Why this section matters: Most of a company's data should be stored and processed in a data center. The physical and environmental protections built into data centers are intended to provide a safe haven for data. This section asks questions about these security controls, to ensure they can provide adequate protection for confidential data.
Warning — possible medium-risk issue
When strong physical security controls are in place, certain requirements that are usually recommended (e.g., encryption of data at rest) may be relaxed. These exceptions are acceptable only if specific security controls are implemented in all data centers that may store confidential information. A written policy describing these requirements should be enforced to ensure that a baseline for physical security is uniformly implemented across all data centers.
If you have compensating controls in place or feel that this issue does not constitute a risk in your specific circumstances, please explain below. If you're working to address this issue, include an estimate of when it will be resolved:
Warning — possible high-risk issue
Electronic access control is strongly recommended for data centers that handle or store confidential or sensitive data. Standard (non-electronic) keys are very difficult to control (short of changing the entire lock), and access is generally not logged in an auditable way.
If you have compensating controls in place or feel that this issue does not constitute a risk in your specific circumstances, please explain below. If you're working to address this issue, include an estimate of when it will be resolved:
Warning — possible high-risk issue
Make sure to put procedures in place to regularly verify that security controls are working as intended.
List the controls that are not regularly tested, and explain whether you have compensating controls in place:
Warning — possible high-risk issue
HVAC and temperature inside data centers should be monitored, and appropriate personnel should be informed when they are outside normal ranges.
If you have compensating controls in place, such as automatic failover to another data center, please explain below:
Warning — possible high-risk issue
Physical access to data center facilities should generally be highly restricted, because a breach can affect confidentiality, integrity, and availability of information. It's important to have an auditable process for granting and revoking physical access, and for reviewing physical entry logs. Otherwise it won't be possible to determine at any given time who actually has access to the data center and the data stored within it.
If you have compensating controls in place or feel that this issue does not constitute a risk in your specific circumstances, please explain below. If you're working to address this issue, include an estimate of when it will be resolved:
Warning — possible medium-risk issue
Unfortunately, security incidents (whether physical or logical) are not always immediately detected. It's important to retain physical access log files, typically for six months, in case they're needed for investigation.
If you have compensating controls in place or feel that this issue does not constitute a risk in your specific circumstances, please explain below. If you're working to address this issue, include an estimate of when it will be resolved:
Warning — possible medium-risk issue
In data theft incidents, it is not always immediately obvious that data has been copied (after all, nothing is missing per se). To address this, physical access logs should be regularly reviewed so that irregularities can be quickly identified and investigated.
If you have compensating controls in place or feel that this issue does not constitute a risk in your specific circumstances, please explain below. If you're working to address this issue, include an estimate of when it will be resolved:
Warning — possible medium-risk issue
If availability is a strong concern for your project, you should make sure you're able to quickly switch to a different data center that is not geographically close to the one that's experiencing the outage.
If you have compensating controls in place or feel that this issue does not constitute a risk in your specific circumstances, please explain below. If you're working to address this issue, include an estimate of when it will be resolved:
Warning — possible high-risk issue
To ensure that current security controls are adequate, it's important to assess the physical and environmental risks that your data center (or data center provider) is exposed to.
If you have compensating controls in place or feel that this issue does not constitute a risk in your specific circumstances, please explain below. If you're working to address this issue, include an estimate of when it will be resolved: