What's Happening?
Federal buildings are experiencing a significant shift where facilities management and information security are merging, a change that was not necessarily planned but is now underway. Historically, operational technology (OT) networks, such as building automation
systems, were isolated from enterprise IT networks. However, modern facilities increasingly see OT and IT sharing the same physical infrastructure, like structured cabling and switching. While OT traffic is logically segregated into its own VLANs, this integration means building systems are no longer physically isolated and fall under the purview of the Chief Information Officer (CIO) for defense. Devices within these systems, such as field controllers, now authenticate users, hold credentials, run patchable firmware, and export data, making them information systems regardless of their traditional labels. This integration brings them under the scope of the Federal Information Security Modernization Act (FISMA), requiring agencies to secure these systems according to the National Institute of Standards and Technology’s (NIST) Risk Management Framework. This means building management platforms may now require authorization packages, impact-level categorization, and continuous monitoring, similar to systems handling sensitive agency data.
Why It's Important?
This merger of facilities management and information security in federal buildings has profound implications for operational efficiency, cybersecurity, and compliance. The integration of OT and IT networks means that vulnerabilities in building systems can now pose risks to the broader federal enterprise network, potentially exposing sensitive data or critical infrastructure to cyber threats. The application of FISMA and NIST standards to building systems elevates the security requirements for facility managers, who traditionally have not been focused on information security. This necessitates a new level of collaboration between facilities teams and IT security offices to ensure compliance and protect federal assets. Failure to integrate security requirements early in the specification and procurement process can lead to wasted resources, project delays, and the deployment of unauthorized platforms. Furthermore, the shift impacts vendor relationships, as remote access and firmware updates for building systems now require stricter controls and adherence to IT security protocols, moving away from previous, less regulated practices.
What's Next?
To navigate this evolving landscape, federal agencies need to implement several key strategies. Firstly, information-system requirements must be integrated into the specifications for all new facility projects, uplifts, and platform migrations from the outset, rather than being an afterthought. This proactive approach will ensure that security is built into the system design, authentication, segmentation, and access control mechanisms. Secondly, agencies should utilize operational technology (OT) specific standards, such as NIST SP 800-82, instead of solely relying on IT playbooks. This recognizes the unique operational constraints of building systems, where a surprise reboot of a chiller, for example, can have significant consequences. Finally, facility managers require adequate IT training to understand the new security landscape, speak the language of cybersecurity, and effectively manage their responsibilities within this merged environment. This training will empower FMs to become active participants in the authorization process, leveraging their intimate knowledge of the building to ensure effective security implementation.
Beyond the Headlines
The convergence of facilities management and information security in federal buildings highlights a broader trend of increasing digitalization and interconnectedness across all sectors. This development underscores the critical need for a holistic approach to security that transcends traditional departmental silos. The ethical implications revolve around the balance between operational convenience and robust security, especially as more building functions become software-driven and remotely accessible. Legally, the expanded scope of FISMA to include OT systems means that federal agencies face heightened accountability for securing these previously overlooked assets. Culturally, this shift demands a transformation in how facilities and IT personnel collaborate, fostering a shared understanding of risks and responsibilities. In the long term, this integration could lead to more resilient and intelligent federal buildings, but it also necessitates continuous adaptation to emerging threats and technological advancements, ensuring that security measures evolve alongside the systems they protect.













