50% found this document useful (2 votes)
195 views46 pages

Data Center Audit Essentials Guide

An audit of a data center involves an independent and thorough examination of the facility and its operations. It includes an on-site inspection by auditors and a review of documentation. The goal is to evaluate availability, risks, compliance with standards, and potential weaknesses in order to improve effectiveness and avoid downtime. Benefits include gaining a detailed understanding of the current status to inform enhancements and provide assurances to stakeholders.

Uploaded by

xuyen tran
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
50% found this document useful (2 votes)
195 views46 pages

Data Center Audit Essentials Guide

An audit of a data center involves an independent and thorough examination of the facility and its operations. It includes an on-site inspection by auditors and a review of documentation. The goal is to evaluate availability, risks, compliance with standards, and potential weaknesses in order to improve effectiveness and avoid downtime. Benefits include gaining a detailed understanding of the current status to inform enhancements and provide assurances to stakeholders.

Uploaded by

xuyen tran
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Reasons for an Audit
  • Benefits
  • Nature and Scope
  • On-site Inspection
  • More than a Checklist
  • Result and Conclusion

Data Center Auditing

What you need to know about your DC infrastructure

Volkmar Bend DCDC


TÜV Informationstechnik GmbH
Member of TÜV NORD GROUP
AUDIT
An audit is a systematic and independent examination of records, documents and vouchers of an object or
an organization to ascertain how far the statements and disclosures present a true and fair view of the
object of the audit. The auditor perceives and recognizes the propositions before him / her for examination,
obtains evidence, evaluates the same and formulates an opinion on the basis of his judgement which is
communicated through his audit report.

Any subject matter may be audited. Audits provide third party assurance to various stakeholders that the
subject matter is free from material misstatement. Areas which are commonly audited include: Compliance
audit, internal controls, quality management, project management.

As a result of an audit, stakeholders may effectively evaluate and improve the effectiveness of risk manage-
ment, control, and the governance process over the subject matter.

Source: Wikipedia
TÜVIT TSI INTERNATIONAL – AUDIT AND CERTIFICATION PROJECTS

UK GER

LUX
A UK
ES CH Iran
US China

Saudi UAE Thailand


Arabia
Singapore

South
Africa
CONTENTS

 Reasons for an audit Reasons:


Insecurity about the current status of a data
 Benefits center, i.e. level of resilience, survivability, code
conformance. Or as a basis for a refurbishment
 Nature and scope or expansion project. Or to be used as an
internal or external proof of quality (marketing
 On-site inspection tool).
 More than a checklist
 Result and conclusion
RISK POTENTIALS

 Force Majeure
 Technical faults
 Criminal acts
 Negligence
AVAILABILITY

Data center requirements 24/7


PRINCIPLES OF AVAILABILITY

 Fault tolerance  Prioritization


 Redundancy  Transparency
 Separation  Automatism
 Robustness  Autonomy
 Scalability  Diversification
AVAILABILITY
 There are requirements by authorities, statutory organizations,
supervisory boards, etc., published in form of guidelines, laws, Availability
codes, regulations, …
 Priority are heath and safety issues
 Examples Protection of
– Building codes property

– Fire protection
– etc.
 There are recommendations regarding the protection of property Protection of humans

 Definition of availability??
CONTENTS

 Reasons for an audit Benefits:


Gaining detailed information about the data
 Benefits center’s current status, fault tolerances,
uncovering potential weaknesses to avoid any
 Nature and scope downtime, providing recommendations
regarding enhancements and / or potential
 On-site inspection alternatives.
 More than a checklist
 Result and conclusion
BENEFITS

Industry Customers and markets

Market position
Vendors
Bank
Courts of law

Liabilities Basel II/III

IT-operator
Conditions
Confidence
Board Insurance company
THERE ARE MANY DESIGN GUIDES …
EXCERPTS FROM THE TIA-942

Contradiction
AUDIT CATALOGUE
 Conclusion: The basis for an audit should be defined in a way that inspections will be compre-
hensive and results reproducible.
 Examples from the audit catalogue:
L1 L2 L3 L4
CONTENTS

 Reasons for an audit Nature and scope:


An independent third party analysis, neutral
 Benefits and vendor independent, carried out by trained
 Nature and scope and experiences data center professionals, pre-
ferably with an engineering background, involv-
 On-site inspection ing the client’s staff or representatives.
Covering all relevant fields including site and
 More than a checklist building, electrical and mechanical systems,
security systems, cabling, organization and do-
 Result and conclusion
cumentation, considering recognized national
and international data center standards.
IMPULSES

Important:
Holistic
approach
ENVIRONMENT
Avoidance of
 Flooding areas
 Major traffic arteries
 Explosion hazards
 Airborne contaminants
 Sources of vibration
 Political targets
 Event venues
 Etc.
CONSTRUCTION
 Protection of incoming supply lines
 Arrangement of rooms
 Constructive fire protection
 Constructive water protection
 Protection against intrusion
 Lightning protection
 Spatial separations
 Etc.
FIRE PROTECTION
 Central panel
 Smoke and other detectors
 VESDA systems
 Fire suppression systems
 Fire prevention systems
 Fire dampers
 Etc.
SECURITY SYSTEMS
 Access control system
 Gathering of data
 Coding
 Intrusion protection system
 Detectors
 CCTV
 Security zones
 Security personnel
 Etc.
ENERGY SUPPLY
 TN-S Net
 Redundancies
 Transformers
 UPS
 Generator
 Fuel storage
 Cable pathways
 SPDs
 Etc.
HVAC
 CRAC units
 Chillers
 Cooling towers / heat exchangers
 Piping and valves
 Leakage detection
 Ventilation and air filtering
 BAS
 Etc.
ORGANIZATION
 Maintenance + repairs
 Proper operation
 Responsibilities
 Security inspections
 Coordination between IT + FAC
 Testing
 Training
 Etc.
DOCUMENTATION
 Security concept
 Environmental analysis (min. 1.5 mile radius)
 DR concepts
 Floor plans
 Schematics
 Installation layouts
 Energy- and AC requirements
 List of alarms
 Etc.
2 SITES
 2 Data centers at
 2 Locations
 2 Supply paths and
 Redundant connections
 With different environmental risks
CABLING
 Redundant WAN links
 Separation of power and data cables
 Installation of cables
 Rack built-up
 Rack feeds
CONTENTS

 Reasons for an audit On-site inspection:


An onsite inspection by auditing experts as an
 Benefits essential auditing component after evaluation
of submitted documents to verify the present
 Nature and scope conditions, incl. testing and an assessment of
capacities, constraints and operation proce-
 On-site inspection dures.
 More than a checklist
 Result and conclusion
BASIC REQUIREMENTS
Documents Personnel
 current  Knowledgeable contact persons
 Originator  Access to all buildings, systems, and
 Hard copy and/or digital components
 Documents  Potentially with prior NDA
– Legend
– Scale (with floor plans)
– Date
– Suitable scale
CHECKING OF DOCUMENTS – COMMENTS

 Check on completeness
 Distribution of documents according to disciplines
 Analysis of security concept in combination with enclosed plans and schematics
 Comparison of descriptions to TSI requirements. Non-conformities, undocumented
implementations and misleading explanations will be collected in a comments list.
 Check of documents as preparation for on-site inspection
DOCUMENTATION

Risk analysis Site plan Schematics Name plate information of


Security concept Floor plans  EAC important components,
Fire protection concept Sections  Intrusion detection e.g. transformers, UPS,
DR plan  Fire detection batteries, gen sets, chillers,
Environmental analysis Projections onto floor plan of  Fire suppression cooling towers, etc.
 main supply pathways  Energy supply Energy balance
 security zones  Mechanical supply Cooling capacity balance
 intrusion detectors  Ventilation Acceptance certificates
 EAC components Room list
 CCTV cameras Door / Windows schedule
 misc. sensors, e.g. leakage
TECHNICAL KNOW-HOW
 An interdisciplinary team of technical experts will audit and evaluate the data center, e.g.
from the following fields:

– Electrical engineering
– Mechanical engineering
– Electronic security systems
– Architects
– Physicists
– Information technology
– Cabling specialists
ON-SITE INSPECTION
 Audit  Level 2: 2 auditors 1 day
– Environment  > Level 2: 3-4 auditors 1-3 days
– All IT-rooms
– All support rooms  Discussion of concepts and
– All adjacent rooms implementation with local
– Control room technical staff or planners
– Pathways  Triggering of alarms
– Roof  Photos of special situations
– Raised floor and risers
CONTENTS

 Reasons for an audit Not just checklist:


A customized format but based on well document-
 Benefits ed procedures, taking into account the data center’s
specific characteristics by analyzing and evaluating
 Nature and scope all aspects, using an engineering-based and protect-
ion-objective approach.
 On-site inspection
 More than a checklist
 Result and conclusion
THE AUDIT AND CERTIFICATION SCHEME
Audit catalogue
Design guides

UPTIME TIER BICSI 002 TIA 942 BITKOM EN 50600


THE PROBLEM WITH AN AUDIT

Some things can be


measured precisely,
different to the quality
of a data center …
THE PILLARS OF INFRASTRUCTURAL MEASURES
Smoke detectors
Temperature sensors
EAC
etc.

Detection
Precaution
SPSs
Intrusion protection
UPS Reaction
etc.
Forwarding of alarms
but also Fire suppression
Planning Switching between power sources
certification etc.
METHODOLOGY: COMPLY OR EXPLAIN

Goal: Protection by other objects


Avoidance of major
traffic arteries with an Course of traffic artery
increased risk of the
transport of hazardous
Speed limit
goods (risk analysis) Distance to
major traffic User frequency
artery
Type of construction Type of road

Room arrangement Accident statistics


CONTENTS

 Reasons for an audit Outcome:


The evaluation reports must be comprehensive,
 Benefits concise and pragmatic, making practical re-
 Nature and scope commendations for improvements and suggest-
ions for a realistic implementation, specific to
 On-site inspection the audited facility, with reproducible conclus-
ions.
 More than a checklist
 Result and conclusion
TYPICAL PROBLEMS (EXAMPLES)

 Fire stops
 Fire loads (boxes, waste cans)
 Security deficiencies / differences in quality
 Monitoring of intrusion attempts and protection against intrusion are different things

 Congestion of raised floor


 A property „following“ a standard
does not conform to the standard
TYPICAL PROBLEMS (EXAMPLES)

 Grounding connections
 Human mistakes (design, installation, operation, maintenance)
 Missing sensibility of the personnel
 Reaction to alarms
 Insufficient reserves
 Documentation is not up-to-date
PROJECT X

 ABC powder fire extinguishers


 1 ceiling mounted smoke detector + ASD
 Gas suppression system (3 bottles insufficient)
 EAC tokens in office drawer
 Missing drip trays underneath pipes
PROJECT Y

 Position fire dampers


 Caps on ceiling mounted smoke detectors
 Gas suppression system
 Technical building with wooden stairs
 Missing screw in major flange
 Tilted pedestals in raised floor
AUDIT AS BASIS OF A CERTIFICATION
The advantages of a certification:
 Creating trust with your clients.
 Provision of a proof of quality for monitoring institutions / internal revision /
accountants.
 You are improving and securing the quality of your services.
 Generation of a competitive advantage in the industry.
VERIFYING IS BETTER THAN A VERBAL STATEMENT
A LOOK TO THE FUTURE

What will be the future international standards for Data Centers (and also for audits)?

The ISO/IEC committee has decided on May 18th 2017 to develop documents for sustainable
ICT facilities and infrastructure, such as data centers. These documents will use the EN 50600
as the basis and will also consider other standards and best practices.

Resolutions adopted at the 18 May 2017 JTC 1/SC 39 Plenary in Sunnyvale, Ca.
AT THE CONCLUSION
YOUR POINT OF CONTACT

TÜV Informationstechnik GmbH


Langemarckstrasse 20
45141 Essen, Germany

Volkmar Bend DCDC


[Link].(USA) Dipl.-[Link].(TH)
Data Center Auditor
IT Infrastructure
+49-201-8999-579
[Link]@[Link]

Common questions

Powered by AI

Redundancy in data center infrastructure is critical for maintaining operational reliability and minimizing downtime during unexpected failures. It involves having backup systems and components such as TN-S networks, redundant generators, UPS systems, and multiple cable pathways to ensure continued operation despite individual component failures . This layered protection supports uninterrupted services, which is vital for meeting the high availability demands of modern data centers .

An on-site inspection is essential in data center audits as it allows auditors to verify the actual conditions against the documented claims, assess capacities, identify constraints, and review operational procedures . It includes testing and engagement with local technical staff to discuss concepts and implementations, ensuring that all aspects of the data center are functioning as intended . This practical verification step contributes to a thorough and accurate evaluation of the data center .

Availability in data center operations refers to the requirement of maintaining 24/7 operational readiness . Key principles involved in ensuring availability include fault tolerance, redundancy, separation, robustness, scalability, prioritization, transparency, automatism, autonomy, and diversification . These principles ensure that data centers can withstand interruptions and continue to provide intended services without significant downtime .

Security systems in data center management are crucial for preventing unauthorized access and ensuring the protection of data. Critical components of effective security systems include access control systems, data gathering, coding, intrusion protection systems, detectors, CCTV, security zones, and security personnel . These components work collaboratively to create multiple layers of security, addressing both physical and digital threats to the data center's operations .

A comprehensive documentation process is crucial in data centers to ensure efficient operation, safety, and compliance with standards. Key elements to include are security concepts, environmental analyses, disaster recovery plans, floor plans, schematics, installation layouts, energy and AC requirements, and a list of alarms . Detailed and up-to-date documentation supports maintenance and troubleshooting activities, facilitating a clear understanding of the data center’s infrastructure and operations .

The location of a data center should avoid areas prone to flooding, major traffic arteries, explosion hazards, airborne contaminants, sources of vibration, and political targets . Construction plans should ensure the protection of supply lines, effective room arrangements, fire protection measures, water protection measures, intrusion protection, lightning protection, and spatial separations . These precautions help mitigate various environmental risks that could affect the data center’s operations and integrity .

Data center audits recommend methodologies such as ‘comply or explain’ where detailed evidence and explanations are required when standards aren’t met . This approach ensures transparency and accountability, prompting organizations to either demonstrate compliance or justify deviations based on risk assessments and operational needs . It supports continuous improvement by encouraging data centers to address discrepancies proactively .

Typical challenges identified in data center audits include fire stops, security deficiencies, documentation not up-to-date, missing grounding connections, and human errors in design, installation, operation, and maintenance . These issues may lead to increased vulnerabilities to outages, security breaches, and legal non-compliance, ultimately affecting the center's operational efficiency and reputation . Addressing these challenges is critical to maintaining a high standard of data center operations .

Certification based on data center audits creates a competitive advantage by establishing trust with clients and serving as a proof of quality for monitoring institutions, internal revisions, and accountants . It enhances the quality of services and provides a market edge. Future developments in international standards are anticipated with the ISO/IEC committee’s decision to develop documents for sustainable ICT facilities and infrastructure, such as the use of EN 50600 as a basis, integrating other standards and best practices . This evolution reflects the growing emphasis on sustainability and operational excellence in data center management .

The main reasons for conducting a data center audit include assessing the current status of data center resilience, survivability, and code conformance. Audits provide a basis for refurbishment or expansion projects and serve as internal or external proof of quality, which can be used as a marketing tool . The benefits to stakeholders include gaining detailed information about the data center's current status, identifying fault tolerances, uncovering potential weaknesses to avoid downtime, and receiving recommendations for improvements or alternatives . Moreover, stakeholders can effectively evaluate and improve risk management, control, and governance processes over the subject matter .

Data Center Auditing
What you need to know about your DC infrastructure
Volkmar Bend DCDC
TÜV Informationstechnik GmbH
Member
AUDIT
An audit is a systematic and independent examination of records, documents and vouchers of an object or 
an organizatio
TÜVIT TSI INTERNATIONAL – AUDIT AND CERTIFICATION PROJECTS 
UK
US
LUX
Iran
UK
South 
Africa
A
CH
ES
UAE
Saudi 
Arabia
Singapo
CONTENTS 
Reasons for an audit
Benefits
Nature and scope
On-site inspection
More than a checklist
Result and conclusion
RISK POTENTIALS 

Force Majeure

Technical faults

Criminal acts

Negligence
AVAILABILITY 
Data center requirements 24/7
PRINCIPLES OF AVAILABILITY 

Fault tolerance

Redundancy

Separation

Robustness

Scalability

Prioritization

Transpa
AVAILABILITY 
There are requirements by authorities, statutory organizations, 
supervisory boards, etc., published in form o
CONTENTS 
Reasons for an audit
Benefits
Nature and scope
On-site inspection
More than a checklist
Result and conclusion
BENEFITS 
Industry
Customers and markets
Courts of law
Bank
Insurance company
Board
Liabilities
Vendors
Market position
Basel

You might also like