← Controls / PE

PE-17 Alternate Work Site

Physical and Environmental Protection

Moderate High

Description

a. Determine and document the [Assignment: organization-defined alternate work sites] allowed for use by employees; b. Employ the following controls at alternate work sites: [Assignment: organization-defined controls]; c. Assess the effectiveness of controls at alternate work sites; and d. Provide a means for employees to communicate with information security and privacy personnel in case of incidents.

Supplemental Guidance

Alternate work sites include government facilities or the private residences of employees. While distinct from alternative processing sites, alternate work sites can provide readily available alternate locations during contingency operations. Organizations can define different sets of controls for specific alternate work sites or types of sites depending on the work-related activities conducted at the sites. Implementing and assessing the effectiveness of organization-defined controls and providing a means to communicate incidents at alternate work sites supports the contingency planning activities of organizations.

Changes from Rev 4

Control text requires determining and documenting allowable alternate work sites New parameter includes specifying alternate work sites Discussion expanded to benefits of assessing effectiveness of applied controls

Patterns that use this control (1)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.5.14A.6.7A.7.9

ISO 27002:2022

6.7

COBIT 2019

DSS01DSS05

SOC 2 TSC

A1.2

CSA CCM v4

HRS-04

CSA AICM v1

HRS-04

PRA Operational Resilience

SS1/21-5.3

BSI IT-Grundschutz

CON.7INF.1INF.2OPS.1.2.4

ANSSI

Hygiene.37SecNumCloud.12.1

FINMA Circular 2023/1

IV.E(89)IV.E(90)

OSFI B-13

B-13.2.6B-13.3.2

EU GDPR

Art.32(1)(b)

BIO2

6.7

RBI CSF

ITGRCA.20

FISC Security Guidelines

FISC.F5

HKMA TM-E-1

TME1.5.1TME1.6.4TME1.8.5

DNB Good Practice

DNB.11.3

SAMA CSF

3.7

NCA ECC

1-112-6

UAE IA

T6

CBB TM

TM-10

Qatar NIA

PS

CBE CSF

CTO-10

SA JS2

JS2-PE

CBN CSF

Part10

BoG CISD

CISD-XIV

BoM CTRM

3.5

IOSCO Cyber Resilience

PROT-5

CPMI-IOSCO PFMI

CG.RRPFMI.P17

FFIEC IS

II.C.8

ECB CROE

CROE.2.3.6CROE.2.5.2

EBA ICT Guidelines

3.4.3

SEBI CSCRF

PR.PE

BOT Cyber Resilience

Ch2.8

CMMC 2.0

PE

Solvency II

EIOPA-ICT-4.5

Lloyd's Minimum Standards

PHYS.1

HITRUST CSF v11

01.d05.c

ISO 27799

6.3

ISO 17799 (legacy)

11.7.2

COBIT 4.1 (legacy)

None.