{"data":{"id":"PE-14","name":"Environmental Controls","family":"PE","family_name":"Physical and Environmental Protection","withdrawn":false,"description":"a. Maintain [Selection (one or more): temperature; humidity; pressure; radiation; [Assignment: organization-defined environmental control]] levels within the facility where the system resides at [Assignment: organization-defined acceptable levels]; and\nb. Monitor environmental control levels [Assignment: organization-defined frequency].","supplemental_guidance":"The provision of environmental controls applies primarily to organizational facilities that contain concentrations of system resources (e.g., data centers, mainframe computer rooms, and server rooms). Insufficient environmental controls, especially in very harsh environments, can have a significant adverse impact on the availability of systems and system components that are needed to support organizational mission and business functions.","enhancements":[{"id":"PE-14(01)","name":"Automatic Controls","statement":"Employ the following automatic environmental controls in the facility to prevent fluctuations potentially harmful to the system: [Assignment: organization-defined automatic environmental controls].","baselines":[]},{"id":"PE-14(02)","name":"Monitoring with Alarms and Notifications","statement":"Employ environmental control monitoring that provides an alarm or notification of changes potentially harmful to personnel or equipment to [Assignment: organization-defined personnel or roles].","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"PE-14","name":"Environmental Controls","description":"a. Maintain [Selection (one or more): temperature; humidity; pressure; radiation; [Assignment: organization-defined environmental control]] levels within the facility where the system resides at [Assignment: organization-defined acceptable levels]; and\nb. Monitor environmental control levels [Assignment: organization-defined frequency].","discussion":"The provision of environmental controls applies primarily to organizational facilities that contain concentrations of system resources (e.g., data centers, mainframe computer rooms, and server rooms). Insufficient environmental controls, especially in very harsh environments, can have a significant adverse impact on the availability of systems and system components that are needed to support organizational mission and business functions.","related_controls":["AT-03","CP-02"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Temperature and Humidity Controls' Adds parameter for selection of specific types of environmental controls to maintain Discussion amplifies impact of insufficient environmental controls"}},"compliance_mappings":{"iso_27001_2022":["A.7.5","A.7.8","A.7.11"],"iso_27002_2022":["7.5","7.8"],"cobit_2019":["DSS01","DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.IR-02"],"cis_controls_v8":[],"soc2_tsc":["A1.2","A1.2-POF2"],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["INF.1","INF.2"],"anssi":["Hygiene.38","SecNumCloud.12.3"],"osfi_b13":["B-13.2.6"],"finma_circular":["IV.A(28)","IV.E(89)"],"gdpr":[],"dora":[],"bio2":["7.5","7.8"],"rbi_csf":["Annex1.3","ITGRCA.18"],"fisc":["FISC.F2"],"lgpd_bcb":[],"hkma_tme1":["TME1.5.1"],"mlps_2":["8.1.1.7"],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-10"],"nca_ecc":["1-11"],"qatar_nia":["PS"],"sama_csf":["3.7"],"uae_ia":["T6"],"bog_cisd":["CISD-XIV"],"bom_ctrm":["3.5"],"cbe_csf":["CTO-10"],"cbn_csf":["Part10"],"sa_js2":["JS2-PE"],"bot_cyber":["Ch2.8"],"cpmi_pfmi":["PFMI.P17"],"eba_ict":["3.4.3"],"ecb_croe":["CROE.2.3.6"],"ffiec_is":["II.C.8"],"iosco_cyber":["PROT-5"],"sebi_cscrf":["PR.PE"],"cmmc_2":["PE"],"nerc_cip":[],"nrc_73_54":["RG5.71-B-PE"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":["Clause 4"],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["08.b","09.b"],"iso_27799":["11.2"],"lloyds_ms":["PHYS.1"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.5"],"owasp_masvs_v2":[],"csa_ccm_v4":["DCS-13"],"csa_aicm":["DCS-13"],"ccss_v9":["1.03.3","1.03.7"],"mica":[],"basel_sco60":["SCO60.53"],"bssc":["NOS-09"],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.7.11 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-002"]}}