Building systems
HVAC, lighting, meters, lifts, alarms, access and other controlled equipment.
A connected building is not just an IT network with unusual devices. It is an operating environment where a digital action can change access, comfort, safety, energy use, and continuity.
List the systems that can affect the building, every path into them, the people who can change them, and the minimum safe operating state. Controls come after the map—not before it.
Control in view
Segmentation, accountable maintenance, and recoverable operations are visible controls—not policy language alone.
01
02
03Published 8 September 2026 · reviewed 9 September 2026. Editorial illustrations generated for Hamed Helped; they do not depict a named site, vendor, or client.
System boundary
HVAC, lighting, meters, lifts, alarms, access and other controlled equipment.
Controllers, gateways, protocols, management servers, cloud links and integrations.
Facilities teams, integrators, maintainers, manufacturers and support accounts.
Comfort, access, life-safety interfaces, uptime, evidence, and recovery.
Risk register
You cannot make a lifecycle, vulnerability, or recovery decision for devices and software the asset team cannot name.
A support route with no named owner, approval window, or review record becomes an unmanaged operating dependency.
Every integration between building, corporate, cloud, and third-party environments changes the path a failure can take.
A patch policy that ignores uptime, vendor support, backups, and test conditions is not yet an operational plan.
The team needs a shared answer for what the building should do when a controller, network, cloud service, credential path, or integration is unavailable.
Control baseline
Record device, software, protocol, network location, support status, responsible owner, and operational consequence.
Identify remote paths and service accounts. Define who approves access, for how long, and what record remains.
Show where building systems meet enterprise IT, cloud services, mobile credentials, and third parties.
Pair updates with backups, rollback conditions, maintenance windows, and a documented minimum safe state.
Ask for inventories, access logs, architecture records, support dates, recovery tests, and named exceptions—not a generic assurance.
Governance
| Decision | Lead | Required input | Evidence retained |
|---|---|---|---|
| Operational priority | Property operations | Critical services and minimum safe state | Approved system criticality map |
| Network boundary | IT / OT security | Connections, protocols, data flows, and remote paths | Current architecture and exception register |
| Vendor access | System owner | Support need, identity, duration, and approval | Access record and periodic review |
| Recovery acceptance | Operations + safety stakeholders | Backup, rollback, manual mode, and test result | Recovery exercise record |
First 30 days
Bring operations, IT, physical security, key vendors, and procurement into one boundary review.
Inventory critical systems, connections, remote paths, owners, and support status.
Choose a high-consequence unmanaged access or network path and give it an owner and control.
Walk one realistic loss scenario through manual operation, rollback, communication, and evidence.
Next decision
Evidence trail
Primary federal guidance covering OT environments, including building automation and physical access control examples.
Current building-specific orientation published August 2026.
Industry research on the organizational meeting point of physical and cybersecurity.