STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 1 Release: 3 Benchmark Date: 15 Jun 2020:

Environmental IA Controls - Fire Inspections/ Discrepancies

DISA Rule

SV-41036r3_rule

Vulnerability Number

V-30991

Group Title

Environmental IA Controls - Fire Inspections/ Discrepancies

Rule Version

EC-07.03.01

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Periodic fire marshal inspections of (IT) computing facilities must be conducted (minimum annually) and discrepancies noted during the inspections must be promptly addressed.

Check Contents

Check fire marshal inspection reports and documentation that verifies discrepancies are addressed and corrected.

Inspections must be conducted on at least an annual basis.

NOTES:

1. In general this should be applied to major IT equipment areas (generally computer rooms with raised floor space containing servers and communications equipment). The requirement should not be applied to administrative/office space.

2. Also, this requirement should not be applied to a tactical environment, unless it is a fixed computer facility supporting missions in a Theater of Operations. The standards to be applied for applicability in a tactical environment are: 1) The facility containing the computer room has been in operation over 1-year. 2) The facility is "fixed facility" - a hard building made from normal construction materials - wood, steel, brick, stone, mortar, etc.

3. Even if there is no finding the reviewer should note in the report the date the last fire marshal or similar inspection was conducted with a summary of results. This information could be useful during subsequent inspections.

Vulnerability Number

V-30991

Documentable

False

Rule Version

EC-07.03.01

Severity Override Guidance

Check fire marshal inspection reports and documentation that verifies discrepancies are addressed and corrected.

Inspections must be conducted on at least an annual basis.

NOTES:

1. In general this should be applied to major IT equipment areas (generally computer rooms with raised floor space containing servers and communications equipment). The requirement should not be applied to administrative/office space.

2. Also, this requirement should not be applied to a tactical environment, unless it is a fixed computer facility supporting missions in a Theater of Operations. The standards to be applied for applicability in a tactical environment are: 1) The facility containing the computer room has been in operation over 1-year. 2) The facility is "fixed facility" - a hard building made from normal construction materials - wood, steel, brick, stone, mortar, etc.

3. Even if there is no finding the reviewer should note in the report the date the last fire marshal or similar inspection was conducted with a summary of results. This information could be useful during subsequent inspections.

Check Content Reference

M

Target Key

2506

Comments