{"data":{"id":"PE-10","name":"Emergency Shutoff","family":"PE","family_name":"Physical and Environmental Protection","withdrawn":false,"description":"a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations;\nb. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system or system component] to facilitate access for authorized personnel; and\nc. Protect emergency power shutoff capability from unauthorized activation.","supplemental_guidance":"Emergency power shutoff primarily applies to organizational facilities that contain concentrations of system resources, including data centers, mainframe computer rooms, server rooms, and areas with computer-controlled machinery.","enhancements":[{"id":"PE-10(01)","name":"Accidental and Unauthorized Activation","withdrawn":true,"incorporated_into":["PE-10"]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"PE-10","name":"Emergency Shutoff","description":"a. Provide the capability of shutting off power to [Assignment: organization-defined system or individual system components] in emergency situations;\nb. Place emergency shutoff switches or devices in [Assignment: organization-defined location by system or system component] to facilitate access for authorized personnel; and\nc. Protect emergency power shutoff capability from unauthorized activation.","discussion":"Emergency power shutoff primarily applies to organizational facilities that contain concentrations of system resources, including data centers, mainframe computer rooms, server rooms, and areas with computer-controlled machinery.","related_controls":["PE-15"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Adds parameter for specifying applicable system or individual system components"}},"compliance_mappings":{"iso_27001_2022":["A.7.5","A.7.11"],"iso_27002_2022":["7.5","7.11"],"cobit_2019":["DSS01","DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.IR-02"],"cis_controls_v8":[],"soc2_tsc":["A1.2"],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["INF.1","INF.2"],"anssi":["Hygiene.38","SecNumCloud.12.3"],"osfi_b13":["B-13.2.6"],"finma_circular":["IV.E(89)"],"gdpr":[],"dora":[],"bio2":["7.5","7.11"],"rbi_csf":["Annex1.3","ITGRCA.18"],"fisc":["FISC.F2"],"lgpd_bcb":[],"hkma_tme1":["TME1.5.1"],"mlps_2":[],"dnb_good_practice":["DNB.18.1"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-10"],"nca_ecc":["1-11"],"qatar_nia":["PS"],"sama_csf":["3.7"],"uae_ia":["T6"],"bog_cisd":["CISD-XIV"],"bom_ctrm":["3.5"],"cbe_csf":["CTO-10"],"cbn_csf":["Part10"],"sa_js2":["JS2-PE"],"bot_cyber":["Ch2.8"],"cpmi_pfmi":["PFMI.P17"],"eba_ict":["3.4.3"],"ecb_croe":["CROE.2.3.6"],"ffiec_is":["II.C.8"],"hipaa_sr":["§164.308(a)(7)(ii)(C)","§164.310(a)(2)(i)"],"iosco_cyber":["PROT-5"],"sebi_cscrf":["PR.PE"],"cmmc_2":["PE"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":["Clause 4"],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["08.b"],"iso_27799":[],"lloyds_ms":["PHYS.1"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.5"],"owasp_masvs_v2":[],"csa_ccm_v4":["DCS-14"],"csa_aicm":["DCS-14"],"ccss_v9":["1.03.3"],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-002"]}}