{"data":{"id":"PE-17","name":"Alternate Work Site","family":"PE","family_name":"Physical and Environmental Protection","withdrawn":false,"description":"a. Determine and document the [Assignment: organization-defined alternate work sites] allowed for use by employees;\nb. Employ the following controls at alternate work sites: [Assignment: organization-defined controls];\nc. Assess the effectiveness of controls at alternate work sites; and\nd. Provide a means for employees to communicate with information security and privacy personnel in case of incidents.","supplemental_guidance":"Alternate work sites include government facilities or the private residences of employees. While distinct from alternative processing sites, alternate work sites can provide readily available alternate locations during contingency operations. Organizations can define different sets of controls for specific alternate work sites or types of sites depending on the work-related activities conducted at the sites. Implementing and assessing the effectiveness of organization-defined controls and providing a means to communicate incidents at alternate work sites supports the contingency planning activities of organizations.","enhancements":[],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"PE-17","name":"Alternate Work Site","description":"a. Determine and document the [Assignment: organization-defined alternate work sites] allowed for use by employees;\nb. Employ the following controls at alternate work sites: [Assignment: organization-defined controls];\nc. Assess the effectiveness of controls at alternate work sites; and\nd. Provide a means for employees to communicate with information security and privacy personnel in case of incidents.","discussion":"Alternate work sites include government facilities or the private residences of employees. While distinct from alternative processing sites, alternate work sites can provide readily available alternate locations during contingency operations. Organizations can define different sets of controls for specific alternate work sites or types of sites depending on the work-related activities conducted at the sites. Implementing and assessing the effectiveness of organization-defined controls and providing a means to communicate incidents at alternate work sites supports the contingency planning activities of organizations.","related_controls":["AC-17","AC-18","CP-07"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Control text requires determining and documenting allowable alternate work sites New parameter includes specifying alternate work sites Discussion expanded to benefits of assessing effectiveness of applied controls"}},"compliance_mappings":{"iso_27001_2022":["A.5.14","A.6.7","A.7.9"],"iso_27002_2022":["6.7"],"cobit_2019":["DSS01","DSS05"],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":["A1.2"],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":["SS1/21-5.3"],"bsi_grundschutz":["CON.7","INF.1","INF.2","OPS.1.2.4"],"anssi":["Hygiene.37","SecNumCloud.12.1"],"osfi_b13":["B-13.2.6","B-13.3.2"],"finma_circular":["IV.E(89)","IV.E(90)"],"gdpr":["Art.32(1)(b)"],"dora":[],"bio2":["6.7"],"rbi_csf":["ITGRCA.20"],"fisc":["FISC.F5"],"lgpd_bcb":[],"hkma_tme1":["TME1.5.1","TME1.6.4","TME1.8.5"],"mlps_2":[],"dnb_good_practice":["DNB.11.3"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-10"],"nca_ecc":["1-11","2-6"],"qatar_nia":["PS"],"sama_csf":["3.7"],"uae_ia":["T6"],"bog_cisd":["CISD-XIV"],"bom_ctrm":["3.5"],"cbe_csf":["CTO-10"],"cbn_csf":["Part10"],"sa_js2":["JS2-PE"],"bot_cyber":["Ch2.8"],"cpmi_pfmi":["CG.RR","PFMI.P17"],"eba_ict":["3.4.3"],"ecb_croe":["CROE.2.3.6","CROE.2.5.2"],"ffiec_is":["II.C.8"],"iosco_cyber":["PROT-5"],"sebi_cscrf":["PR.PE"],"cmmc_2":["PE"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["01.d","05.c"],"iso_27799":["6.3"],"lloyds_ms":["PHYS.1"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.5"],"owasp_masvs_v2":[],"csa_ccm_v4":["HRS-04"],"csa_aicm":["HRS-04"],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.5.14, A.7.9 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-015"]}}