ISO/IEC 22237-6:2024
Information technology — Data centre facilities and infrastructures — Part 6: Security systems
Information technology — Data centre facilities and infrastructures — Part 6: Security systems
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 34
- Дата публикации:
- 19 февраля 2024 г.
- Издание:
- ISO/IEC IS 22237 edition 1 version 1
- ICS:
- 13.220.99
This document specifies requirements and recommendations concerning the physical security of data centres based on the criteria and classifications for “availability”, “security” and “energy efficiency enablement” within ISO/IEC 22237-1. This document provides designations for the data centre spaces defined in ISO/IEC 22237-1. This document specifies requirements and recommendations for such data centre spaces, and the systems employed within those spaces, in relation to protection against: a) unauthorized access addressing organizational and technological solutions; b) intrusion; c) internal fire events igniting within data centre spaces; d) internal environmental events (other than fire) within the data centre spaces which would affect the defined level of protection; e) external environmental events outside the data centre spaces which would affect the defined level of protection. NOTE Constructional requirements and recommendations are provided by reference to ISO/IEC 22237-2. Safety and electromagnetic compatibility (EMC) requirements are outside the scope of this document and are covered by other standards and regulations. However, information given in this document can be of assistance in meeting these standards and regulations. Conformance of data centres to the present document is covered in Clause 4.
Abstract
Overview
ISO/IEC 22237-6:2024 establishes comprehensive requirements and recommendations for the physical security of data centre facilities and infrastructures. As part of the ISO/IEC 22237 series, this standard specifically addresses how data centre spaces can be protected against unauthorized access, intrusion, fire, and environmental threats. It incorporates the criteria and classifications for availability, security, and energy efficiency from ISO/IEC 22237-1, providing a standardized framework essential for data centre design, operation, and management worldwide.
By focusing on physical security, ISO/IEC 22237-6 helps organizations mitigate risks to data centre assets and maintain service availability and data integrity. It supports stakeholders in conducting proper risk assessments and implementing protection strategies appropriate to their specific requirements.
Key Topics
- Physical Security Requirements: The standard details how to assess and assign Protection Classes to different data centre spaces and infrastructure elements, based on risk analysis.
- Protection Against Unauthorized Access: It establishes organizational and technological solutions to restrict access to authorized personnel only.
- Intrusion Prevention: Strategies for detection and mitigation of unauthorized entry, including requirements for intrusion detection systems.
- Fire and Environmental Event Response: Guidelines for managing and responding to fire events as well as other internal or external environmental hazards.
- Risk Management: Risk analysis forms a foundation for determining security measures, considering threats, vulnerabilities, and asset criticality.
- Access Control Models: Utilizes layered "defence in depth" models and specifies four Protection Classes and corresponding access control levels.
- System Integration: Guidance for integrating security lighting, video surveillance, access control, and alarm monitoring systems.
Applications
ISO/IEC 22237-6:2024 is designed for a diverse audience involved in data centre lifecycle management:
- Data Centre Owners and Operators: To ensure facility security aligns with international best practices, supporting regulatory compliance and protection of critical assets.
- Facility Managers and Security Professionals: For the implementation of effective organizational and technical controls, including access control systems and monitoring infrastructures.
- Architects, Designers, and Contractors: To incorporate security requirements early in the design and construction phases, ensuring physical barriers and spaces meet the required Protection Classes.
- Project Managers and Auditors: As a reference for evaluating physical security measures during audits, risk assessments, and certifications.
- IT Managers and System Integrators: Facilitates selection and deployment of security systems that comply with recognized standards.
- Suppliers and Installers: Assists in delivering and commissioning security systems tailored to the specified Protection Class and risk profile.
By standardizing how physical security is addressed, organizations can scale their data centre protections according to business needs and regulatory landscapes.
Related Standards
ISO/IEC 22237-6 is part of a series of standards that together form the backbone of best practices for data centre design and operation:
- ISO/IEC 22237-1: General concepts - lays out the overall classification and foundational principles.
- ISO/IEC 22237-2: Building construction - covers constructional requirements for data centre structures.
- ISO/IEC 22237-3: Power distribution - specifies electrical system requirements.
- ISO/IEC 22237-4: Environmental control - deals with temperature, humidity, and related controls.
- IEC 60839-11 series: Guidelines and requirements for access control and alarm systems.
- IEC 62676: For video surveillance system usage in security applications.
Other related domains, such as fire safety and electromagnetic compatibility (EMC), are addressed by complementary standards referenced within the ISO/IEC framework.
ISO/IEC 22237-6:2024 is a crucial standard for organizations seeking to bolster their data centre security, protect sensitive information, and ensure uninterrupted IT services. Implementing its guidance supports risk management objectives while enabling compliance with global best practices in data centre operations.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 39 - Sustainability, IT and data centres
- SKU
- ISO/IEC 22237-6:2024
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 22237-3:2021
ДействующийInformation technology — Data centre facilities and infrastructures — Part 3: Power distribution
Overview ISO/IEC 22237-3:2021, "Information technology - Data centre facilities and infrastructures - Part 3: Power distribution", defines requirements and recommendations for power supplies to, and…
ISO/IEC 22237-2:2024
ДействующийInformation technology — Data centre facilities and infrastructures — Part 2: Building construction
Overview ISO/IEC 22237-2:2024 - Information technology - Data centre facilities and infrastructures - Part 2: Building construction - specifies requirements and recommendations for the construction o…
ISO/IEC 22237-4:2021
ДействующийInformation technology — Data centre facilities and infrastructures — Part 4: Environmental control
Overview ISO/IEC 22237-4:2021 - Information technology - Data centre facilities and infrastructures - Part 4: Environmental control - defines requirements and recommendations for environmental contro…
IEC 60839-11-2:2014
ДействующийAlarm and electronic security systems - Part 11-2: Electronic access control systems - Application guidelines
Overview IEC 60839-11-2:2014 is an international standard published by the International Electrotechnical Commission (IEC) that provides comprehensive application guidelines for Electronic Access Con…
IEC 62676-2-31:2019
ДействующийVideo surveillance systems for use in security applications - Part 2-31: Live streaming and control based on…
Overview IEC 62676-2-31:2019 is an international standard developed by the International Electrotechnical Commission (IEC) that focuses on video surveillance systems used for security applications. T…