PE-18 Location Of Information System Components

Physical and Environmental Protection

Low Moderate High

Description

The organization positions information system components within the facility to minimize potential damage from physical and environmental hazards and to minimize the opportunity for unauthorized access.\n

Supplemental Guidance

Physical and environmental hazards include, for example, flooding, fire, tornados, earthquakes, hurricanes, acts of terrorism, vandalism, electrical interference, and electromagnetic radiation. Whenever possible, the organization also considers the location or site of the facility with regard to physical and environmental hazards.\n

Enhancements

(1) The organization plans the location or site of the facility where the information system resides with regard to physical and environmental hazards and for existing facilities, considers the physical and environmental hazards in its risk mitigation strategy.\n

Compliance Mappings

ISO 27002:2022

7.127.37.57.8

SOC 2 TSC

A1.2

ISO 17799 (legacy)

9.2.1

COBIT 4.1 (legacy)

DS12.1