← Controls / PE

PE-14 Environmental Controls

Physical and Environmental Protection

Low Moderate High

Description

a. Maintain [Selection (one or more): temperature; humidity; pressure; radiation; [Assignment: organization-defined environmental control]] levels within the facility where the system resides at [Assignment: organization-defined acceptable levels]; and b. Monitor environmental control levels [Assignment: organization-defined frequency].

Supplemental Guidance

The provision of environmental controls applies primarily to organizational facilities that contain concentrations of system resources (e.g., data centers, mainframe computer rooms, and server rooms). Insufficient environmental controls, especially in very harsh environments, can have a significant adverse impact on the availability of systems and system components that are needed to support organizational mission and business functions.

Changes from Rev 4

Title changed from 'Temperature and Humidity Controls' Adds parameter for selection of specific types of environmental controls to maintain Discussion amplifies impact of insufficient environmental controls

Enhancements (2)

What NIST adds to this control. Select one to read its statement.

PE-14(01) Automatic Controls

Employ the following automatic environmental controls in the facility to prevent fluctuations potentially harmful to the system: [Assignment: organization-defined automatic environmental controls].

PE-14(02) Monitoring with Alarms and Notifications

Employ environmental control monitoring that provides an alarm or notification of changes potentially harmful to personnel or equipment to [Assignment: organization-defined personnel or roles].

Patterns that use this control (1)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.7.5A.7.8A.7.11

ISO 27002:2022

7.57.8

COBIT 2019

DSS01DSS05

NIST CSF 2.0

PR.IR-02

SOC 2 TSC

A1.2A1.2-POF2

CSA CCM v4

DCS-13

CSA AICM v1

DCS-13

BSI IT-Grundschutz

INF.1INF.2

ANSSI

Hygiene.38SecNumCloud.12.3

FINMA Circular 2023/1

IV.A(28)IV.E(89)

OSFI B-13

B-13.2.6

BIO2

7.57.8

RBI CSF

Annex1.3ITGRCA.18

FISC Security Guidelines

FISC.F2

HKMA TM-E-1

TME1.5.1

MLPS 2.0

8.1.1.7

SAMA CSF

3.7

NCA ECC

1-11

UAE IA

T6

CBB TM

TM-10

Qatar NIA

PS

CBE CSF

CTO-10

SA JS2

JS2-PE

CBN CSF

Part10

BoG CISD

CISD-XIV

BoM CTRM

3.5

IOSCO Cyber Resilience

PROT-5

CPMI-IOSCO PFMI

PFMI.P17

FFIEC IS

II.C.8

ECB CROE

CROE.2.3.6

EBA ICT Guidelines

3.4.3

SEBI CSCRF

PR.PE

BOT Cyber Resilience

Ch2.8

CMMC 2.0

PE

10 CFR 73.54

RG5.71-B-PE

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.5

Lloyd's Minimum Standards

PHYS.1

HITRUST CSF v11

08.b09.b

ISO 27799

11.2

CCSS v9.0

1.03.31.03.7

Basel SCO60

SCO60.53

BSSC Standards

NOS-09

ISO 17799 (legacy)

9.2.110.5.110.7.1

COBIT 4.1 (legacy)

DS12.4