Improve vulnerability management processes to ensure system changes occur within organization timelines.
Develop and approve an authorization to operate for the special-purpose systems.
Include system personnel during the security categorization process to ensure that all necessary information types are considered when determining the security categorization for special-purpose systems.
Implement the appropriate physical security controls to restrict and monitor access to the facility, its server room, communication closets, and generators.
Implement and monitor emergency power and uninterruptible power supplies that support information technology resources.
Validate that appropriate physical and environmental security measures are implemented and functioning as intended.