PE-19: Information Leakage

PE-19 requires organizations to protect systems from information leakage caused by electromagnetic signal emanations.

Quick-reference card

FieldValue
Control IDPE-19
Control titleInformation Leakage
FrameworkNIST SP 800-53, Revision 5
Control familyPhysical and Environmental Protection (PE)
BaselinesNot part of any baseline
Implementation levelOrganization
RelevanceFirst Party and Third Party
Risk severityMedium

What PE-19 requires

PE-19 requires organizations to protect systems from information leakage caused by electromagnetic signal emanations. The control addresses a physical security risk that most compliance programs overlook: data escaping a facility not through a network breach or an insider, but through the unintended radio-frequency signals that every electronic device emits during normal operation.

In practice, this means identifying which systems process data sensitive enough to warrant emanation protections, then applying technical and physical countermeasures proportional to the risk. The NIST SP 800-53 framework ties the selection of those countermeasures directly to the security categorization of the system with respect to confidentiality, organizational security policies, and the organization’s risk tolerance.

Unlike controls that focus on logical access or network segmentation, PE-19 sits at the intersection of physical security and signals intelligence. Organizations handling classified or high-confidentiality data have long addressed this risk under programs like TEMPEST (Telecommunications Electronics Material Protected from Emanating Spurious Transmissions), but the control applies broadly to any environment where electromagnetic signal emanations could expose sensitive information to an untrusted party.

Why it matters

Most organizations treat physical security as perimeter defense: locked doors, badge readers, camera systems. Electromagnetic signal emanations represent a different threat vector entirely, one where sensitive data can leave a facility without a single packet crossing the network boundary.

The risk is not theoretical in a compliance sense. Auditors evaluating PE-19 look for evidence that the organization has assessed whether its systems emit exploitable electromagnetic signals and has documented the decision to apply or waive specific countermeasures. Without that assessment, you face a control gap that can cascade into broader findings during an audit of the Physical and Environmental Protection family.

Specifically, when systems process information at higher confidentiality levels, the absence of emanation protections introduces a vulnerability class that network-layer controls cannot address. A well-configured firewall, endpoint detection system, or data loss prevention program does nothing against signals captured from unshielded cabling or monitors.

Organizations that fail to account for electromagnetic leakage risk also lack the documentation trail auditors expect. Without a formal risk assessment that evaluates emanation threats against the system’s security categorization, the organization cannot demonstrate that it made an informed, risk-based decision about PE-19 applicability.

What attackers exploit

Electromagnetic signal emanation risks stem from specific physical and environmental conditions. The following vectors represent the areas PE-19 is designed to address:

  • Unshielded data cables carrying sensitive information in areas accessible to unauthorized parties
  • Display equipment emitting signals that can be reconstructed to reveal on-screen content
  • Processing hardware generating electromagnetic signatures correlated with cryptographic operations
  • Facilities lacking controlled zones or adequate physical separation between classified and unclassified systems
  • Telecommunications infrastructure without appropriate filtering or shielding at facility boundaries

How to implement PE-19

Implementation starts with a gap that trips up many organizations: the assumption that PE-19 only applies to classified government environments. The control applies wherever the system’s confidentiality categorization and organizational policy indicate that electromagnetic emanation risks are material. Organizations that skip the initial risk assessment cannot demonstrate compliance, regardless of whether they ultimately need TEMPEST-grade shielding.

For your organization

Begin by conducting an electromagnetic emanation risk assessment for systems that process sensitive or high-confidentiality data. This assessment should evaluate the physical environment, the types of data processed, and the proximity of untrusted parties to the systems in question.

Based on the assessment findings, select and implement countermeasures proportional to the identified risk. These countermeasures typically fall into three categories:

  • Shielding and containment: Installing electromagnetic shielding on rooms, enclosures, or individual equipment to reduce signal leakage below exploitable levels. This ranges from shielded cables and filtered power lines to fully screened rooms that meet national emissions security standards.
  • Physical separation: Positioning systems that process sensitive data away from facility boundaries, public areas, or spaces accessible to unauthorized individuals. The goal is to increase the distance between the emanating source and any potential collection point.
  • Testing and validation: Conducting periodic electromagnetic signal emanation tests to verify that countermeasures remain effective. Document test results, including the testing methodology, equipment used, and any remediation actions taken.

Maintain a formal policy that ties PE-19 requirements to the organization’s system categorization process. When a system’s confidentiality level changes, reassess the emanation risk and update protections accordingly. Organizations that integrate data leak prevention strategies across both digital and physical channels build a more resilient control environment.

For your vendors

When assessing third-party compliance with PE-19, focus on whether the vendor has performed an electromagnetic emanation risk assessment for the systems that process your data and whether countermeasures are in place where warranted.

Request the following during vendor assessments:

  • Emanation risk assessment documentation: Ask the vendor to provide evidence that they have evaluated electromagnetic signal leakage risks for systems handling your data. The assessment should reference the system’s security categorization and the vendor’s risk tolerance thresholds.
  • Shielding and countermeasure evidence: Request records of any physical or technical countermeasures deployed, including shielded enclosures, filtered power supplies, or controlled-zone configurations. Verify that the countermeasures align with the risk assessment findings.
  • Testing records: Ask for results from electromagnetic signal emanation tests conducted on relevant systems. Look for documentation of testing frequency, methodology, equipment, and any corrective actions triggered by test failures.

Red flags include vendors who claim PE-19 is not applicable without providing a documented risk assessment, vendors who cannot produce testing records for systems in controlled environments, and vendors whose physical security policies make no reference to emanation risks despite processing high-confidentiality data.

Evidence examples

Evidence categoryExample artifact
Policy documentationPhysical and environmental protection policy defining emanation risk assessment requirements, system categorization thresholds, and countermeasure selection criteria
Procedural guidanceProcedures addressing electromagnetic signal emanation protections, including roles, review cadence, and escalation paths
Risk assessment recordsCompleted emanation risk assessment identifying systems evaluated, confidentiality categorization, assessed risk levels, and countermeasure decisions
Shielding and countermeasure inventoryDocumentation of mechanisms protecting systems against electromagnetic signal emanations, including shielded rooms, filtered cabling, and controlled zones
Facility configuration recordsFacility layout documentation showing physical separation between sensitive systems and untrusted or uncontrolled areas
Test resultsRecords from electromagnetic signal emanation tests, including testing methodology, equipment used, findings, and remediation actions

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20227.5 Protecting against physical and environmental threatsPartial
ISO 27001:20227.8 Equipment siting and protectionPartial
ISO 27001:20228.12 Data leakage preventionPartial
  • AC-18 — Wireless Access: Wireless access controls complement PE-19 by managing authorized radio-frequency transmissions, reducing the attack surface for electromagnetic interception.
  • PE-18 — Location of System Components: Physical placement of system components directly affects emanation exposure, making PE-18 a foundational dependency for PE-19 countermeasures.
  • PE-20 — Asset Monitoring and Tracking: Tracking the location and movement of assets that process sensitive data supports PE-19 by ensuring emanation-sensitive systems remain within controlled environments.

Frequently asked questions

What is NIST SP 800-53 PE-19

PE-19 requires organizations to protect systems from information leakage caused by electromagnetic signal emanations. The control addresses the risk that electronic equipment emits radio-frequency signals during normal operation that could be intercepted to reconstruct the data being processed. Organizations must assess emanation risks based on system confidentiality categorization and implement countermeasures such as shielding, physical separation, and periodic emanation testing. PE-19 applies to any system where the security categorization and organizational policy indicate that electromagnetic leakage is a material risk.

What happens if PE-19 is not implemented

Failure to implement PE-19 leaves organizations without documented evidence that electromagnetic signal emanation risks have been assessed and addressed. Auditors reviewing the Physical and Environmental Protection family will flag the absence of an emanation risk assessment as a control gap, even if the organization ultimately determines that no countermeasures are needed. Without testing records and facility configuration documentation, the organization cannot demonstrate that it made a risk-informed decision about emanation protections. This gap can trigger broader audit findings and undermine the credibility of the overall physical security control environment.

How do you audit PE-19

Auditing PE-19 starts with verifying that the organization has completed an electromagnetic signal emanation risk assessment tied to the system’s confidentiality categorization. Review the physical and environmental protection policy for language addressing emanation risks and countermeasure selection criteria. Examine records from electromagnetic signal emanation tests, including the testing methodology, equipment used, and any corrective actions. Inspect the facility housing the system to confirm that shielding, controlled zones, or physical separation measures match the documented countermeasure decisions. Compare the evidence against the organization’s stated risk tolerance to confirm that the selected protections are proportional.

What is TEMPEST in the context of information security

TEMPEST refers to the study and control of compromising electromagnetic emanations from electronic equipment. In the context of PE-19, TEMPEST standards and testing methodologies provide the technical foundation for evaluating whether systems leak exploitable signals. Organizations subject to national emissions security policies use TEMPEST-certified equipment, shielded facilities, and periodic emanation testing to satisfy PE-19 requirements for systems processing classified or high-confidentiality data. The term covers both the threat (unintentional electromagnetic signal leakage) and the countermeasures (shielding, filtering, and facility design) used to mitigate it.

How UpGuard helps with PE-19 compliance

While PE-19 focuses on physical electromagnetic emanation controls, a complete compliance posture requires visibility across your entire risk surface. UpGuard supports organizations managing NIST SP 800-53 compliance by providing continuous monitoring and risk assessment capabilities that complement physical security controls.

  • Vendor Risk: Assess and monitor third-party compliance with physical and environmental protection requirements, including PE-19 emanation controls, through standardized security questionnaires and continuous risk scoring.
  • Breach Risk: Gain visibility into your external attack surface to identify exposures that physical controls alone cannot address, supporting a layered defense strategy aligned with NIST SP 800-53 requirements.

Experience superior visibility and a simpler approach to cyber risk management