Quick-reference card
| Field | Value |
|---|---|
| Control ID | PE-11 |
| Control Name | Emergency Power |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Physical and Environmental Protection |
| Baselines | MODERATE HIGH |
| Implementation Level | Organization |
| Relevance | First Party and Third Party |
| Risk Severity | Low |
What this control requires
PE-11 requires your organization to provide an uninterruptible power supply (UPS) that keeps critical systems running long enough to either shut down gracefully or switch to long-term backup power. The control exists because even a brief power loss can corrupt data, disrupt operations, and create security gaps that persist well after the lights come back on.
In practice, this means you need more than a generator sitting in a parking lot. A UPS delivers near-instantaneous protection using stored energy from batteries, supercapacitors, or flywheels. Its purpose isn’t to run your data center indefinitely. Instead, it bridges the gap between the moment main power fails and the moment a standby power source, such as a backup generator, takes over. Without that bridge, systems experience uncontrolled shutdowns that can damage hardware, corrupt databases, and leave security tools offline.
The NIST SP 800-53 framework specifically frames this as a selection-based requirement. Your organization must decide whether the UPS supports an orderly shutdown of the system or a full transition to long-term alternate power. That decision should align with your business continuity objectives and the criticality of the systems being protected.
Why it matters
Most organizations treat emergency power as a facilities concern rather than a security control. That disconnect shows up in audits when security teams can’t produce evidence that UPS systems are tested, maintained, or scoped to cover the systems that matter.
But the compliance risk is concrete. PE-11 is included in both the MODERATE and HIGH NIST SP 800-53 baselines, meaning any organization building a system security plan against those baselines must address it. Auditors will look for documentation proving your UPS exists, covers the right systems, and has been tested within a defined interval. Missing or outdated test records are a common finding that can delay an authority to operate.
Specifically, when emergency power controls are absent or poorly maintained, the security implications extend beyond simple downtime. Uncontrolled shutdowns can disable firewalls, intrusion detection systems, and logging infrastructure, creating windows where malicious activity goes unrecorded.
What attackers exploit
- Power-dependent security controls going offline: firewalls, cameras, access control systems, and SIEM platforms that lose power stop providing protection and visibility simultaneously
- Data corruption from uncontrolled shutdowns: databases and file systems left in inconsistent states can expose sensitive records or create integrity gaps
- Delayed incident detection: when logging infrastructure loses power, attackers gain unmonitored windows to operate freely
- Physical security gaps during outages: electronic locks, badge readers, and surveillance systems that lack backup power create physical entry points
- Recovery confusion: organizations without tested power failover procedures spend critical time troubleshooting infrastructure instead of monitoring for threats
How to implement
The biggest implementation mistake is treating PE-11 as a one-time procurement exercise. Buying a UPS is step one. Keeping it tested, properly scoped, and documented is where most organizations fall short.
For your organization
Start by inventorying every system that falls within your authorization boundary and determining which ones require uninterruptible power protection. Your compliance checklist should prioritize systems where an uncontrolled shutdown would cause data loss, compromise security monitoring, or violate your contingency plan.
Once you’ve identified in-scope systems, decide whether each needs orderly shutdown capability or full transition to long-term alternate power. Systems supporting real-time operations or critical security functions typically need the latter. Back-office systems may only need enough battery runtime for a clean shutdown.
Specifically, when selecting and deploying UPS equipment, size the battery capacity to match the load and the expected generator start time (or shutdown sequence duration). Undersized UPS units are a frequent audit finding. Document the rated runtime under actual load conditions, not just the manufacturer’s specifications.
Build a testing schedule into your maintenance program. UPS systems degrade over time as batteries age. Quarterly load tests and annual full-discharge tests are common practices. Record the results and retain them as evidence. Auditors reviewing your PE family controls will expect to see test records with dates, pass/fail outcomes, and remediation actions for any failures.
In practice, this means your system security plan should explicitly name the UPS systems protecting in-scope assets, document the failover strategy (shutdown versus transition), and reference the testing procedures. Update this documentation whenever you add systems, replace equipment, or change your continuity objectives.
For your vendors
When assessing a vendor’s emergency power posture, your goal is to confirm that their critical infrastructure, including the systems processing your data, won’t experience uncontrolled outages that compromise availability or integrity.
Start with your vendor risk questionnaire. Ask whether the vendor maintains UPS protection for systems within the scope of your engagement. Request specifics about the UPS configuration, including battery runtime, load capacity, and whether the UPS supports orderly shutdown or transition to generator power.
But questionnaire responses alone aren’t sufficient. Request supporting evidence such as UPS test records from the past 12 months, the vendor’s emergency power policy, and any relevant sections of their system security plan. A vendor that can produce recent test records with documented pass/fail outcomes demonstrates operational maturity. A vendor that can only point to a purchase order from three years ago is a red flag.
Specifically, when reviewing vendor documentation, look for gaps between what the policy says and what the test records show. A policy requiring quarterly UPS testing paired with test records from 18 months ago signals a control that exists on paper but not in practice. Also verify that the vendor’s UPS coverage extends to the physical infrastructure supporting your data, not just their primary data center equipment.
Where this breaks down is with vendors using shared hosting or cloud infrastructure. In those cases, the vendor may rely on the cloud provider’s power infrastructure. Ask the vendor to confirm how emergency power is addressed in their supply chain and whether they’ve reviewed their provider’s SOC 2 report for relevant physical security controls.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Emergency power policy | Physical and environmental protection policy defining UPS requirements, coverage scope, testing frequency, and roles responsible for maintenance |
| UPS inventory and specifications | Documentation listing each UPS unit, rated capacity, battery type, expected runtime under load, and the systems it protects |
| UPS test records | Quarterly and annual test logs showing date, load tested, duration, pass/fail results, and corrective actions taken for failures |
| System security plan (PE-11 section) | SSP section documenting the failover strategy (orderly shutdown or transition to alternate power) for each in-scope system |
| Contingency plan integration | Contingency plan sections referencing emergency power procedures, generator start sequences, and coordination with UPS failover |
| Maintenance and replacement records | Service records for battery replacements, firmware updates, and vendor maintenance visits with dates and outcomes |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 7.11 Supporting utilities | Partial |
Related controls
- AT-03 — Role-based Training: ensures personnel responsible for UPS maintenance and emergency power procedures receive training on their specific roles during power events
- CP-02 — Contingency Plan: defines the broader continuity strategy that PE-11’s emergency power capability supports, including failover sequencing and recovery priorities
- CP-07 — Alternate Processing Site: addresses long-term continuity when primary facilities lose power beyond what UPS and generators can sustain
Frequently asked questions
What is NIST SP 800-53 PE-11?
PE-11 is a physical and environmental protection control that requires organizations to deploy an uninterruptible power supply for systems within their authorization boundary. The UPS must support either an orderly shutdown or a transition to long-term alternate power when the primary power source fails. This control appears in both the MODERATE and HIGH baselines of NIST SP 800-53 Revision 5. It’s focused on bridging the gap between power loss and generator activation or clean system shutdown.
What happens if PE-11 is not implemented?
Without an uninterruptible power supply, systems experience uncontrolled shutdowns during power failures, which can corrupt databases, disable security monitoring tools, and create gaps in audit logs. Auditors reviewing your system security plan will flag the absence of documented UPS coverage and test records as a control deficiency. For organizations pursuing an authority to operate, a missing PE-11 implementation can delay or block authorization. The downstream effects also weaken related controls like CP-02 (Contingency Plan), since your continuity strategy depends on power staying available long enough to execute failover procedures.
How do you audit PE-11?
Auditing PE-11 starts with reviewing UPS test records to verify that equipment is tested on a defined schedule and that results are documented with pass/fail outcomes. Assessors will also examine the system security plan to confirm it specifies whether each in-scope system uses the UPS for orderly shutdown or transition to alternate power. Physical inspection of UPS equipment and comparison against the documented inventory rounds out the assessment. Look for alignment between the emergency power policy’s stated testing frequency and the actual dates in the test logs.
What is the difference between a UPS and a backup generator?
A UPS provides near-instantaneous power from stored energy in batteries, supercapacitors, or flywheels, bridging the seconds or minutes between a power failure and the activation of longer-term backup. A backup generator, by contrast, takes time to start and stabilize before it can carry the full electrical load. PE-11 specifically addresses the UPS component because the generator’s startup delay is exactly the window where uncontrolled shutdowns and equipment damage occur.