Skip to main content
← All controls
PE-13 / PE-14 / PE-15 / A.7.4 / CIS-12.8 NIST SP 800-53 Rev 5

Environmental monitoring + alerting

Demonstrate that environmental monitoring systems are deployed across critical infrastructure locations, configured with appropriate thresholds and alert mechanisms, and actively maintained to detect and notify personnel of adverse environmental conditions in real time.

Description

What this control does

Environmental monitoring and alerting systems continuously collect and analyze physical and logical infrastructure telemetry to detect anomalous conditions that could indicate security incidents, operational failures, or infrastructure compromise. These systems measure temperature, humidity, power, physical access events, fire suppression status, and other environmental parameters in data centers, server rooms, and critical facilities, generating real-time alerts when thresholds are exceeded. Effective implementation prevents data loss from environmental failures, supports incident response, and provides forensic evidence for physical security investigations.

Control objective

What auditing this proves

Demonstrate that environmental monitoring systems are deployed across critical infrastructure locations, configured with appropriate thresholds and alert mechanisms, and actively maintained to detect and notify personnel of adverse environmental conditions in real time.

Associated risks

Risks this control addresses

  • Undetected temperature or humidity excursions causing hardware failure and data loss without advance warning
  • Water leaks from HVAC, plumbing, or fire suppression systems damaging equipment before personnel respond
  • Power anomalies including voltage fluctuations or UPS failures degrading system availability without detection
  • Unauthorized physical access to server rooms or equipment cages occurring without triggering alarms
  • Fire or smoke conditions escalating due to delayed detection and notification of monitoring personnel
  • Equipment theft or tampering going unnoticed due to absence of motion, door, or rack access sensors
  • Environmental sensor failures creating blind spots that mask developing threats to infrastructure

Testing procedure

How an auditor verifies this control

  1. Obtain and review the inventory of all data centers, server rooms, telecommunications closets, and critical infrastructure locations requiring environmental monitoring.
  2. Collect configuration documentation for deployed environmental monitoring systems including sensor types, placement diagrams, monitored parameters, and alert thresholds.
  3. Verify that monitoring coverage includes temperature, humidity, water detection, power status, physical access controls, and fire/smoke detection for each critical location.
  4. Select a sample of environmental sensors and physically inspect their installation, operational status, and positioning relative to critical equipment.
  5. Review alerting configurations including notification recipients, escalation procedures, communication channels (email, SMS, SNMP traps, integration with SIEM), and redundancy mechanisms.
  6. Examine historical alert logs from the past 90 days to confirm sensors are generating alerts, personnel are responding, and thresholds trigger appropriately.
  7. Request evidence of alert testing procedures and review records demonstrating simulated or actual alert generation and successful notification delivery.
  8. Interview facilities and security operations personnel to confirm they understand monitoring responsibilities, alert response procedures, and escalation protocols.
Evidence required Collect environmental monitoring system configuration exports showing sensor inventory, threshold settings, and alert rules; network diagrams or floor plans indicating sensor placement; alert notification logs demonstrating recent alert generation and delivery; photographs or inspection records of physical sensor installations; standard operating procedures for alert response; and test records showing validation of alert delivery mechanisms within the past 90 days.
Pass criteria All critical infrastructure locations have deployed environmental monitoring covering temperature, humidity, water, power, and physical access; alert thresholds are documented and appropriate to equipment specifications; alerts successfully deliver to designated personnel through tested notification channels; and historical logs demonstrate active monitoring with timely response to triggered alerts.

Where this control is tested

Audit programs including this control