Skip to main content
The state of ai impact assessment
BACS Cybersecurity Checklist: 15 Steps to Protect Your Building Control SystemsRegulatory Bodies
7 min readFor IT Security Teams

BACS Cybersecurity Checklist: 15 Steps to Protect Your Building Control Systems

Your building automation systems weren't designed for internet connectivity. Now they're exposed to the same threat actors targeting your corporate network, but with operational technology constraints that make traditional IT security controls impractical or dangerous to deploy.

NIST released a quick-start infographic and supporting resources to help Building Automation & Control Systems owners and operators address this gap. This checklist translates those resources into actionable steps your security team can verify and complete.

What This Checklist Covers

This checklist applies to commercial and federal facilities running BACS for HVAC, lighting, access control, fire alarms, energy management, and related systems. If your building control systems connect to corporate networks or cloud services, you're managing operational technology risk whether you've acknowledged it or not.

The checklist prioritizes immediate security improvements that don't require system downtime or major capital investment. Each item maps to NIST guidance while respecting the performance, reliability, and safety requirements that distinguish OT from traditional IT environments.

Prerequisites

Before starting this checklist, confirm you have:

  • Asset inventory: A documented list of all BACS devices, controllers, and network connections.
  • Network diagrams: Current topology showing how BACS networks connect to corporate IT and external services.
  • Change authority: Permission to modify network configurations and access controls without emergency approval processes.
  • Vendor contacts: Current support agreements and technical contacts for your building management system providers.

Ensure you can produce these documents within 30 minutes when an auditor or incident responder asks for them.

BACS Security Checklist

Network Segmentation

1. Isolate BACS networks from corporate IT using dedicated VLANs or physical separation

Reference: NIST SP 800-82 (under revision), NIST Cybersecurity Framework (CSF) 2.0 PR.AC-5

Check for: Firewall rules preventing direct access between building control networks and general corporate systems. BACS controllers should not share network segments with workstations or servers.

Ensure a network engineer attempting to ping a BACS controller from a corporate workstation receives no response. All legitimate access routes through documented jump hosts or management consoles.

2. Implement allowlist-based firewall rules for BACS network traffic

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 PR.PT-4

Check for: Firewall configurations that explicitly permit only required protocols and ports. Default-deny posture with documented exceptions for each allowed connection.

Your firewall logs should show zero attempts to establish unauthorized protocols. Every permitted rule includes a business justification and review date.

3. Disable internet access for building controllers and sensors

Reference: NIST SP 800-82

Check for: Outbound internet blocks at the network perimeter. Cloud-connected systems route through authenticated proxies, not direct internet connections.

BACS devices should not reach public DNS servers or external IP addresses. Cloud integration happens through dedicated gateways with credential management.

Access Control

4. Remove default credentials from all BACS devices and controllers

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 PR.AA-1, ANSI/ISA-62443

Check for: Password audits showing no vendor default passwords (admin/admin, root/root, etc.) in active use. Unique credentials for each administrative account.

Ensure you can't log into any building controller using credentials published in vendor documentation or online forums.

5. Implement Privileged Access Management for BACS administrative accounts

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 PR.AA-6

Check for: Just-in-Time Access provisioning for building system administrators. Session recording for privileged activities. Automated credential rotation.

Building engineers should request time-limited access through a PAM system. You can review video recordings of what they changed during emergency maintenance windows.

6. Enforce Role-Based Access Control aligned with operational responsibilities

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 PR.AA-5

Check for: Documented roles (facility manager, HVAC technician, security operator) with specific permission sets. Regular access reviews removing permissions no longer needed.

Your lighting technician should not modify fire alarm configurations. Former employees' credentials should stop working on their last day without manual intervention.

Visibility and Monitoring

7. Deploy passive network monitoring on BACS segments

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 DE.CM-1

Check for: Network taps or SPAN ports feeding traffic to a security monitoring platform. Baseline traffic patterns documented for normal operations.

You should receive alerts when a building controller starts communicating with unexpected IP addresses or using protocols not seen in your baseline.

8. Enable logging on all BACS devices that support it

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 DE.CM-6

Check for: Syslog forwarding configured on controllers, building management servers, and network devices. Logs retained for a minimum of 90 days.

You should be able to reconstruct who changed HVAC setpoints last Tuesday at 3 AM and from which workstation they connected.

9. Integrate BACS security events into your Security Operations Center

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 DE.AE-2

Check for: BACS log sources feeding your SIEM. Correlation rules detecting suspicious patterns (off-hours access, configuration changes, network anomalies).

Your SOC team should see BACS alerts in the same dashboard as corporate IT events. They should understand which building system events require immediate response.

Vulnerability Management

10. Establish a BACS-specific patching process that accounts for operational constraints

Reference: NIST SP 800-82, NIST Cybersecurity Framework (CSF) 2.0 2.0 ID.RA-2

Check for: Documented testing procedures for patches. Approved maintenance windows. Rollback procedures. Vendor support verification before applying updates.

Critical vulnerabilities should be patched within documented timeframes. Avoid causing unplanned building system outages by applying untested updates.

11. Maintain vendor support agreements for all critical BACS components

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 ID.AM-2

Check for: Active maintenance contracts. Documented escalation procedures. Security advisory subscriptions from vendors.

When a critical vulnerability announcement arrives, you should be able to contact vendor support and receive patch guidance within your SLA timeframe.

Incident Response

12. Develop BACS-specific incident response procedures

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 RS.MA-1

Check for: Playbooks covering scenarios like ransomware on building management servers, unauthorized access to controllers, and denial-of-service affecting HVAC systems. Contact lists including facilities staff and building system vendors.

Your Computer Security Incident Response Team should be able to execute Containment, Eradication, and Recovery steps for a building system compromise without waiting for someone to explain how HVAC controllers work.

13. Test incident response procedures with tabletop exercises

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 RS.MA-2

Check for: Annual exercises simulating BACS security incidents. Participation from IT security, facilities management, and executive leadership. Documented lessons learned and procedure updates.

When you simulate a ransomware infection on your building management server, participants should know whether to fail-safe systems to manual mode or maintain automated operation during recovery.

Governance

14. Assign clear ownership for BACS cybersecurity

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 GV.OC-1

Check for: Written responsibility matrices showing who owns risk decisions, who implements controls, and who monitors compliance. Regular meetings between IT security and facilities management.

When auditors ask who's responsible for BACS security, you should get one answer. That person should have budget authority and report to senior leadership.

15. Document BACS security requirements in vendor contracts and RFPs

Reference: NIST Cybersecurity Framework (CSF) 2.0 2.0 GV.SC-1

Check for: Security specifications in building system procurement documents. Vendor security assessment requirements. Contractual obligations for vulnerability disclosure and patch delivery.

Your next HVAC system upgrade should include vendors who commit to 30-day patch delivery for critical vulnerabilities and support secure remote access protocols.

Common Mistakes

Treating BACS like IT infrastructure: Operational technology requires different security approaches. You can't reboot a chiller during business hours to apply patches. Your controls must account for 24/7 operational requirements and safety implications.

Assuming air gaps still exist: If your building management system has a web interface or sends email alerts, it's networked. Cloud-connected thermostats and remote monitoring services mean your BACS touches the internet whether facilities staff acknowledge it or not.

Ignoring resource constraints: NIST's guidance recognizes that BACS operators face limited budgets and staff. Prioritize the controls that reduce your highest risks first. Network segmentation and credential management deliver more risk reduction than perfect patch compliance.

Overlooking physical security integration: Your access control system is both a physical security tool and a cyber asset. Compromised badge readers can grant building access. Coordinate security requirements with your physical security team.

Next Steps

Start with items 1-6 focused on network segmentation and access control. These deliver immediate risk reduction without requiring new technology purchases.

Review NIST's Cybersecurity for Building Systems Project for detailed implementation guidance. If you operate water/wastewater, transportation, energy, or manufacturing facilities, consult the sector-specific resources from NIST's National Cybersecurity Center of Excellence.

NIST is revising NIST SP 800-82 Guide to Operational Technology Security with an updated draft expected later in 2026. Subscribe to NIST's OT security updates to receive the public comment draft.

Your building automation systems control the physical environment where your people work. Secure them with the same rigor you apply to systems containing sensitive data.

Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.

You Might Also Like