# Source register

Access date for all sources: 2026-09-22.

| ID | Primary or authoritative source | Material use | Limitation |
|---|---|---|---|
| S1 | Ready.gov, “Emergency Plans,” https://www.ready.gov/business/emergency-plans | Supports pairing information-technology disaster recovery with business-continuity planning and preparing communications in advance. | General business-preparedness guidance; it does not prescribe self-storage workflows, service states or outage durations. |
| S2 | Federal Trade Commission, “Protecting Personal Information: A Guide for Business,” https://www.ftc.gov/business-guidance/resources/protecting-personal-information-guide-business | Supports data inventory, data minimization, access limits, secure handling, employee training and advance response planning. | General U.S. business guidance, not legal advice or a finding about any facility. |
| S3 | PCI Security Standards Council, “Maintaining Payment Security,” https://www.pcisecuritystandards.org/merchants/process/ | Supports using approved payment technology, protecting cardholder data, and the instruction not to store sensitive cardholder data on computers or paper. | High-level merchant guidance; an operator must follow its own payment processor, acquiring bank, contract and current PCI obligations. |
| S4 | National Institute of Standards and Technology, “Cybersecurity Framework,” https://www.nist.gov/cyberframework | Supports the Govern, Identify, Protect, Detect, Respond and Recover functions and evidence-led recovery discipline. | A connectivity outage is not automatically a cybersecurity incident. The article uses the recovery principle without claiming compliance, certification or incident status. |

## Evidence boundary

The article presents an operating method. It does not claim that a named facility, company, platform or provider uses the method; it does not report customer results, downtime, recovery time, security findings, compliance or performance. The 35-minute scenario is fictional. Any implementation must be aligned with the operator's emergency plan, privacy policy, payment requirements, contracts and technical procedures.
