The environment is protected by suitable measures, with specialised equipment installed to monitor and control it: the natural and man-made disasters that could strike where IT facilities sit are identified and their likely effect assessed; the way equipment, including mobile and off-site devices, is shielded from environmental threats is determined, with a policy restricting food, drink and smoking in sensitive areas and banning storage of stationery and other flammable supplies in computer rooms; sites and server rooms are kept clean and safe; facilities are located and built to reduce exposure to fire, smoke, water, air, vibration, chemicals, explosives, theft, vandalism and terror; protective measures and contingency plans are checked against what insurance policies require; environmental alarms are handled through documented and tested procedures that prioritise alarms and set out contact with emergency authorities and trained staff; and detectors for fire, water, smoke and humidity are monitored and maintained.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.