Cybersecurity For Building Automation Systems BY RON BERNSTEIN, MEMBER ASHRAE S ecuring building automation systems is a critical aspect of any commercial building design. Building owners, network and system designers, contractors and suppliers all must account for both physical and logical aspects of security. This article provides an overview and identifies the physical and logical considerations for designing a robust security specification. WHO OWNS THE CYBERSECURITY PLAN? One initial question that is often asked: Who is responsible for the cybersecurity of the building automation system (BAS)? The answer is somewhat complex as the BAS design and implementation crosses multiple domains and has responsibilities across varying project entities. Ron Bernstein is CEO of RBCG Consulting in Encinitas, Calif. He is a voting member of ASHRAE Technical Committee 1.4, Control Theory and Application, and of SGPC, Specifying Building Automation Systems. 18 ASHRAE JOURNAL ashrae.o rg M AY 2023http://www.ashrae.org