Overview
ISO 23234:2021 - "Buildings and civil engineering works - Security - Planning of security measures in the built environment" - provides requirements and recommendations for planning and designing protective security in buildings, infrastructure and civil engineering projects. The standard focuses on achieving optimal protection of assets against malicious acts while balancing functional, financial and aesthetic considerations. It applies to new builds, refurbishments and development projects in both government and private sectors.
Key topics and requirements
- Security planning integrated with risk management: Security planning is presented as a staged process aligned to project lifecycle phases (strategic definition; preparation and brief; concept design; developed/technical design; construction; testing and handover; in use; decommissioning).
- Defined security deliverables per stage: Examples include asset inventory, protective security objectives, threat assessment and scenario selection, security risk analyses (strategic, preparation, concept, decommissioning), and inputs to zoning, tender documentation and operations manuals.
- Roles and competencies: The standard identifies specialist roles needed in projects - security planner, security risk adviser, technical security adviser, operational security adviser, and project information security adviser - and describes their expected contributions.
- Information security for the project: Requirements and recommendations for handling sensitive project information during planning and delivery.
- Integration and verification: Emphasis on integrating security measures into architectural and operational design, participation in testing, commissioning and handover, and ongoing security verification and training in the operational phase.
- Scope limits: ISO 23234 is independent of particular risk-assessment methods and does not prescribe how to perform risk assessments or how to design specific mitigation measures; it prescribes what planning and organizational steps are required.
Applications and users
ISO 23234 is practical for organizations involved in the built environment that need to incorporate protective security into project delivery:
- Architects, engineers and design teams embedding security in concept and technical designs
- Project owners and principal contractors managing security requirements across project stages
- Security consultants and advisors responsible for threat assessment, security strategy and verification
- Facility managers and operators implementing operational security, training and maintenance
- Public authorities and private developers delivering critical infrastructure, transport hubs, public buildings and industrial sites
Using ISO 23234 helps ensure consistent, auditable security planning across lifecycle stages and supports compliance with national security requirements where applicable.
Related standards
Commonly used alongside ISO 23234 are risk and information standards such as ISO 31000 (risk management) and ISO/IEC 27001 (information security management), which can complement the planning requirements described in ISO 23234.