Quick-reference card
| Field | Value |
|---|---|
| Control ID | PE-17 |
| Control Name | Alternate Work Site |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Physical and Environmental Protection (PE) |
| Baselines | MODERATE, HIGH |
| Relevance | Organization (First Party and Third Party) |
| Risk Severity | Medium |
What this control requires
PE-17 requires your organization to identify every alternate work site your employees use, enforce defined security controls at those locations, and verify those controls actually work. This control treats home offices and other remote locations as extensions of your corporate environment, not exceptions to it.
In practice, this means you need a documented and approved list of alternate work sites, a defined set of security controls tailored to each site type, and a structured process to assess whether those controls remain effective over time. You also need a clear communication channel so employees at remote locations can reach your security and privacy teams without delay when incidents occur.
Where this control breaks down in most organizations isn’t the documentation. It’s the assumption that a VPN and a policy document are sufficient. PE-17 demands ongoing assessment of controls at each site type, which forces you to distinguish between a home office with an encrypted laptop on a secured network and a coffee shop with shared Wi-Fi and no physical barriers.
Why it matters
Most organizations treat alternate work sites as a policy checkbox rather than a genuine attack surface. The shift to distributed workforces made this gap more visible, but the underlying risk predates any pandemic-era policy changes. When your employees operate outside controlled physical environments, every assumption you’ve made about network segmentation, physical access, and endpoint security needs re-examination.
Failing to implement PE-17 creates measurable compliance exposure. Federal agencies and contractors operating under NIST SP 800-53 moderate and high baselines face audit findings when alternate work site controls aren’t documented, assessed, or enforced. For organizations pursuing FedRAMP authorization or FISMA compliance, a gap here can delay or derail certification.
The risk extends beyond audit findings. Without defined controls for remote access and the cybersecurity exposure it creates, your organization has no consistent baseline for how sensitive data is handled outside the office. Assessors will look for evidence that you’ve identified site-specific risks and addressed them with proportional controls, not a one-size-fits-all policy.
Beyond compliance, weak alternate work site controls introduce operational risks that compound over time. Unmonitored remote environments become the path of least resistance for adversaries who’ve already mapped your perimeter defenses.
The following vectors are common in environments where PE-17 controls are absent or poorly assessed:
- Unsecured home networks with default router credentials, no network segmentation, and shared access among household members
- Unencrypted endpoints used at alternate sites where physical theft or loss goes unreported
- Lack of incident reporting channels, leaving employees with no way to escalate security events from remote locations
- Shadow IT adoption at remote sites, where employees use unapproved tools and cloud services because approved alternatives don’t work well outside the office
- Inconsistent patching and configuration on devices that rarely connect to corporate management infrastructure
How to implement
The most common failure mode with PE-17 isn’t a lack of policy. It’s a disconnect between what your policy says about alternate work sites and what your employees actually experience when they work from one. Bridging that gap requires controls that are specific to site types, regularly assessed, and paired with a functioning incident communication channel.
For your organization
Start by building a categorized inventory of alternate work site types your employees use. Don’t limit this list to home offices. Include co-working spaces, partner facilities, travel locations, and any government facility used outside your primary site. Each category should carry a defined risk profile and a corresponding set of required controls.
Define the minimum security controls for each site type. For home offices, this typically includes encrypted endpoints, VPN or zero-trust network access, endpoint detection and response (EDR) agents, and working from home security practices your employees can follow. For less controlled environments like hotels or co-working spaces, consider stronger controls such as privacy screens, automatic screen locks, and restrictions on printing or local storage.
Document your approval process. Employees should formally acknowledge the security requirements for their alternate work site before using it for work involving sensitive systems. This acknowledgment creates a record that assessors will look for during audits.
Establish a recurring assessment cadence. PE-17 doesn’t just require you to deploy controls. It requires you to assess their effectiveness. Quarterly self-assessments or annual spot checks, combined with automated endpoint compliance verification, provide the evidence auditors need. Track assessment results and remediation actions in a centralized system.
Build a dedicated incident communication channel for remote employees. This can’t just be an email address buried in a policy document. Employees at alternate work sites need a clear, accessible path to reach your security and privacy teams, whether that’s a dedicated hotline, a chat channel, or an on-call rotation with documented escalation procedures.
For your vendors
When your vendors’ employees work from alternate sites while handling your data, you inherit their remote work risk. Your third-party risk assessments should explicitly address PE-17 requirements, not just assume that a vendor’s SOC 2 report covers alternate work site controls.
Include targeted questions in your vendor security questionnaires. Ask whether the vendor maintains a documented list of approved alternate work sites, what controls are required at each site type, how frequently those controls are assessed, and whether employees at remote sites have a defined incident reporting channel. Generic questions about “remote work policies” won’t surface the specific gaps PE-17 targets.
Request evidence beyond policy documents. Ask for recent assessment results from alternate work site control evaluations, endpoint compliance reports, and documentation of the incident communication process available to remote workers. A vendor that can produce current assessment records demonstrates operational maturity. One that can only provide a policy PDF likely hasn’t tested those controls.
Watch for red flags during assessments. Vendors that can’t distinguish between their alternate work site policy and their general remote access policy likely haven’t implemented PE-17 at the level of specificity the control demands. The same applies to vendors who can’t describe how they verify that controls at remote sites remain effective over time.
Incorporate PE-17 into your continuous monitoring program for critical vendors. As remote work arrangements change, the controls your vendor had in place during their last assessment may no longer reflect their current environment. Periodic re-evaluation ensures that alternate work site risks don’t accumulate unnoticed in your supply chain.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Alternate work site policy | Physical and environmental protection policy defining approved alternate work site categories, acceptable use criteria, and employee acknowledgment requirements |
| Site inventory and approval records | Documented list of approved alternate work sites by type, with risk classifications and approval dates |
| Required controls catalog | List of security controls required at each alternate work site type, including endpoint encryption, VPN configuration, and physical safeguards |
| Control assessment results | Assessment reports evaluating the effectiveness of security controls at alternate work sites, including findings and remediation tracking |
| Incident communication procedures | Documented process for employees at alternate work sites to contact security and privacy personnel, including escalation paths and contact methods |
| System security plan | System security plan sections describing alternate work site controls, risk acceptance decisions, and integration with the broader physical protection program |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.14 Information transfer | Partial |
| ISO 27001:2022 | 6.7 Remote working | Partial |
| ISO 27001:2022 | 7.9 Security of assets off-premises | Partial |
| NIST SP 800-171 Rev 3 | 03.10.06 Alternate Work Site | Partial |
Related controls
- AC-17 — Remote Access: Governs the policies, procedures, and technical mechanisms for authorizing and monitoring remote connections to organizational systems, directly complementing the physical and environmental focus of PE-17.
- AC-18 — Wireless Access: Addresses the restrictions and protections required for wireless network connections, which are a primary connectivity method at most alternate work sites.
- CP-07 — Alternate Processing Site: Covers the establishment and maintenance of alternate processing sites for continuity of operations, distinct from the employee-focused alternate work sites addressed by PE-17.
Frequently asked questions
What is NIST SP 800-53 PE-17
PE-17 is a physical and environmental protection control that requires organizations to document approved alternate work sites, enforce security controls at those locations, assess control effectiveness, and provide employees with a way to report security incidents from remote locations. It applies to any location outside your primary facility where employees perform work, including home offices and government facilities. The control appears in both moderate and high baselines, making it mandatory for most federal systems and FedRAMP-authorized environments.
What happens if PE-17 is not implemented
Without PE-17, your organization lacks a structured approach to managing security risks at alternate work sites, which creates audit findings during FISMA and FedRAMP assessments. Assessors will flag the absence of a documented site inventory, missing control assessments, and the lack of a defined incident communication channel for remote employees. Beyond compliance consequences, the gap leaves your organization unable to verify that endpoints and networks at remote locations meet your security baseline.
How do you audit PE-17
Auditing PE-17 starts with verifying that a documented list of approved alternate work sites exists and that each site type has defined security controls. Assessors then examine whether your organization has conducted and recorded effectiveness assessments for those controls, looking for specific assessment reports with findings and remediation actions. The audit also confirms that a functioning incident communication mechanism exists for employees at alternate sites, typically by reviewing documented escalation procedures, contact methods, and evidence that employees have been informed of the process.
What security controls are needed for remote work sites
The specific controls depend on the risk profile of each alternate work site type, but PE-17 expects organizations to define and document these controls rather than apply a generic policy. Common controls include endpoint encryption, VPN or zero-trust network access, EDR agents, automatic screen locks, and restrictions on local data storage. Your organization should also implement physical safeguards appropriate to the site type and maintain a clear process for employees to report security incidents from any remote location.