Overview
ISO/IEC 22237-6:2024 establishes comprehensive requirements and recommendations for the physical security of data centre facilities and infrastructures. As part of the ISO/IEC 22237 series, this standard specifically addresses how data centre spaces can be protected against unauthorized access, intrusion, fire, and environmental threats. It incorporates the criteria and classifications for availability, security, and energy efficiency from ISO/IEC 22237-1, providing a standardized framework essential for data centre design, operation, and management worldwide.
By focusing on physical security, ISO/IEC 22237-6 helps organizations mitigate risks to data centre assets and maintain service availability and data integrity. It supports stakeholders in conducting proper risk assessments and implementing protection strategies appropriate to their specific requirements.
Key Topics
- Physical Security Requirements: The standard details how to assess and assign Protection Classes to different data centre spaces and infrastructure elements, based on risk analysis.
- Protection Against Unauthorized Access: It establishes organizational and technological solutions to restrict access to authorized personnel only.
- Intrusion Prevention: Strategies for detection and mitigation of unauthorized entry, including requirements for intrusion detection systems.
- Fire and Environmental Event Response: Guidelines for managing and responding to fire events as well as other internal or external environmental hazards.
- Risk Management: Risk analysis forms a foundation for determining security measures, considering threats, vulnerabilities, and asset criticality.
- Access Control Models: Utilizes layered "defence in depth" models and specifies four Protection Classes and corresponding access control levels.
- System Integration: Guidance for integrating security lighting, video surveillance, access control, and alarm monitoring systems.
Applications
ISO/IEC 22237-6:2024 is designed for a diverse audience involved in data centre lifecycle management:
- Data Centre Owners and Operators: To ensure facility security aligns with international best practices, supporting regulatory compliance and protection of critical assets.
- Facility Managers and Security Professionals: For the implementation of effective organizational and technical controls, including access control systems and monitoring infrastructures.
- Architects, Designers, and Contractors: To incorporate security requirements early in the design and construction phases, ensuring physical barriers and spaces meet the required Protection Classes.
- Project Managers and Auditors: As a reference for evaluating physical security measures during audits, risk assessments, and certifications.
- IT Managers and System Integrators: Facilitates selection and deployment of security systems that comply with recognized standards.
- Suppliers and Installers: Assists in delivering and commissioning security systems tailored to the specified Protection Class and risk profile.
By standardizing how physical security is addressed, organizations can scale their data centre protections according to business needs and regulatory landscapes.
Related Standards
ISO/IEC 22237-6 is part of a series of standards that together form the backbone of best practices for data centre design and operation:
- ISO/IEC 22237-1: General concepts - lays out the overall classification and foundational principles.
- ISO/IEC 22237-2: Building construction - covers constructional requirements for data centre structures.
- ISO/IEC 22237-3: Power distribution - specifies electrical system requirements.
- ISO/IEC 22237-4: Environmental control - deals with temperature, humidity, and related controls.
- IEC 60839-11 series: Guidelines and requirements for access control and alarm systems.
- IEC 62676: For video surveillance system usage in security applications.
Other related domains, such as fire safety and electromagnetic compatibility (EMC), are addressed by complementary standards referenced within the ISO/IEC framework.
ISO/IEC 22237-6:2024 is a crucial standard for organizations seeking to bolster their data centre security, protect sensitive information, and ensure uninterrupted IT services. Implementing its guidance supports risk management objectives while enabling compliance with global best practices in data centre operations.