PE-23: Facility Location

PE-23 requires organizations to factor physical and environmental hazards into every decision about where systems are physically housed.

Quick-reference card

FieldValue
Control IDPE-23
Control titleFacility Location
FrameworkNIST SP 800-53 Revision 5
Control familyPhysical and Environmental Protection (PE)
Baselines
Implementation levelOrganization
RelevanceFirst Party and Third Party
Risk severityLow

What this control requires

PE-23 requires organizations to factor physical and environmental hazards into every decision about where systems are physically housed. That means you don’t get to pick a data center, server closet, or co-location facility based on lease price alone and then bolt on resilience after the fact. The control has two parts: when you’re planning a new facility, you must evaluate location-specific hazards — floods, seismic activity, wildfire corridors, electromagnetic interference — before committing to a site. When you’re operating out of an existing facility, those same hazards need to be folded into your organization’s broader risk management strategy so leadership can make informed accept-or-mitigate decisions.

In practice, this means PE-23 sits upstream of most other physical security controls. If your facility is in a 100-year floodplain and you haven’t documented that risk, every downstream control — from fire suppression to contingency planning — inherits a blind spot. The control doesn’t prescribe specific countermeasures; it requires that the risk calculus happens and that the results feed into how you allocate resources.

For organizations relying on cloud providers or co-location vendors, PE-23 still applies. You’re responsible for understanding the physical risk posture of the facilities where your systems reside, even when you don’t own the building. That due diligence should be baked into your vendor selection criteria and revisited when contracts renew.

Why it matters

PE-23 occupies a governance-tier position in the NIST SP 800-53 control catalog, which means its failure mode isn’t an exploit — it’s an oversight that compounds across your entire physical security program. When facility location hazards aren’t assessed and documented, organizations carry unquantified risk that auditors will flag and that insurance underwriters increasingly scrutinize.

The challenge is that many organizations treat site selection as a facilities management decision rather than a security one. Physical site planning documents either don’t exist or sit in a property management folder no one in the security team has ever opened. The result is a gap between what the organization assumes about its physical risk posture and what actually exists on paper — a gap that becomes visible the moment an auditor asks for evidence.

Specifically, when an organization can’t demonstrate that environmental hazards were considered during site planning, auditors question the integrity of the entire risk management strategy. If you haven’t assessed flood risk, seismic exposure, or proximity to high-value targets for terrorism or vandalism, how can the contingency plan (CP-02) be credible? How can the broader risk management strategy (PM-09) account for threats it never enumerated?

This compliance exposure is compounded for organizations with distributed infrastructure. Each facility — whether owned, leased, or contracted through a co-location provider — represents a separate location-risk assessment that should feed into your organizational risk register.

What auditors look for:

  • Physical site planning documents that account for natural disaster risk (floods, earthquakes, tornadoes, hurricanes)
  • Evidence that environmental hazard assessments informed the organizational risk management strategy
  • Documentation showing fire, electromagnetic interference, and vandalism risks were evaluated for each facility
  • Proof that existing facility risks are reviewed periodically, not just at initial site selection
  • Alignment between facility hazard assessments and contingency planning assumptions

How to implement

Most organizations struggle with PE-23 not because the concept is difficult but because the responsibility falls between teams — facilities, security, risk management, and IT operations — without a clear owner.

For your organization

Start by identifying every facility where organizational systems reside. This includes owned buildings, leased office space, on-premises server rooms, and any co-location or cloud data center your organization contracts with. You can’t assess location-based risk for facilities you haven’t inventoried.

For each facility, conduct or obtain a physical and environmental hazard assessment. This assessment should evaluate flood zone classification (FEMA flood maps are a baseline), seismic zone rating, wildfire risk indices, hurricane and tornado exposure based on historical data, and proximity to industrial or military sites that could introduce electromagnetic interference or make the facility a secondary target. The assessment should also address human-caused hazards: terrorism risk based on proximity to high-profile targets, vandalism exposure, and civil unrest potential.

The resulting documentation — your physical site planning documents — should be formal artifacts, not informal notes. They need to be version-controlled, dated, and signed off by the risk owner. These documents feed directly into your organizational risk management strategy and should be referenced in your contingency plan.

Where this breaks down is in ongoing maintenance. PE-23 isn’t a one-time checkbox. Environmental conditions change: new FEMA flood maps get published, seismic risk assessments are updated, and urban development can alter a facility’s threat profile. Build a review cadence — annually at minimum — and tie it to your broader risk assessment cycle under RA-03.

For organizations using cloud or co-location providers, request the provider’s facility risk assessments as part of your due diligence. Major providers publish data center location information and resilience certifications, but you’re still responsible for documenting how those assessments factor into your own risk strategy. A physical and data center security questionnaire can help structure the right questions during vendor selection and periodic reassessment.

For your vendors

When evaluating whether a vendor meets PE-23 requirements, your goal is to verify that they’ve assessed physical and environmental hazards for the facilities housing your data or systems — and that those assessments are current.

Start with your security questionnaire. Ask vendors to describe their facility site selection process, including what physical and environmental hazards they evaluate before choosing a location. Request copies of their physical site planning documents or, at minimum, a summary of the hazards assessed and mitigations in place. Look for specifics: flood zone ratings, seismic classifications, backup power capacity against sustained weather events, and fire suppression capabilities appropriate to the local risk profile.

Red flags include vendors who can’t name the geographic region of their facilities, vendors whose “disaster recovery” documentation doesn’t reference specific environmental hazards, and vendors who treat co-location as a complete transfer of physical risk without demonstrating their own oversight. A vendor saying “our cloud provider handles that” without evidence of their own due diligence is a finding, not an answer.

Deepen your assessment by asking for evidence that environmental hazard reviews are periodic, not just conducted at facility build-out. Request documentation showing how facility risk assessments feed into the vendor’s broader risk management strategy. If the vendor operates from multiple locations, each site should have its own hazard assessment.

UpGuard Vendor Risk can streamline this process by centralizing vendor security questionnaire responses and tracking evidence artifacts across your third-party portfolio, making it easier to verify PE-23 compliance at scale without chasing individual vendor contacts.

Evidence examples

CategoryArtifact description
Physical site planningFormal site assessment documents evaluating flood zones, seismic ratings, wildfire indices, and proximity to high-risk targets for each facility
Environmental hazard assessmentAnalysis of natural disaster exposure (hurricanes, tornadoes, earthquakes) and human-caused threats (terrorism, vandalism, electromagnetic interference) per location
Risk management strategyOrganizational risk management strategy documentation showing how facility hazard findings inform risk acceptance, mitigation, or transfer decisions
Contingency plan alignmentContingency plan (CP-02) sections referencing facility-specific environmental risks and corresponding recovery procedures
Facility inventoryCurrent inventory of all facilities housing organizational systems, including owned, leased, and contracted co-location sites
Periodic review recordsEvidence of scheduled reassessment of facility hazards, including updated FEMA flood maps, seismic data, and changed threat conditions

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20227.5 Protecting against physical and environmental threatsPartial
ISO 27001:20227.8 Equipment siting and protectionPartial
  • CP-02 — Contingency Plan: The contingency plan should account for facility-specific environmental hazards identified under PE-23
  • PE-18 — Location of System Components: Addresses where components sit within a facility, complementing PE-23’s focus on the facility itself
  • PE-19 — Information Leakage: Facility location can influence exposure to electromagnetic eavesdropping or signal interception risks
  • PM-08 — Critical Infrastructure Plan: Facility location decisions directly affect how critical infrastructure dependencies are managed
  • PM-09 — Risk Management Strategy: PE-23 hazard assessments are a required input to the organizational risk management strategy
  • RA-03 — Risk Assessment: The risk assessment process should incorporate physical and environmental findings from PE-23 site evaluations

Frequently asked questions

What is NIST SP 800-53 PE-23?

PE-23 is the NIST SP 800-53 control that requires organizations to evaluate physical and environmental hazards when planning or operating facilities that house information systems. It applies to both new site selection and existing facilities, ensuring that risks like floods, seismic activity, and electromagnetic interference are documented and factored into the organizational risk management strategy. The control doesn’t mandate specific countermeasures — it mandates that physical site planning documents exist and that hazard findings feed into broader risk decisions.

What happens if PE-23 is not implemented?

Without PE-23 implementation, your organization carries undocumented physical risk that undermines the credibility of your entire risk management strategy. Auditors will flag the absence of physical site planning documents and environmental hazard assessments as a gap, particularly when reviewing contingency planning and disaster recovery readiness. The downstream impact is significant: if you can’t demonstrate that facility flood zone classifications or seismic ratings were evaluated, related controls like CP-02 and PM-09 lose their evidentiary foundation.

How do you audit PE-23?

Auditing PE-23 starts with requesting physical site planning documents for each facility where organizational systems reside and verifying that those documents address specific environmental hazards — flood zones, seismic exposure, wildfire risk, and human-caused threats. The auditor then checks whether these hazard findings are reflected in the organizational risk management strategy, not just filed away in a facilities folder. Evidence of periodic reassessment is also critical: a site planning document from the facility’s original build-out, with no updates reflecting changed environmental conditions, won’t satisfy a thorough review.

What physical hazards should be considered when choosing a facility location?

Organizations should evaluate a comprehensive set of natural and human-caused hazards during facility site planning. Natural hazards include floods (using FEMA flood zone maps as a baseline), earthquakes, tornadoes, hurricanes, and wildfires. Human-caused hazards include terrorism risk based on proximity to high-profile targets, vandalism, and electromagnetic interference from nearby industrial or military operations. The environmental hazard assessment should also consider incoming electromagnetic radiation and electrical interference that could disrupt system operations. Each hazard should be documented in the physical site planning documents with a corresponding risk rating and mitigation approach.

Experience superior visibility and a simpler approach to cyber risk management