Lesson 9.3Lesson 9.3 · Security, Privacy & Governance
Standards & Interoperability
Open standards keep a building open - and keep you out of the walled garden
The most expensive word in a smart-building contract is proprietary.
No single vendor makes the whole building. HVAC from one supplier, lighting from another, access control from a third, meters from a fourth, a platform from a fifth - a smart building only works if these parts can talk. Whether they can, and whether you can swap or add one later, is decided by standards.
This is where the field is quietly won or lost. Choose open standards and the building stays open: parts interoperate, you can change vendors, and your data is yours. Drift into a walled garden - proprietary protocols, closed platforms, data you cannot export - and you are locked in, at the vendor's mercy for price and roadmap for the life of the building. This lesson maps the standards landscape so you can keep the doors open.
Open protocols + shared schema + data export. Walled garden = whole-system exit cost. 27001 = process, not product.
Why interoperability matters
Interoperability is the ability of independent systems to exchange information and use it - to work together without a custom, hand-built bridge for every pair. In a building it is not a nicety; it is the difference between a coherent system and an expensive pile of silos. Without it, the lighting cannot tell the HVAC a zone is empty, the analytics platform cannot read the meters, and every new device needs bespoke integration work that costs more than the device.
Interoperability has layers. At the bottom is connectivity - can the devices physically exchange bytes (BACnet, Modbus, KNX, MQTT)? Above that is semantics - do they agree on what the bytes mean? A value of 22 is useless unless both sides know it is the supply-air temperature of AHU-3 in Celsius. This is the harder, more valuable layer, and it is why data schemas like Brick and Project Haystack matter as much as the wire protocols. True interoperability needs both: a shared language and a shared dictionary. Get it, and a building becomes a platform you can build on; miss it, and every improvement is a fresh integration bill.
Two layers: connectivity (can they talk?) + semantics (do they agree what it means?). Need both.
Open standards versus walled gardens
An open standard is published, vendor-neutral and implementable by anyone - BACnet (ASHRAE/ISO 16484-5) for building automation, MQTT (OASIS/ISO) for lightweight messaging, KNX for control, and open data schemas like Brick and Haystack for meaning. Because many vendors implement them, parts from different suppliers interoperate, and you can swap or add components without ripping out the whole system.
A walled garden is the opposite: a vendor whose devices, protocol and cloud are proprietary and only work with each other. It is often genuinely easier at first - one throat to choke, a polished experience, fast setup. The cost arrives later. When everything speaks only the vendor's private language, your exit cost is the entire system: to change one part you must change all of it, the vendor sets the price because you have no alternative, and if they raise fees, drop a feature or go out of business, you are stranded. Your data may be trapped in their cloud in a format you cannot export. The honest trade-off: walled gardens optimise for convenience today; open standards optimise for freedom and cost over the building's life. For an asset that lasts decades, that second horizon almost always wins - which is why insisting on open protocols and exportable data is one of the most valuable specification decisions you can make.
Open = swap any vendor. Walled garden = exit cost is the whole system. Buildings last decades.
ISO/IEC 27001 and the security standards
Standards are not only about making things talk; they are also about doing things safely and provably. The headline security standard is ISO/IEC 27001, the international standard for an information security management system (ISMS). Crucially, it is not a product or a firewall you buy - it is a managed discipline: identify your information risks, select and apply controls to treat them, check that they work through audit and monitoring, and continuously improve. A plan-do-check-act cycle that makes security an ongoing practice rather than a one-off purchase.
For a building project, 27001 (often alongside the NIST Cybersecurity Framework from the first lesson, and OT-specific standards such as the IEC 62443 family for industrial control systems) gives everyone a shared, auditable language for how secure is secure enough. When a client asks a platform vendor 'are you 27001 certified?', they are asking whether security is a governed system there, not an afterthought. As a designer you will not run the ISMS, but you should know to ask for these credentials, to write them into the brief, and to treat certification as a meaningful signal - while remembering that a certificate is evidence of a managed process, not a guarantee of invulnerability. The deep assessment and certification remain the work of qualified security professionals and accredited auditors.
A worked example: specifying an open building
Principles get real at specification time, so walk through a concrete brief. A client is fitting out a mid-size office and wants smart HVAC, lighting, access control, metering and an analytics dashboard from several suppliers. Left to chance, each trade installs its own controller, its own protocol and its own app, and two years later the client discovers that adding a simple 'empty room, lights off' rule means paying three vendors to build custom integrations - and that their energy data lives in a dashboard they cannot export. That is the walled-garden outcome arriving by drift, one procurement at a time.
The open alternative is written into the brief before anyone buys anything. At the connectivity layer you require compliance with open protocols - BACnet for HVAC and controls, KNX or BACnet for lighting, Modbus or BACnet for meters, MQTT where lightweight IoT messaging is used - so any compliant device from any vendor can join the network. At the semantic layer you require the delivered system to be tagged to an open schema - Brick or Project Haystack - so the data is self-describing and a new analytics tool can read 'supply-air temperature of AHU-3' without a bespoke mapping exercise. You require ISO/IEC 27001 credentials, or a clear NIST-framework mapping, from any platform vendor. And - the clause most often forgotten - you require data portability: the right to export all historical and live data in an open format, at any time, at no punitive cost.
On a larger project you also name who owns interoperability: a master systems integrator whose job is to make these standards actually hold across trades. The result is a building that behaves like a platform - swap a chiller vendor, add an analytics startup, change platforms - without ripping everything out. None of this bans proprietary products; if a closed device is genuinely the best tool, it can still be chosen, but as a deliberate, costed exception with an exit path, not a default. The whole discipline reduces to a sentence a designer can carry into any procurement meeting: prefer open, insist on export, and make proprietary a decision, not an accident.
Standards as protection against lock-in
Pull the threads together and standards reveal their real strategic value: they are insurance against being trapped. Three practical rules protect a project. First, specify open protocols - require BACnet, MQTT, KNX or equivalent at the connectivity layer so devices from any compliant vendor can join. Second, demand a shared semantic model - Brick or Haystack tagging - so the data is self-describing and a new analytics tool can understand it without a bespoke mapping project. Third, and most overlooked, secure data portability in the contract: you must be able to export your building's historical and live data, in an open format, and take it with you. Data you cannot export is data you do not really own.
The rise of the master systems integrator - the specialist who makes many vendors interoperate around open standards - exists precisely because this is hard and valuable. None of it means never buying proprietary technology; sometimes a closed product is genuinely the best tool. It means going in with eyes open - pricing the lock-in, keeping an exit path, and never accidentally surrendering your data or your freedom to switch. For a designer, the memorable rule is simple: prefer open, insist on export, and treat proprietary as a deliberate, costed choice - never a default you drifted into.
It helps to remember why this matters more for buildings than for most technology. A phone or a laptop is replaced every few years, so a little lock-in is tolerable; a building stands for decades, and the systems inside it are expected to be upgraded, extended and re-tendered many times over that life. A lock-in decision taken casually at fit-out therefore compounds for thirty years, long after the person who made it has moved on. Open standards are how you hand the next owner, the next integrator and the next analytics tool a building they can still work with. That long horizon - designing for people and systems you will never meet - is exactly the architectural instinct this course keeps returning to, applied now to data and protocols rather than brick and steel.
Specify open protocols + shared schema + data export in the contract. Data you cannot export you do not own.
BACnet (ISO 16484-5)
Open building-automation protocol
Vendor-neutral, widely implemented; specifying it keeps HVAC and controls interoperable across suppliers.
MQTT
Open lightweight publish/subscribe messaging
An OASIS/ISO standard common in IoT; open and broadly supported, so devices are not tied to one platform.
Brick Schema / Project Haystack
Open semantic models for building data
Give data shared meaning so any tool can understand it - the semantic layer that makes real interoperability possible.
ISO/IEC 27001
Information security management system
A managed plan-do-check-act discipline, not a product; certification signals security is governed, though never a guarantee.
Workshop - grade a system for openness and lock-in
Take a real or proposed smart-building product and interrogate it for interoperability and exit risk. The goal is to turn a glossy brochure into an honest openness score.
A product spec sheet or vendor site, and this lesson's interoperability map. No purchase or account needed - documentation review only.
Goal: judge a product's openness and lock-in risk Inputs: a smart-building product or platform + its spec/marketing Time: ~30 minutes
- 1Connectivity check: what protocols does it speak? Open (BACnet, MQTT, KNX, Modbus) or proprietary-only? Note whether third-party devices can join.
- 2Semantics check: does it use or export an open data schema (Brick, Haystack) so other tools can understand its data, or is the meaning locked inside its own app?
- 3Exit check: can you export your full historical and live data in an open format and take it elsewhere? If the answer is unclear, treat it as no.
- 4Security-standard check: does the vendor hold ISO/IEC 27001 or map to the NIST framework, and can they show it? Note it as a signal, not a guarantee.
- 5Score it: rate the product open / mixed / walled garden, list what you would require in the contract to reduce lock-in, and decide whether any proprietary parts are a deliberate, costed choice.
You’ll walk away with
A one-page openness scorecard for a product: its protocols, semantic model, data-export answer, security-standard credentials, an overall open/mixed/walled verdict, and the contract clauses you would insist on to protect against lock-in.
Three altitudes on the same idea
Read the band that fits you — or all three.
Open standards are a specification you control at design stage. Writing 'BACnet-compliant, Brick/Haystack-tagged, data exportable in open format' into the brief costs nothing now and saves the owner from a decades-long lock-in later. You are also the natural champion for a master systems integrator role on larger projects - the person who keeps every vendor honest and interoperable. Design the building as an open platform, not a stack of private silos.
The smart-interior products you love are where walled gardens sneak in. A beautiful lighting or blinds ecosystem that only works with its own app and hub is a lock-in decision hiding as a design choice. Favour products that speak open protocols (KNX, BACnet, standard MQTT) and can join the building's wider system, so your interiors stay part of one coherent, swappable whole rather than an island the client is stuck with.
Interoperability is where the integrator careers are. Understanding open protocols, data schemas like Brick and Haystack, and security standards like ISO/IEC 27001 is exactly the literacy master systems integrators, consultants and platform teams hire for. It is also durable knowledge - open standards outlive individual products. Learn the landscape here and you can speak fluently to every vendor in the room.
“One vendor for everything is simpler, so a single proprietary ecosystem is the smart choice.”
Do it yourself
Judge the openness, not the marketing.
- 1Name the two layers of interoperability and why both are needed.
- 2Give two open protocols and say what layer each addresses.
- 3In one sentence, what is the real cost of a walled garden over a building's life?
- 4What does ISO/IEC 27001 certify - a product, or a process?
- 5State the three specification rules that protect a project from lock-in.
The one line to carry out
Peer-reviewed journals & authoritative standards
- 01BACnet — Wikipedia, 2026.
- 02MQTT — Wikipedia, 2026.
- 03Brick Schema - metadata schema for buildings — Brick, 2026.
- 04ISO/IEC 27001 — Wikipedia, 2026.
Open, secure, well-governed systems still have to keep the building running when something fails. Next we close the module with resilience and reliability - fail-safe defaults, graceful degradation and the discipline of never letting the twin become a single point of failure.
The author
Amogh N P
Architect, interior designer, and creative polymath. Studio Matrx began in his notebooks — his vision of design made honest, useful, and open to everyone. Its Academy is written and taught in his memory, and free, forever.
More about Amogh →