← Controls / PE

PE-11 Emergency Power

Physical and Environmental Protection

Moderate High

Description

Provide an uninterruptible power supply to facilitate [Selection (one or more): an orderly shutdown of the system; transition of the system to long-term alternate power] in the event of a primary power source loss.

Supplemental Guidance

An uninterruptible power supply (UPS) is an electrical system or mechanism that provides emergency power when there is a failure of the main power source. A UPS is typically used to protect computers, data centers, telecommunication equipment, or other electrical equipment where an unexpected power disruption could cause injuries, fatalities, serious mission or business disruption, or loss of data or information. A UPS differs from an emergency power system or backup generator in that the UPS provides near-instantaneous protection from unanticipated power interruptions from the main power source by providing energy stored in batteries, supercapacitors, or flywheels. The battery duration of a UPS is relatively short but provides sufficient time to start a standby power source, such as a backup generator, or properly shut down the system.

Enhancements (2)

What NIST adds to this control. Select one to read its statement.

PE-11(01) Alternate Power Supply — Minimal Operational Capability High

Provide an alternate power supply for the system that is activated [Selection (one): manually; automatically] and that can maintain minimally required operational capability in the event of an extended loss of the primary power source.

PE-11(02) Alternate Power Supply — Self-contained

Provide an alternate power supply for the system that is activated [Selection (one): manually; automatically] and that is: a. Self-contained; b. Not reliant on external power generation; and c. Capable of maintaining [Selection (one): minimally required operational capability; full operational capability] in the event of an extended loss of the primary power source.

Patterns that use this control (1)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.7.5A.7.11

ISO 27002:2022

7.57.11

COBIT 2019

DSS01DSS05

NIST CSF 2.0

PR.IR-02PR.IR-04

SOC 2 TSC

A1.2

CSA CCM v4

BCR-11DCS-14

CSA AICM v1

BCR-11DCS-14

BSI IT-Grundschutz

INF.1INF.2

ANSSI

Hygiene.38SecNumCloud.12.3

FINMA Circular 2023/1

IV.A(28)IV.E(89)

OSFI B-13

B-13.2.6

BIO2

7.57.11

RBI CSF

Annex1.3ITGRCA.18

FISC Security Guidelines

FISC.F2

HKMA TM-E-1

TME1.5.1

MLPS 2.0

8.1.1.8

DNB Good Practice

DNB.18.1

SAMA CSF

3.7

NCA ECC

1-11

UAE IA

T6

CBB TM

TM-10

Qatar NIA

PS

CBE CSF

CTO-10

SA JS2

JS2-PE

CBN CSF

Part10

BoG CISD

CISD-XIV

BoM CTRM

3.5

IOSCO Cyber Resilience

PROT-5

CPMI-IOSCO PFMI

CG.RRPFMI.P17

FFIEC IS

II.C.8

HIPAA Security Rule

§164.308(a)(7)(ii)(C)§164.310(a)(2)(i)

ECB CROE

CROE.2.3.6CROE.2.5.2

EBA ICT Guidelines

3.4.3

SEBI CSCRF

PR.PE

BOT Cyber Resilience

Ch2.8

CMMC 2.0

PE

10 CFR 73.54

RG5.71-B-PE

API 1164

Sec 14

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.5

Lloyd's Minimum Standards

PHYS.1

HITRUST CSF v11

08.b09.b

ISO 27799

17.3

Basel SCO60

SCO60.53SCO60.65

BSSC Standards

NOS-09

ISO 17799 (legacy)

9.2.2

COBIT 4.1 (legacy)

DS12.4