8 min

Preparing a server room for information system attestation

Practical server room preparation for attestation, covering the room, access, power, logs, documents, and a pre-inspection review.

Preparing a server room for information system attestation

Attestation fails less often because a polished policy binder is missing than because the documents contradict what an inspector sees in the server room. If an order authorizes four employees but the controller accepts twelve cards, that discrepancy becomes a finding. The same logic applies to power diagrams, equipment inventories, maintenance logs, and backup records.

Preparation should move from the boundaries of the attestation object to every physical and documentary piece of evidence. First, fix the scope of the information system, sites, integrations, and accountable people. Next, test the room and its utility systems under load, then compare the logs with actual operations. Renovating a server room without this sequence often spends the budget while leaving the original problem untouched.

This guide addresses practice in Kazakhstan. The main references are the Rules for Attestation approved by Government Resolution No. 298, the Uniform Requirements for ICT and Information Security approved by Resolution No. 832, and the Attestation Examination Methodology. Regulations change, so the working group must check the applicable edition, object class, and industry requirements before filing an application.

The object boundary determines the inspection scope

You cannot prepare the server room separately from the information system. Inspectors compare the physical site with the declared hardware and software complex, networks, security controls, and integrations. Begin with a one-page boundary map. It should show the primary and backup sites, servers and storage systems, network nodes, security appliances, communication links, external services, administrator workstations, and every exchange point with other informatization objects.

First, establish whether attestation is mandatory for your system. The Rules under Resolution No. 298 include, among mandatory objects, information systems of government bodies, systems of state legal entities, and non-state systems that integrate with a government body's system or generate state electronic information resources, as well as critical information and communication infrastructure objects. Other non-state systems may seek voluntary attestation. This distinction is practical: the legal basis determines the participants, applicable documents, and permitted hosting locations.

Next, record the object class and hosting model. For government body objects, the requirements for primary and backup sites depend on the class. A rented data center does not remove the system owner's duties. The contract, responsibility matrix, and operating evidence must answer the same questions that an inspector would ask in an in-house server room. The statement "the provider handles it" proves nothing without a contract appendix, test report, or log export.

Treat virtualization separately. A hypervisor may hide a physical server from the application diagram, but it does not move that server outside the examination boundary. If one cluster hosts several systems, show the logical separation, identify who administers the shared platform, and state which common failures would affect the attestation object. Do not confuse the business function boundary with the infrastructure boundary. The first explains the system's purpose; the second shows which components actually process and transmit protected information.

The result should be an approved inventory in which every component has an inventory or serial number, purpose, owner, physical location, firmware or system software version, and a reference to the diagram. If a rack contains a device absent from the inventory, resolve it before the examination. If the inventory still lists a retired server, remove the entry through the established procedure and retain the basis for the change.

The room must exclude predictable threats

A server room meets the requirements only when its location and construction keep out through traffic, dust, water, and uncontrolled utilities. The Uniform Requirements call for a separate, non-passage room without window openings. Existing windows must be covered or sealed with non-combustible materials. Surfaces must not release or accumulate dust, the flooring must have antistatic properties, and the enclosing structures must provide a sealed room.

Inspect the route to the room as carefully as the room itself. Under the Uniform Requirements, the door must be at least 1.2 m wide and 2.2 m high, open outward or slide, and have no threshold or central post in the frame. These dimensions allow equipment to enter and leave safely. A narrow corridor in front of a compliant door can make the actual route unusable, so measure the entire path from the unloading area to the rack.

Transit pipes for ordinary and fire water supply, heating, and sewerage must not pass through the server room or above it on the same floor. Inspect the space above the suspended ceiling and below the raised floor, not only the visible part of the room. A common failure is mundane: the drawing shows a clean zone, but an old pipe crosses above the end rack after an undocumented remodel. A ceiling photograph does not replace an as-built utility plan.

Use the raised floor or suspended ceiling for cabling and utility lines, not for storage. Boxes, removed disks, packaging, cans, and cleaning supplies raise the fire load, hide leaks, and obstruct maintenance. Set aside a separate location near the server room for critical spare parts, as required by the Uniform Requirements, and keep an inventory of it.

Rack placement must account for equipment and cable weight, clear service aisles, airflow, and cable routes. Obtain evidence of the allowable floor and raised-floor load, then compare it with the weight of fully populated racks, UPS units, and batteries. "The floor looks strong" has no evidentiary value. You need a calculation, a construction data sheet, or an opinion from a competent organization that applies to the installed configuration.

Create a floor plan showing the controlled-zone boundary, doors, camera coverage, sensors, cooling units, extinguishing modules, power feeds, grounding bus, and emergency shutdown points. The plan saves time during an examination, but its main benefit comes earlier. While placing each object on the plan, the team almost always finds a blind spot, an unlabeled breaker, or a sensor missing from the operating inventory.

Access must leave verifiable evidence

The access control system must provide authorized entry and exit, and the authorized-person list must match active identifiers. Compare the entire chain rather than surnames in two spreadsheets: the access order or request, area-owner approval, card issuance, controller record, passage event, periodic review, and revocation after a transfer or dismissal.

Indefinite contractor access is a frequent error. A technician came to replace an air conditioner last year, the work closed, but the card still works. Give temporary access an expiry time at issuance, name the escort, and set permitted time windows. Define emergency access in advance as well: who may approve entry, how staff identify a technician arriving at night, and who reviews the records on the next business day.

The Uniform Requirements specifically state that the entrance design must prevent an access identifier from being passed back through the vestibule. In practice, inspectors look beyond the reader to the door closer, lock, position sensor, exit button, emergency release, and the guard response. A door held open turns an expensive access system into decoration even while the controller records events correctly.

Cameras must cover all entrances and exits plus the space and aisles near equipment, with images displayed at a dedicated console in a continuously staffed security room. Test the actual view with the door both closed and open, recording quality under normal lighting, clock synchronization, archive access, and the retention period approved by the organization under applicable requirements. Do not guess a period. Show the document that establishes it, the recorder setting, and the oldest available recording.

Run one test visit as an end-to-end scenario. An authorized employee enters, performs registered work, and leaves. The reviewer then connects the request, two access-control events, the video segment, and the work-log entry on one timeline. If the clocks differ by seven minutes or the log says only "technical work," the evidence falls apart. Time synchronization and meaningful records cost less to fix before the application.

A paper visitor log can form part of the process, but it cannot repair a weak access system. The entry should record date and time, visitor identity, organization, reason for the visit, escort, area, and departure time. Do not collect extra personal data without a defined purpose and retention period. The process owner should be able to produce records for a requested period and explain every exception, including an emergency door release.

Power and climate control are tested by failure

Simply having a UPS, generator, and air conditioners does not prove readiness. You need calculations, diagrams, maintenance records, and tests under a credible load. The Uniform Requirements call for two power feeds from separate external sources at 400/230 V and 50 Hz, an independent generator, and automatic transfer switching. The server room equipment and systems receive power through UPS units, whose capacity accounts for the full load and room for growth.

Build a single-line diagram from the external feeds to the rack power distribution units. Mark the automatic transfer switch, generator, UPS, bypass, protective devices, emergency shutdown, and utility-system loads. Then compare labels on the diagram, switchboards, cables, and racks. A breaker naming mismatch looks minor until the on-call engineer disconnects the wrong line.

The UPS autonomy calculation must cover the transfer to backup feeds and generator startup. A battery data-sheet figure says little without a current test because capacity declines, temperature affects batteries, and the load changes when new servers arrive. Record the test date, initial load, loss of the main feed, generator start time, lowest charge, alarms, and return to the normal supply. If a full failure test would be unsafe, agree on a controlled method with the electrical-authority personnel and document its limitations.

The server room's functional grounding is separate from the building's protective grounding. Bond metal structures to the common grounding bus and connect each rack with its own conductor. Have a qualified specialist measure the parameters and issue a report that identifies an instrument with current calibration. A label on a yellow-green wire proves only that a label exists.

Measure climate conditions where the equipment operates, not with one thermometer by the door. Monitoring should observe conditions in cabinets and racks, and thresholds should follow installed-equipment requirements and design decisions. Compare sensors with a reference instrument, create an alarm safely, and trace the notification to the on-call person. Record who responds, the internal response target, and the action required after one cooling unit fails.

Do not claim N+1 resilience if no one has tested the loss of one component. The Uniform Requirements set server room infrastructure availability at no less than 99.7 percent. To manage that figure, the organization must define a failure, establish the source of downtime data, and assign someone to verify the calculation. Otherwise the percentage remains a number in a document that the logs cannot reproduce.

Fire, water, and cabling need separate evidence

Support available across the country
GSE's nationwide service network helps maintain the server room after equipment enters operation.
Discuss a project

Server room fire protection must work as one sequence of detection, warning, shutdown, and safe gas removal. The Uniform Requirements call for an automatic gas extinguishing installation independent of the building system. Powder and liquid extinguishing agents are not used. Early smoke detection and manual detectors at the exit initiate the sequence, and the extinguishing-agent release delay may not exceed 30 seconds.

Test the entire sequence without releasing gas unless the approved test procedure requires otherwise. A detector generates a signal, signs inside and outside warn people, ventilation dampers close, equipment power shuts down according to the design, security receives the event, and the responsible person follows the instruction. A service certificate saying "system operational" is weaker than a report listing the inputs, outputs, delays, and faults actually tested.

Check the exhaust ventilation used to remove extinguishing gas and the arrangements for staff safety. The door should make the evacuation procedure and the ban on re-entry clear until the responsible person gives permission. Update phone lists after staffing changes. An instruction that names a departed manager first is dangerous and takes one phone call to expose.

Label cable routes at both ends and reconcile them with the diagrams. Route power and telecommunications cables in accordance with the design requirements, seal penetrations, and close unused openings. Find temporary patch cords, extension leads, and unlabeled connections. Temporary arrangements tend to remain for years until a nighttime failure forces someone to discover what they serve.

Document maintenance of critical equipment. The Uniform Requirements explicitly name equipment servicing, troubleshooting, failures and outages, restoration results, and post-warranty support. Certified technical personnel perform the work, and intervention in operating equipment requires permission from the head of the IT unit or a deputy. Link every service report to a request, approval, technician, affected assets, time, result, and post-work check.

When a site needs modernization, GSE.kz can combine server hardware, system integration, and data center infrastructure with continuous nationwide technical support after delivery. The competent authority still makes the attestation decision, while the system owner remains responsible for complete internal processes and records.

Documents must describe one real server room

The document set is ready when another administrator can reproduce the operating rules from it, not when every file merely has a signature. The annex to the Rules under Resolution No. 298 lists an information security policy, risk assessment method, rules for asset records, continuity, inventory, internal audit, access control, authentication, antivirus controls, physical protection, an administrator guide, a backup and recovery procedure, and instructions for incident and crisis response. Systems using cryptographic protection need the corresponding rules as well.

Do not copy that list into local documents without assigning responsibility. Build a matrix with the fields "requirement, document, clause, owner, evidence." For physical access, evidence may be an access-system export and an authorization review. For power, use a diagram and transfer-test report. For backup, use a job record and recovery result. For maintenance, use a request and service report. An empty cell identifies real work rather than an editorial omission.

Check identifiers horizontally across the set. The system name, owner, operator, site address, room numbers, roles, and department names must match in every order, diagram, and procedure. After a move, the old address often remains in the continuity plan. After a reorganization, a nonexistent unit stays in the access procedure. After a UPS replacement, the former model remains in the equipment passport. An inspector does not have to guess which document is correct.

Every document needs approval, version, effective date, owner, review procedure, and change history. A review interval does nothing if the owner records no result. A dated, signed note stating "reviewed, no changes" is better than a silent file left in a shared folder for four years.

A rented facility requires a clear division of duties. State in the contract appendix who maintains access control, cameras, the generator, UPS, fire suppression, and cooling; who provides logs; who reports an incident; who admits the examination team; and how changes are approved. Obtain actual reports and exports before the self-assessment. A provider's management-system certificate does not prove that a particular door closes or that the selected camera retains recordings for the required period.

Keep an approved copy of the package submitted for attestation. Working documents may change, but the team must know which version the inspectors received. If a correction is necessary, process it through change management and assess its effect on the object boundary. Silently replacing a diagram the night before the visit creates more questions than a transparent correction log.

Logs prove that controls work over time

Capacity for the operating load
S200 servers form part of an infrastructure solution shaped around your information system.
Choose a solution

A log exists to reconstruct an event and the accountable person's decision, not to satisfy a line in an inventory. The minimum set depends on the architecture and local rules, but a server room commonly generates access-control records, video, climate and power alarms, fire and security alarms, maintenance, visitor, incident, change, backup, and system-monitoring records.

Create a six-field profile for each log: owner, time source, event coverage, storage location, retention period, and review method. Add integrity controls and the list of people who may delete or modify records. If a log sits on the same server whose failure it must explain, send or copy it to an independent node in line with the chosen architecture.

Events from different systems must form one timeline. Configure a common trusted time source for servers, network devices, access control, cameras, and utility monitoring, then monitor drift. A camera clock that continually runs fast will damage an investigation despite perfect image quality. After restarting a controller, verify not only access but also the retained time and event queue.

Do not collect successful events alone. Access records need denials, repeated attempts, a door held open, forced opening, communication loss, and operator actions. Power records need battery and generator transfers, bypass, overload, and battery faults. Climate records need threshold breaches, lost sensors, and alarm acknowledgements. Exceptions demonstrate that a control detects a problem and triggers action.

Select one ordinary operating month and sample five different event types. For each, find the source record, notification, staff response, closure, and related document. If a temperature alarm exists but no response was recorded, do not backfill the log. Register the nonconformity, fix the cause, and collect a new operating history.

Do not assign one universal retention figure to every record. Applicable rules, the log's purpose, risk assessment, investigation needs, and internal documents determine the period. The declared period must match the technical setting and the archive actually available. Test retrieval of an archived record, administrator rights, and system behavior when the disk becomes full.

Self-assessment should follow the examination logic

A server room needs one infrastructure
GSE combines servers, data center infrastructure, and system integration within one project.
Discuss a project

A useful self-assessment follows evidence and observable actions because the Attestation Examination Methodology evaluates physical protection, access, external threats, server room work, equipment placement, utility services, cabling, maintenance, and secure disposal as distinct processes. The examination team does not need a tour of the strongest controls. It needs an unbroken control chain, including awkward exceptions.

Run the self-assessment in this order:

  1. Freeze the component inventory and diagram for one day, then physically locate every sampled asset and connection.
  2. Follow a visitor from request to departure, including video, escort, and revocation of temporary access.
  3. Trigger safe test alarms for access control, climate, and utility monitoring, then trace notification and response.
  4. Perform an approved power transfer and a recovery from backup, preserving source data, timings, and results.
  5. Select a recent maintenance task, change, and incident, then assemble the complete chain of requests, approvals, logs, and closure for each.

Include an information security specialist, system administrator, facility engineer, security representative, and business-process owner in the review group. Have someone who does not operate a particular control examine its evidence. An internal owner easily fills a missing step from memory, while an outside inspector sees only the record and observable action.

Record nonconformities with the fields requirement, fact, risk, corrective action, owner, due date, closure evidence, and retest. Do not mark an item complete when equipment has merely been purchased. Closure means the device is installed, added to diagrams and inventories, tested, placed under maintenance, and understood by the staff who respond to its alarm.

Separate blocking defects from manageable ones. A missing required fire suppression system or second power feed cannot be corrected with a new instruction. A mismatched role name can be corrected in documents, but first check whether it conceals an actual gap in accountability. Applicable requirements and risk set the priority, not ease of correction.

After closing the register, repeat the sample with different dates and assets. One perfectly prepared contractor visit does not prove a stable process. You need a history showing that ordinary employees have followed the same procedure for months without staging it for an inspection.

Fix the state and change rules before the visit

A few days before the examination, stop decorating the room and fix the verified state while restricting unapproved changes. The Rules under Resolution No. 298 describe attestation as application intake and package review, attestation examination, commission review, and a decision by the competent authority. The examination covers documentation, organizational controls, technical protection, and object components, so an unexpected device replacement affects several parts of the evidence at once.

Approve a short stability window. Every configuration, access, power-diagram, network-connection, or equipment change goes through the appointed coordinator, receives an impact assessment, and appears in the current package. Emergency work remains allowed, but staff must record it immediately under the established procedure. A hidden repair is more dangerous than the outage itself.

Build an evidence index instead of another thick binder. For each Methodology item, identify the document, accountable person, and a ready example record. Prepare controlled access to electronic logs and video archives, test demonstration accounts, check security-team communication devices, and ensure that panels an inspector may ask to see can be opened safely.

Hold a 30-minute briefing for the participants. Everyone should know the object boundary, their role, the procedure for escorting inspectors, and the answer rule: show facts rather than speculate. If an employee does not know, they call the control owner instead of inventing an explanation. Name one request coordinator so departments do not hand over conflicting versions of diagrams and orders.

The work does not end when the attestation certificate is issued. Its validity depends on unchanged operating conditions, functionality, the hardware and software complex, and the technologies that determine the security of protected information. Material system development requires an impact assessment and the actions required by current law and rules. Keep the evidence register as an operating tool, because the next examination begins on the date of the first change, not one week before the next visit.

FAQ

Which information systems require attestation in Kazakhstan?

The requirement depends on the owner, integrations, purpose, and designation as a critical ICT infrastructure object. Compare the system with the list in the Rules under Resolution No. 298 and confirm the conclusion with the person accountable for compliance before planning the work.

Can a system in a rented data center receive attestation?

Renting a facility does not prevent attestation if the hosting model is permitted for the object class. The contract and its appendix must allocate duties and provide access to logs, test reports, and the facility itself.

Must windows be removed from an existing server room?

The Uniform Requirements call for a room without window openings. If windows already exist, cover or seal them with non-combustible materials while observing the sealing and design requirements.

Which server room logs do inspectors most often request?

They usually need access and visitor records, video archives, climate and power alarms, maintenance, incidents, changes, and backup records. The exact set follows the system boundary and local documents, and each log should prove the response as well as the event.

Can a data center certificate replace utility-system checks?

No. A certificate may confirm a management system or certification scope, but not the state of a particular door, camera, power line, or archive during the selected period. Request evidence for the specific facility and services.

How much UPS autonomy is required for attestation?

The Uniform Requirements tie autonomy to transfer time for backup feeds and generator startup instead of setting one figure for every facility. Calculate the actual load, measure battery condition, and support the scenario with a test report.

Can the visitor log exist only on paper?

A paper log can form part of the established process if its entries are complete, protected, and available for review. It does not replace working access control, video surveillance, and revocation of electronic permissions.

What should we do when self-assessment finds a nonconformity?

Record the fact, risk, action, owner, and deadline, then collect closure evidence and retest the control. Do not rewrite the past: a new and honest operating history is stronger than a fabricated old one.

Should the generator and fire suppression be tested before inspection?

Confirm their operation through a safe, approved method. Generator evidence should cover transfer under a credible load; fire protection tests normally verify signals and automation without a gas release unless the procedure requires otherwise.

When do changes require a new attestation?

Material changes to operating conditions, functionality, the hardware and software complex, or security technologies require a formal assessment under current rules. Use change management to decide before implementation whether notification or repeat attestation is necessary.