A.7.8 Equipment siting and protection
Site equipment securely and protect it.
12
artefacts
3
held by a system
2
at each review
moderate
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- HVAC maintenance logs · SIEM / log platform
- Temperature and humidity monitoring reports · SIEM / log platform
- Access control logs for equipment rooms · Physical access / facilities
periodic reviewEvidence produced at each review
- Fire suppression system inspection certificates · Physical access / facilities
- Key card issuance records · Physical access / facilities
governing documentDocuments that govern the control
- Floor plan with equipment locations · Policy repository / GRC workspace
- Rack elevation diagrams · Policy repository / GRC workspace
- Power distribution schematics · Policy repository / GRC workspace
- CCTV footage retention policy · Policy repository / GRC workspace
- Preventive maintenance schedule for servers · Policy repository / GRC workspace
- Incident reports of equipment relocation · Document repository
- Asset inventory with location tags · Policy repository / GRC workspace
First move
Start with the 3 of 12 artefacts that already live in a system (SIEM / log platform); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Assuming perimeter security covers equipment
- Outdated or missing environmental monitoring data
- Lack of documented siting criteria
- Inconsistent access logs for equipment areas
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.7.7 Clear desk and clear screen · A.7.9 Security of assets off-premises