It must contain the following information:
- installation of air conditioning systems to ensure optimal temperature and humidity values for the safe operation of equipment
- use of fireproof materials and installation of fire prevention and extinguishing systems, specially designed to avoid equipment damage
- proper sizing of the electrical network, according to the consumption of the equipment used
- guaranteeing safety in the event of foreseeable failures of utility systems (water, gas, etc.) serving the space hosting the data center
- use of UPS devices and/or electrical generators to ensure uninterrupted operation of equipment in case of main power supply failure; the emergency power supply time will be calculated based on estimated repair times for possible malfunctions in the main electrical network
- duplication of all elements of the electrical network and ensuring the possibility of automatic switching from the main network to the backup network
- use of working procedures to ensure periodic backup of all information stored in the data center and storing it in a different space from the main data center area, with the same security conditions as the main space, located at a distance from the main space that meets European standards in the field
- ensuring maintenance procedures for equipment and infrastructure, following the recommendations of the respective equipment manufacturers, in order to minimize the risk of technical problems
- in the case of critical equipment (whose permanent operation is essential for ensuring the continuity of the data center operation), backup equipment will be provided, which will be used during maintenance operations involving stopping or disconnecting the respective equipment and during periods when the main equipment is affected by technical failures
- the data center must have a scalable structure, both in terms of the computing equipment used and the infrastructure, in order to maintain the system's performance at a constant level if new conditions appear (increasing data center capacity, new facilities, etc.)
- controlled access to the data center equipment used for electronic document archiving, specifying several levels of access rights for the personnel operating the systems
- use of special equipment to avoid and detect physical intrusions
- intrusion detection systems (Intrusion Detection System - IDS)
- firewall (software and/or hardware), routers for traffic filtering
- antivirus systems
- securing authentication and authorization processes for data access
- automatic logging of actions performed in the system
- chronological logging of actions performed in the system (physical access to equipment, switching from one system to another, maintenance processes, operator actions, etc.)
- regular evaluation of the data center infrastructure, security system, and computing equipment used, including backup systems
- use of a quality management system
- evaluation of the effects of expansions and upgrades
- regular auditing of the security plan
- periodic evaluation and improvement of the personnel
- implementation of human resources policies to ensure data center operation by specialized personnel with certifications in the field*