DCS-13: Environmental Systems

Control Family:

Datacenter Security

CSF v1.1 References:

PF v1.0 References:

Info icon.

Control is new to this version of the control set and incorporates the following item from the previous version: BCR-03: Datacenter Utilities / Environmental Conditions.

Control Statement

Implement and maintain data center environmental control systems that monitor, maintain and test for continual effectiveness the temperature and humidity conditions within accepted industry standards.

Implementation Guidance

Examples of environmental systems include but are not limited to temperature and humidity systems, fire prevention, and detection systems. Environmental system reviews should include activities to ensure continual effectiveness, and environmental control systems should be maintained at normal operational levels during a power outage.

Auditing Guidance

  1. Confirm the existence of policy and procedures relating to environmental control in the datacenter.
  2. Verify that the environment control systems are documented and operational in accordance with policy and procedures.
  3. Determine if testing for operational control effectiveness is conducted at regular intervals.
  4. Determine if environment system logs (e.g., temperature and humidity) are generated and if related monitoring controls are maintained.
  5. Confirm that the system logs are reviewed on a periodic basis and items are disposed of in accordance with policy and procedures.

[csf.tools Note: For more information on the Cloud Controls Matrix, visit the CSA Cloud Controls Matrix Homepage.]

Cloud Control Matrix is Copyright 2023 Cloud Security Alliance.