SAMMY UI is optimized for resolutions with a width 1024px and higher.
Secure Area Policy and Procedures
DCS-03: Are policies and procedures for maintaining a safe and secure working environment (in offices, rooms, and facilities) established, documented, approved, communicated, enforced, and maintained?
The CSP should identify the manageable parts of the data center and consider operational criteria, such as effectivity, efficiency, compliance, reliability, risk management, functionality, availability, integrity, and confidentiality. Then, the CSP should prepare and maintain policies and procedures for each part.
Policies and procedures should include provisions to restrict physical access to the facilities to prevent unauthorized entry.
Facility areas that house, store, and transact customer data should be configured to prevent confidential information or activities from being visible and audible from the outside.
Electromagnetic shielding should also be considered as appropriate (ISO standard; ISO_IEC_27002_2013 - 11.1.3 (c)).
In addition, the facility itself should be designed and positioned to reduce the risk of natural disasters. Systems and infrastructure should be deployed to enhance fire prevention—typically utilizing zoned dry-pipe sprinkler systems. These systems are intended to be deployed throughout the facility and not just within the computer room.
Control implemented
Control ownership
Description

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for maintaining a safe and secure working environment in offices, rooms, and facilities. Review and update the policies and procedures at least annually.

Secure Area Policy and Procedures
DCS-03: Are policies and procedures for maintaining safe, secure working environments (e.g., offices, rooms) reviewed and updated at least annually?
The CSP should identify the manageable parts of the data center and consider operational criteria, such as effectivity, efficiency, compliance, reliability, risk management, functionality, availability, integrity, and confidentiality. Then, the CSP should prepare and maintain policies and procedures for each part.
Policies and procedures should include provisions to restrict physical access to the facilities to prevent unauthorized entry.
Facility areas that house, store, and transact customer data should be configured to prevent confidential information or activities from being visible and audible from the outside.
Electromagnetic shielding should also be considered as appropriate (ISO standard; ISO_IEC_27002_2013 - 11.1.3 (c)).
In addition, the facility itself should be designed and positioned to reduce the risk of natural disasters. Systems and infrastructure should be deployed to enhance fire prevention—typically utilizing zoned dry-pipe sprinkler systems. These systems are intended to be deployed throughout the facility and not just within the computer room.
Control implemented
Control ownership
Description

Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for maintaining a safe and secure working environment in offices, rooms, and facilities. Review and update the policies and procedures at least annually.