← Controls / PE

PE-13 Fire Protection

Physical and Environmental Protection

Low Moderate High

Description

Employ and maintain fire detection and suppression systems that are supported by an independent energy source.

Supplemental Guidance

The provision of fire detection and suppression systems applies primarily to organizational facilities that contain concentrations of system resources, including data centers, server rooms, and mainframe computer rooms. Fire detection and suppression systems that may require an independent energy source include sprinkler systems and smoke detectors. An independent energy source is an energy source, such as a microgrid, that is separate, or can be separated, from the energy sources providing power for the other parts of the facility.

Enhancements (3)

What NIST adds to this control. Select one to read its statement.

PE-13(01) Detection Systems — Automatic Activation and Notification ModerateHigh

Employ fire detection systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders] in the event of a fire.

PE-13(02) Suppression Systems — Automatic Activation and Notification High

a. Employ fire suppression systems that activate automatically and notify [Assignment: organization-defined personnel or roles] and [Assignment: organization-defined emergency responders]; and b. Employ an automatic fire suppression capability when the facility is not staffed on a continuous basis.

PE-13(04) Inspections

Ensure that the facility undergoes [Assignment: organization-defined frequency] fire protection inspections by authorized and qualified inspectors and identified deficiencies are resolved within [Assignment: organization-defined time period].

Withdrawn by NIST:

  • PE-13(03) Automatic Fire Suppression, now in PE-13(02)

Patterns that use this control (1)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.7.5A.7.8

ISO 27002:2022

7.5

COBIT 2019

DSS01DSS05

NIST CSF 2.0

PR.IR-02

SOC 2 TSC

A1.2

CSA CCM v4

DCS-13

CSA AICM v1

DCS-13

BSI IT-Grundschutz

INF.1INF.2

ANSSI

Hygiene.38SecNumCloud.12.3

FINMA Circular 2023/1

IV.E(89)

OSFI B-13

B-13.2.6

BIO2

7.5

RBI CSF

Annex1.3ITGRCA.18

FISC Security Guidelines

FISC.F2

HKMA TM-E-1

TME1.5.1

MLPS 2.0

8.1.1.5

SAMA CSF

3.7

NCA ECC

1-11

UAE IA

T6

CBB TM

TM-10

Qatar NIA

PS

CBE CSF

CTO-10

SA JS2

JS2-PE

CBN CSF

Part10

BoG CISD

CISD-XIV

BoM CTRM

3.5

IOSCO Cyber Resilience

PROT-5

CPMI-IOSCO PFMI

PFMI.P17

FFIEC IS

II.C.8

ECB CROE

CROE.2.3.6

EBA ICT Guidelines

3.4.3

SEBI CSCRF

PR.PE

BOT Cyber Resilience

Ch2.8

CMMC 2.0

PE

10 CFR 73.54

RG5.71-B-PE

PCI HSM

7

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.5

Lloyd's Minimum Standards

PHYS.1

HITRUST CSF v11

08.b

CCSS v9.0

1.03.3

ISO 17799 (legacy)

9.1.49.2.1

COBIT 4.1 (legacy)

DS12.4