Quick-reference card
| Field | Value |
|---|---|
| Control ID | PE-15 |
| Control Name | Water Damage Protection |
| Framework | NIST SP 800-53, Revision 5 |
| Control Family | Physical and Environmental Protection |
| Baselines | LOW MODERATE HIGH |
| Relevance | Organization (First Party and Third Party) |
| Risk Severity | Low |
What this control requires
PE-15 requires your organization to protect information systems from water damage by installing and maintaining master shutoff or isolation valves that key personnel can quickly locate and operate. Most facility teams treat plumbing infrastructure as a building management concern, but uncontrolled water leakage in a data center or server room can destroy hardware, corrupt storage media, and trigger cascading outages that no amount of redundancy can absorb.
In practice, this control means you need functional shutoff valves positioned where they’re accessible during an emergency, documented procedures that identify who activates them, and a maintenance cadence that confirms the valves actually work. The focus isn’t limited to catastrophic pipe bursts. Even slow leaks from overhead plumbing, condensation from cooling systems, or failed drainage near a raised floor can cause progressive damage that goes unnoticed until equipment fails.
The scope primarily covers facilities with concentrated system resources, including data centers, server rooms, and mainframe computer rooms. Isolation valves let you shut off water to a specific area without disrupting the entire facility, giving you more granular control during an incident. Your NIST SP 800-53 compliance posture depends on demonstrating that these protections exist, function correctly, and are understood by the people responsible for activating them.
Why it matters
Water damage ranks among the most underestimated physical threats to IT infrastructure. Organizations invest heavily in firewalls, endpoint detection, and access controls but overlook the fact that a single plumbing failure in the wrong location can take an entire data center offline. PE-15 exists because the consequences of inaction fall squarely on audit findings and operational continuity.
From a compliance perspective, failing to implement water damage protections exposes your organization to findings during federal audits and third-party assessments. Auditors reviewing the Physical and Environmental Protection family will specifically check whether master shutoff valves exist, whether they’re accessible, and whether key personnel know where they are and how to operate them.
The risk severity is low relative to other controls, but the downstream impact of a water event is disproportionately expensive. Hardware replacement, data recovery, and facility remediation costs compound quickly when water reaches active computing equipment.
What goes wrong without this control
- No shutoff capability during a leak. Without accessible master shutoff or isolation valves, a plumbing failure floods server rooms until building maintenance arrives, potentially hours later.
- Key personnel don’t know valve locations. Even when valves exist, undocumented or poorly communicated locations mean the people who discover the leak can’t act on it.
- Valves fail from neglect. Shutoff valves that haven’t been tested or maintained seize up over time, rendering them useless in an actual emergency.
- Isolation gaps force full-facility shutdowns. Without isolation valves for specific zones, your only option during a leak may be cutting water to the entire building, disrupting operations far beyond the affected area.
How to implement
Most organizations struggle less with the concept of PE-15 than with the follow-through. Valves get installed during construction and then forgotten. Documentation goes stale. Personnel rotate without knowledge transfer. The implementation challenge is sustained operational readiness, not initial deployment.
For your organization
Step 1: Inventory your water infrastructure. Walk every facility that houses concentrated system resources and document all water supply lines, drainage paths, and potential leak sources. Pay special attention to overhead pipes, HVAC condensation lines, and any plumbing that runs through or above server rooms and data centers.
Step 2: Install or verify master shutoff and isolation valves. Confirm that a master shutoff valve exists for each facility’s main water supply. Then install isolation valves for specific high-risk zones so you can cut water to a server room without shutting down an entire floor. Valves should be physically accessible without requiring tools or special access beyond what key personnel already have.
Step 3: Document valve locations and activation procedures. Create a maintained list that identifies every shutoff valve’s physical location, the area it controls, and the steps required to activate it. Include photographs or floor plan markings. Store this documentation where it’s accessible during an emergency, not buried in a shared drive that requires network access you may not have during a water event.
Step 4: Designate and train key personnel. Identify the specific individuals responsible for activating shutoff valves. This group should include facilities staff, on-site security, and IT operations leads. Provide role-based training that covers valve locations, activation procedures, and escalation paths. Training records become audit evidence, so document completion.
Step 5: Establish a testing and maintenance schedule. Test every master shutoff and isolation valve at least annually. Verify that valves open and close properly, that they’re free of corrosion or obstruction, and that labeled signage remains accurate. Log each test with date, tester, valve identifier, and result. Common mistakes include treating valve testing as a one-time commissioning activity rather than a recurring operational task.
Step 6: Integrate with incident response. Your facility incident response procedures should include water damage scenarios with specific instructions for valve activation, equipment power-down sequences, and notification chains.
For your vendors
When assessing whether a vendor meets PE-15, you’re verifying that their facilities protect the systems handling your data from water damage. Self-attestation alone isn’t sufficient for a control this dependent on physical infrastructure.
What to ask in security questionnaires:
- Do your data centers and server rooms have master shutoff valves for water supply lines?
- Are isolation valves installed to allow zone-specific water shutoff without disrupting the full facility?
- Who is responsible for activating shutoff valves, and how are they trained?
- How frequently are shutoff and isolation valves tested, and do you retain maintenance records?
- Can you provide documentation of valve locations and activation procedures?
Evidence to request:
Request the vendor’s physical and environmental protection policy along with their water damage protection procedures. Ask for their most recent valve testing and maintenance logs. If the vendor operates from a colocation facility, confirm whether the colo provider’s supporting utilities controls cover water damage protections, and request evidence from the colo provider directly or through the vendor’s SOC 2 report.
Red flags to watch for:
- The vendor can’t identify who is responsible for water shutoff procedures.
- Valve testing records don’t exist or show gaps longer than 12 months.
- The vendor relies entirely on a building landlord for water infrastructure with no visibility into maintenance status.
- Facilities documentation doesn’t distinguish between general building maintenance and IT-specific environmental protections.
Verification beyond self-attestation: Where possible, request facility tour access or photographs of valve installations and signage. Review SOC 2 Type II reports for physical security findings related to environmental controls. Cross-reference the vendor’s response with their equipment siting and protection practices to confirm consistency.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Policy documentation | Physical and environmental protection policy defining water damage prevention requirements and responsibilities |
| Procedures | Water damage protection procedures specifying valve activation steps, escalation contacts, and post-incident assessment processes |
| Personnel records | List of key personnel with knowledge of master shutoff valve locations and activation procedures, including role assignments and contact information |
| Valve documentation | Master shutoff and isolation valve inventory with physical locations, zone coverage maps, and labeled floor plan diagrams |
| Testing and maintenance logs | Annual valve inspection records documenting test date, valve identifier, functional status, and corrective actions taken |
| Training records | Role-based training completion records for facilities staff and IT operations leads covering valve locations and emergency procedures |
| Facility assessment | Photographs or inspection reports of server rooms and data centers showing valve installations, signage, and accessibility |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 7.11 Supporting utilities | Partial |
| ISO 27001:2022 | 7.5 Protecting against physical and environmental threats | Partial |
| ISO 27001:2022 | 7.8 Equipment siting and protection | Partial |
Related controls
- AT-03 — Role-based Training: ensures that key personnel receive training on their water damage protection responsibilities, including valve locations and activation procedures.
- PE-10 — Emergency Shutoff: covers broader emergency power and system shutoff capabilities that complement water-specific shutoff procedures during facility incidents.
Frequently asked questions
What is NIST SP 800-53 PE-15?
PE-15 is a physical security control that requires organizations to protect information systems from water leakage by maintaining accessible, functional master shutoff or isolation valves known to key personnel. The control applies across LOW, MODERATE, and HIGH baselines, making it a universal requirement for federal systems and any organization using NIST SP 800-53 as its control framework. Your compliance depends on demonstrating that valves exist, work properly, and that designated staff know where they are and how to activate them.
What happens if PE-15 is not implemented?
Without PE-15 implementation, your organization faces audit findings for failing to protect concentrated system resources from water damage. Auditors will flag the absence of master shutoff valves, inaccessible valve locations, or the lack of a documented personnel list as control deficiencies. Beyond compliance, the operational risk is that a plumbing failure in a server room or data center goes uncontrolled because no one can quickly isolate the water supply, leading to extended downtime and costly hardware replacement.
How do you audit PE-15?
Auditors verify PE-15 by inspecting the facility for master shutoff and isolation valves, confirming the valves are accessible and functional, and reviewing the list of key personnel who know valve locations and activation procedures. The assessment includes examining your physical and environmental protection policy, water damage protection procedures, and valve maintenance documentation. Auditors may physically test valve accessibility during a site visit and interview designated personnel to confirm they can describe the shutoff process without relying on written instructions.
What does PE-15(1) automation support require?
PE-15(1) requires organizations to detect the presence of water near information systems and automatically alert key personnel using automated mechanisms. This enhancement moves beyond manual valve management by adding water detection sensors in areas with concentrated system resources, such as under raised floors and near cooling infrastructure. The automated alert must reach designated personnel quickly enough to enable a response before water leakage causes damage to equipment or disrupts operations.