PE-18: Location of System Components

PE-18 requires organizations to position system components within facilities to minimize damage from physical and environmental hazards and

Quick-reference card

FieldValue
Control IDPE-18
Control nameLocation of System Components
FrameworkNIST SP 800-53, Revision 5
Control familyPhysical and Environmental Protection
BaselinesHIGH
RelevanceOrganization (First Party and Third Party)
Risk severityLow

What this control requires

PE-18 requires organizations to position system components within facilities to minimize damage from physical and environmental hazards and reduce opportunities for unauthorized access. Rather than treating server placement as a purely logistical decision, this control forces you to evaluate how location choices affect both resilience and security posture across your NIST SP 800-53 environment.

In practice, this means you must document the specific hazards relevant to each facility, such as flood zones, fire paths, seismic risk, and electromagnetic interference, and then demonstrate that component placement decisions account for those threats. You also need to show that system components aren’t positioned where unauthorized individuals could intercept wireless communications or gain visual or physical proximity to sensitive equipment.

The control applies at the HIGH baseline, making it mandatory for federal systems processing high-impact data. Organizations pursuing NIST SP 800-53 compliance should treat PE-18 as a foundational physical security requirement that connects directly to contingency planning and risk assessment activities. A useful starting point for aligning your broader compliance program is the NIST 800-53 compliance checklist.

Why it matters

PE-18 sits at breach tier 3, meaning the primary risk isn’t a dramatic data exfiltration scenario. Instead, the consequences are audit findings, failed authorizations to operate (ATOs), and compliance gaps that stall your security program. Assessors will flag any environment where component placement decisions can’t be traced back to a documented hazard analysis.

Where this breaks down for most organizations is during facility changes. Teams relocate racks, add edge infrastructure, or consolidate data centers without revisiting the original placement rationale. That drift creates a gap between your system security plan and reality, which is exactly what auditors look for.

Specifically, when system components are positioned near exterior walls, ground-floor windows, or building entry points, the risk of unauthorized signal interception increases. Wireless packet sniffers and directional microphones can capture data from surprising distances when equipment sits in predictable, accessible locations.

The compliance cost of ignoring PE-18 compounds over time. A missing hazard analysis forces rework across your contingency plan, risk assessment, and physical protection documentation. Remediating after an audit finding is significantly more expensive than building placement criteria into your facility management process from the start.

What attackers exploit

  • Electromagnetic emanations from system components placed near exterior walls or shared tenant spaces
  • Wireless signals captured through packet sniffers positioned near windows or building perimeters
  • Physical proximity to entry points, loading docks, or public areas that enable visual reconnaissance of equipment configurations
  • Flood, fire, or seismic damage amplified by components placed in basement server rooms or near water mains without environmental controls
  • Social engineering combined with physical access to unsecured areas adjacent to improperly positioned system components

How to implement

For your organization

Start by completing a facility-specific hazard assessment. Identify every physical and environmental threat relevant to your building, including floods, fires, tornadoes, earthquakes, hurricanes, electromagnetic interference, vandalism, and terrorism. Map these hazards to specific zones within the facility.

Once your hazard map is complete, document placement criteria for each category of system component. Servers, networking equipment, storage arrays, and workstations each have different environmental tolerances and security requirements. Your criteria should specify minimum distances from exterior walls, restricted proximity to entry points, and required environmental controls for each zone.

The next step is to validate current placements against your criteria. Walk the facility with your hazard map and document any components that don’t meet the positioning requirements. Create a remediation plan with timelines for relocating non-compliant equipment.

Build a change management gate that requires placement review before any component is moved, added, or decommissioned. Without this gate, your documentation will drift out of alignment with physical reality within months.

Common mistakes include treating this control as a one-time exercise, failing to account for electromagnetic emanation risks near shared walls, and neglecting to update placement documentation after facility renovations. You should also verify that your system security plan references the hazard analysis and placement criteria explicitly, because assessors will trace that link during authorization reviews.

Maintain an evidence package that includes your hazard analysis, facility floor plans with component locations marked, placement criteria documents, and change management records. These artifacts should be version-controlled and reviewed at least annually.

For your vendors

When evaluating vendor compliance with PE-18, you need to go beyond a self-attestation checkbox. Start with targeted questionnaire questions that reveal whether the vendor has actually performed the analysis this control requires. A physical and data center security questionnaire template can help structure your assessment.

Key questions to include in your vendor assessment:

  • Does the vendor maintain a documented facility hazard analysis that identifies physical and environmental threats?
  • Can the vendor provide facility floor plans showing system component placement relative to identified hazard zones?
  • Does the vendor’s change management process require placement review before equipment moves?
  • How does the vendor address electromagnetic emanation risks for components near facility perimeters?
  • When was the last time the vendor updated its component placement documentation?

Red flags to watch for include vendors who can’t produce a hazard analysis separate from their general security policy, vendors whose floor plans don’t show component locations, and vendors who describe placement decisions as “common sense” without documented criteria.

Verification should include requesting the vendor’s most recent hazard analysis with dates, asking for evidence of placement reviews tied to facility changes, and confirming that the vendor’s system security plan references specific placement criteria. For high-risk vendors, consider requesting a virtual or physical walkthrough of the facility to validate that documentation matches reality.

The gap between documentation and practice is where vendor risk lives for PE-18. A vendor may have a policy that addresses component placement in general terms but lack the facility-specific analysis and positioning evidence the control actually requires.

Evidence examples

Evidence typeExample artifact
Physical and environmental protection policyPolicy document defining organizational requirements for facility hazard analysis and component placement criteria
Facility hazard analysisAssessment identifying specific physical and environmental threats (flood zones, fire paths, seismic risk, electromagnetic interference) for each facility
Component placement documentationFloor plans and rack diagrams showing system component locations relative to identified hazard zones, entry points, and facility perimeters
System security planSSP sections referencing PE-18 implementation, including links to hazard analysis and placement criteria
Change management recordsTickets or workflow records showing placement review approval before component moves or facility modifications

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.10 Acceptable use of information and other associated assetsPartial
ISO 27001:20227.5 Protecting against physical and environmental threatsPartial
ISO 27001:20227.8 Equipment siting and protectionPartial
  • CP-02 Contingency Plan relates to PE-18 because component placement decisions directly affect whether systems can survive physical disruptions covered by contingency planning scenarios.
  • PE-05 Access Control for Output Devices complements PE-18 by controlling who can access output from devices whose physical positioning PE-18 governs.
  • PE-19 Information Leakage extends PE-18’s concern about unauthorized access by addressing electromagnetic signals and emanations that component placement can either mitigate or amplify.
  • PE-20 Asset Monitoring and Tracking supports PE-18 by providing visibility into whether system components remain in their documented positions over time.
  • RA-03 Risk Assessment underpins PE-18’s hazard analysis requirement, because the placement criteria depend on an accurate understanding of threats to the facility.

You can explore the full Physical and Environmental Protection family for additional context on how these controls work together.

Frequently asked questions

What is NIST SP 800-53 PE-18?

PE-18 is a physical security control that requires organizations to position system components within facilities to minimize damage from physical and environmental hazards and reduce unauthorized access opportunities. It applies at the HIGH baseline in NIST SP 800-53 Revision 5. Organizations must document facility-specific hazards and demonstrate that component placement decisions account for those threats.

What happens if PE-18 is not implemented?

Failing to implement PE-18 creates audit findings that can delay or block your authorization to operate. Assessors will flag the absence of a documented hazard analysis and component placement rationale as a plan of action and milestones (POA&M) item. The compliance cost compounds because PE-18 gaps often cascade into related findings for contingency planning and risk assessment controls.

How do you audit PE-18?

Auditing PE-18 starts with reviewing the facility hazard analysis to confirm it identifies specific physical and environmental threats relevant to the building. Assessors then compare facility floor plans and component placement documentation against the hazard analysis to verify that positioning decisions align with identified risks. Physical walkthroughs validate that documentation matches the actual placement of system components, and change management records confirm that placement reviews occur before equipment moves.

What is the difference between PE-18 and PE-23?

PE-18 governs where system components are positioned within a facility, focusing on internal placement relative to hazards and access points. PE-23, Facility Location, addresses the selection of the facility itself, considering geographic, environmental, and threat factors at the site level. Together, they create a layered approach where PE-23 determines the building and PE-18 determines how equipment is arranged inside it.

Experience superior visibility and a simpler approach to cyber risk management