;", and
    • "Increased dependency on IT-based systems."
  • Conduct a place-specific security risk assessment (Dark rectangular box).
  • Decide on appropriate and proportionate mitigation measures commensurate with the place's collective risk appetite (Dark rectangular box).
  • Formally record the risk management process as part of a Security Strategy (Dark rectangular box).
  • Develop a Security Management Plan that will allow the mitigation measures to be implemented consistently on a place-wide scale (Dark rectangular box).
  • Expands via a yellow bar labeled "It should contain policies and processes covering the following aspects of security:" into four light blue circles: 
    • "People",
    •  "Physical", 
    • "Data and information security", and 
    • "Technical (incl. cyber)".
  • Further expands via a yellow bar labeled "It should also contain:" into three yellow rectangular boxes:
    • "The arrangements for governance of, and accountability and responsibility for, delivery of the security-minded approach;"
    • "The approach to managing the deployment and use of Internet of Things (IoT) and other distributed technologies; and"
    • "The arrangements for monitoring and auditing the plan's implementation."
  • Develop a Security Breach/Incident Management Plan (Dark rectangular box).
  • Conduct reviews on a regular basis, as well as in response to significant internal or external changes (Dark rectangular box at the bottom).
  • A side-arrow loops from this final step back up to the step Develop a Security Management Plan, indicating a continuous feedback and review cycle.

Developing a security strategy

The security-minded approach developed within a connected place needs to respond to the vulnerabilities created by changes to more traditional ways of working, and the range of threats that may seek to exploit them, without preventing delivery of the connected place’s aims.

  • The concept of security
  • Security issues
  • The holistic approach to security
  • Understand over security threats to built assets and service in the connected place
  • Success of security advice

What are the new vulnerabilities that are created?

In June 2012, the UK Government published its Open Data White Paper ‘Unleashing the Potential’ which was aimed at:

  • an increase in the volume of data and information being generated and processed, including:

Asset data and information

Personal data

Intellectual property

Commercially sensitive data and information

  • greater sharing and dissemination of data and information within and across organisations with various existing contractual arrangements in place;
  • the potential aggregation of data and information from a wide range of sources;
  • potential differing organisational priorities; governance arrangements; policies and processes; security understanding and concerns; and risk appetite; and
  • the use of interfaces to share data between applications which can increase the exposed data, information and systems to attack.

Contents of a security strategy

The Security Strategy should comprise a record of:

  • The connected place’s security risk management strategy;
  • A list of those to be informed of residual risks;
  • The mechanisms for reviewing and updating the strategy.

Security risk management strategy

Assessment or risk

Where a security-minded approach is adopted, a key component of the process set out in PAS 185 relates to the management of risk. The connected place decision-makers need to assess potential vulnerabilities and threats, in combination with an assessment of the nature of harm that could be caused.

The assessment needs to identify high-level security risks associated with:

  • Governance and accountability
  • People
  • Physical security
  • Data and information
  • Technology
  • Intellectual property
  • Commercial data and information

Security management plan

The Security Management Plan sets out the policies and processes that allow the mitigation measures identified in the Security Strategy to be implemented and managed consistently across the connected place.

It should:

  • Be implementable on a place-wide scale;
  • Be implementable within the organisational complexity and the extent of autonomy that exists within a connected place;
  • Not prevent efficient and effective response to incidents, security breaches, events or any fast-occurring change in risk level.

It should include:

  • Arrangements for governance of, and accountability and responsibility for, delivery of the security-minded approach;
  • The process for embedding the security-minded approach into new or revised contracts;
  • The management of the deployment and use of IoT and other distributed technologies;
  • Policies and processes relating to the aspects of people, physical, data and information and technical (including cyber) security;
  • Arrangements for monitoring and auditing implementation;
  • Mechanisms for review and updating; and
  • The security-minded approach to individual projects or initiatives affecting a connected place.

Coverage of the policies and processes

  • security competence of staff fulfilling specific roles;
  • security screening and vetting;
  • induction requirements;
  • general security training and awareness;
  • role-specific security training;
  • demobilisation of personnel and organisations.
  • physical security measures at locations processing sensitive data or information;
  • protective measures for equipment handling of connected places’ data and/or information; and
  • protective measures for infrastructure supporting data and information sharing and access by citizens.
  • security features required for the connected place’s data and information architecture;
  • managing the accuracy, authenticity and long-term utility of connected places’ data and information;
  • managing the security of data and information that could be used to cause harm to assets, services and/or the connected place’s citizens; and
  • data and information sharing and publication.
  • cyber security of systems and the interconnections and interactions between them;
  • interoperability of systems;
  • configuration management and change control for systems processing place data and/or information;
  • level of software trustworthiness;
  • secure retention, deletion, destruction and/or removal of access to the connected place’s data and information.

Embedding Security

In order to be effective, the security-minded approach must be integrated with other strategic policies, plans, and requirements for the delivery, maintenance and operation of the connected place.

Project, Data or Information Services Sharing Initiative

  • High-Level Strategy & Frameworks:
    • Smart City Framework (SCF) and Smart City Roadmap (Strategy) (both BS ISO 37106) link directly down into operational frameworks.
    • Smart City Concept Model (SCCM) (BS ISO/IEC 30182) sits adjacent to the core strategic path.
    • Security Strategy (PAS 185) guides the overarching security policies.
  • Project & Implementation Initiatives:
    • Smart City Solutions Project Initiative (PAS 184) feeds directly into project execution.
    • Smart City Data and Information Services Sharing Initiative (PAS 183) connects to data sharing processes.
    • Security Management Plan (PAS 185) flows downwards into specific project risk assessments.
  • Project, Data, or Information Services Sharing Initiative (Blue Box):
    • A central blue region encompasses the actionable, project-level frameworks.
    • Data and Information Services Sharing Framework (PAS 183) defines data tiers ranging from open data, public access, group access, and specific access, down to closed data.
    • Project, Service or Initiative-specific Security Risk Management Plan (PAS 185) feeds into a Data and Information Security Triage Process (PAS 185).
    • The triage process and the sharing framework both converge onto a final Data and Information Sharing Agreement (PAS 183 & PAS 185).

Colour-coded key in the bottom right corner defines the standards: 

  • orange for BS ISO 37106
  • dark red for ISO 30182
  • yellow for PAS 183
  • olive green for PAS 184
  • light blue for PAS 185.
Did you find this page useful?
helpfulness rating