Data Center Review Audit Work Program
Data Center Review Audit Work Program
Data Center Review Audit Work Program
SAMPLE 1
Planning
Fieldwork
Report Issuance
AUDIT OBJECTIVES
OVERVIEW
PHYSICAL SECURITY
Ensure that vendor service personnel and visitors are supervised while in
the data center.
2 Source: www.knowledgeleader.com
Audit Step Initial Index
hours, etc.).
• If keys or cipher locks are used, review the adequacy of procedures for
distribution, custody, retrieval and periodic reissuance.
Obtain a list of individuals with access to the data center and test for
reasonableness.
ENVIRONMENTAL
Ensure that clear and adequate fire placards are posted in strategic
locations and that fire alarm pull boxes and emergency power switches
are visible and unobstructed.
Ensure that fire evacuation procedures are posted in the data center.
Ensure that portable fire extinguishers within the data center have been
inspected/recharged within the last 12 months.
3 Source: www.knowledgeleader.com
Audit Steps Initial Index
Review the physical environment of the data center for the following:
• Quality housekeeping occurs (e.g., clean, clutter-free, lack of
flammable materials, etc.).
• Wiring and patch panels are organized in a clean and manageable
fashion.
REPORTING
Hold a closing meeting with key management to review the internal audit
report draft and findings.
4 Source: www.knowledgeleader.com
DATA CENTER REVIEW AUDIT WORK PROGRAM:
SAMPLE 2
Planning
Fieldwork
AUDIT OBJECTIVE
Determine that information resources are protected against unauthorized access and environmental hazards.
5 Source: www.knowledgeleader.com
Time Project Work Step Initial Index
• Ensure that clear and adequate fire placards are posted in strategic
locations and that fire alarm pull boxes and emergency power switches
are visible and unobstructed.
• Ensure that emergency lighting is available in the data center.
• Ensure that there are raised floors, or all equipment is raised at least X
inches off the floor.
• Determine if automatic fire/water detection/extinguishing systems are
present.
• Determine if adequate air conditioning and humidity control systems
are present. If so, verify the following:
− Is the air conditioning unit dedicated?
− Are ventilation and air conditioning systems adequate to maintain
appropriate temperature and humidity levels?
− Are temperature and humidity levels recorded and routinely
monitored?
• Determine if uninterruptible power supply (UPS) systems are present.
If so, perform the following:
− Determine how long the UPS runs.
− Determine the switch over/failover plan to a generator.
• Determine if network cables and sockets are labeled.
• Determine if IS is notified if monitoring systems (for air conditioning,
UPS system, etc.) are triggered.
• Determine if preventive maintenance is performed on data center
equipment (i.e., UPS system, fire suppression, air conditioners, smoke
detectors, etc.).
• Review the physical environment of the data center for the following:
− Quality housekeeping (i.e., clean, clutter-free, lack of flammable
materials, etc.) occurs.
− Wiring and patch panels are organized in a clean and manageable
fashion.
6 Source: www.knowledgeleader.com