Quick-reference card
| Field | Value |
|---|---|
| Control ID | PE-09 |
| Control name | Power Equipment and Cabling |
| Framework | NIST SP 800-53, Revision 5 |
| Control family | Physical and Environmental Protection |
| Baselines | MODERATE HIGH |
| Relevance | Organization (First Party and Third Party) |
| Risk severity | LOW |
What this control requires
PE-09 requires organizations to protect the power equipment and cabling that keep information systems running. As part of the Physical and Environmental Protection family, it addresses a foundational dependency that other technical controls rely on. That means safeguarding everything from internal uninterruptible power supplies (UPSs) and office wiring to external generators, distribution panels, and cabling routes that connect facilities to the grid.
In practice, most teams focus their physical security budgets on server rooms and data center floors while overlooking the infrastructure that feeds those rooms electricity. PE-09 closes that gap by making power protection an explicit obligation. You need to identify every location where power equipment and cabling exist, assess the threats at each location, and apply protections proportional to the risk. Those locations include office buildings, colocation sites, outdoor transformer pads, and even self-contained deployable systems like mobile command vehicles or satellite ground stations.
The control doesn’t prescribe a single protection method because the right answer depends on where the equipment sits. An indoor UPS in a climate-controlled data center faces different threats than a diesel generator on an exposed concrete pad. Your job is to determine the protection type each asset needs, document that determination, and verify the protections remain effective over time. Auditors will look for evidence that you’ve thought through these distinctions rather than applying a blanket policy that ignores environmental context.
Why it matters
Unprotected power equipment creates a single point of failure that can take an entire facility offline. Even organizations with redundant network paths and replicated data stores can lose availability if the electrical infrastructure supporting those systems is damaged or tampered with. PE-09 exists because power is the foundational dependency beneath every other technical control you operate.
Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. Federal agencies operating under NIST SP 800-53 at the MODERATE or HIGH baseline must demonstrate PE-09 compliance during authorization assessments. In practice, missing or weak power protections lead to findings that delay or block authority to operate decisions.
The risk extends beyond compliance. Physical damage to power cabling or equipment can cause unplanned outages that disrupt mission-critical services, corrupt data in transit, or trigger cascading failures across interconnected systems. Recovery costs and reputational impact compound quickly when the root cause is a preventable physical vulnerability.
Beyond accidental damage, power infrastructure is a target. The following threat vectors are relevant to PE-09:
- Intentional cable severing or tampering by insiders or trespassers who can access unprotected cable runs, outdoor conduit, or unlocked electrical panels
- Environmental damage from flooding, fire, rodents, or construction activity in areas where cabling lacks adequate physical shielding
- Power surges and grid instability that reach critical equipment because surge protection, line conditioning, or transfer switches are absent or poorly maintained
- Generator fuel theft or sabotage at outdoor installations that lack fencing, monitoring, or tamper-evident controls
- Supply chain compromise of replacement power components where counterfeit or substandard parts are installed without verification
How to implement
Power protection fails most often when responsibility is split across facilities, IT operations, and security teams without a single owner accountable for the full scope of PE-09.
For your organization
Start by building a complete inventory of power equipment and cabling across every location where your systems operate. This inventory should cover UPS units, power distribution units (PDUs), automatic transfer switches (ATSs), generators, surge protectors, and all cabling runs from the utility entrance to the rack. Document the physical location, environmental exposure, and current protection measures for each asset.
Conduct a site-by-site threat assessment. Indoor equipment in controlled environments may only need locked electrical closets and environmental monitoring. Outdoor generators and transformer pads require fencing, tamper-evident seals, weatherproofing, and potentially video surveillance. Cable routes that pass through shared spaces or cross building boundaries need conduit protection and periodic inspection.
Implement layered protections based on your assessment. Common measures include the following:
- Locking electrical panels and UPS enclosures with access restricted to authorized personnel
- Routing cabling through secured conduit rather than exposed trays in shared or public spaces
- Installing environmental sensors for temperature, humidity, and water detection near power equipment
- Maintaining generator fuel reserves with tamper monitoring and regular testing schedules
- Deploying redundant power paths so that a single cable cut doesn’t cause a full outage
Produce and maintain documentation that auditors expect. Your physical and environmental protection policy should include specific sections on power equipment protection. Supplement the policy with procedures for routine inspection, maintenance schedules, and incident response steps for power-related events. Keep maintenance logs and inspection records as ongoing evidence.
A common mistake is treating PE-09 as a one-time checklist. Power infrastructure changes as organizations expand, relocate, or modify facilities. Build periodic reviews into your maintenance calendar so protections stay aligned with the current environment.
For your vendors
When assessing a vendor’s PE-09 compliance, your goal is to verify that they’ve applied power protections appropriate to the environments where your data is processed or stored. Self-attestation alone isn’t sufficient for this control because power protection is location-specific and difficult to evaluate from a questionnaire alone.
Include questions like the following in your vendor assessment:
- How do you protect power equipment and cabling at each facility that processes or stores our data?
- What types of backup power systems are in place, and how often are they tested?
- Are cable routes physically secured against tampering and environmental hazards?
- Who is responsible for inspecting and maintaining power infrastructure, and on what schedule?
- Have you experienced any power-related outages in the past 12 months, and what was the root cause?
Request supporting evidence beyond the questionnaire responses. Useful artifacts include data center audit reports (SOC 2 Type II reports often cover physical controls), facility diagrams showing power distribution and redundancy, generator test logs, and maintenance records for UPS systems. If the vendor operates in a colocation facility, ask for the colocation provider’s physical security documentation as well.
Watch for red flags. Vendors that cannot describe their power protection strategy in location-specific terms may be applying a generic policy without actual implementation. Gaps in generator testing schedules, missing maintenance records, or reliance on a single power path without documented redundancy should prompt follow-up questions.
Verification beyond self-attestation can include requesting right-to-audit clauses, reviewing third-party assessment reports, or conducting on-site visits for critical vendors. For vendors classified as high risk, periodic reassessment of power protections should be part of your ongoing monitoring program.
Evidence examples
| Evidence type | Example artifact |
|---|---|
| Physical and environmental protection policy | Policy document with sections defining power equipment protection standards, roles, and responsibilities for each facility type |
| Power equipment and cabling protection procedures | Step-by-step procedures for inspecting, maintaining, and securing UPS units, generators, PDUs, transfer switches, and cable routes |
| Power equipment inventory | Asset register listing all power equipment by location, including protection status, last inspection date, and responsible party |
| Facility diagrams | Floor plans and site maps showing power distribution paths, redundancy configurations, and physical protection measures |
| Maintenance and inspection logs | Dated records of generator tests, UPS battery replacements, cable inspections, and environmental sensor calibrations |
| System security plan | Relevant sections documenting PE-09 implementation decisions, threat assessments, and compensating controls for each operating environment |
Cross-framework mapping
| Framework | Control | Coverage |
|---|---|---|
| ISO 27001:2022 | 7.11 Supporting utilities | Partial |
| ISO 27001:2022 | 7.12 Cabling security | Partial |
| ISO 27001:2022 | 7.5 Protecting against physical and environmental threats | Partial |
| ISO 27001:2022 | 7.8 Equipment siting and protection | Partial |
Related controls
- PE-04 — Access Control for Transmission: PE-04 focuses on controlling physical access to transmission lines and cabling distribution points, complementing PE-09’s broader requirement to protect power equipment and cabling from damage and destruction across all facility types.
Frequently asked questions
What is NIST SP 800-53 PE-09?
PE-09 is the NIST SP 800-53 control that requires organizations to protect power equipment and cabling from damage and destruction. It applies to internal infrastructure like UPS units and office wiring as well as external assets like generators and outdoor cabling runs. The control is included in the MODERATE and HIGH baselines, making it mandatory for most federal systems and widely adopted in the private sector.
What happens if PE-09 is not implemented?
Without PE-09 protections, power equipment and cabling remain vulnerable to environmental damage, tampering, and accidental disruption. The immediate consequence is audit findings that can delay or block system authorization decisions. Unprotected power infrastructure also creates availability risk, since a single damaged cable run or failed generator can take dependent systems offline without warning.
How do you audit PE-09?
Auditing PE-09 starts with reviewing the physical and environmental protection policy for sections that specifically address power equipment and cabling protection. Auditors then examine facility diagrams, power equipment inventories, and maintenance logs to verify that documented protections exist in practice. On-site inspection of UPS enclosures, generator installations, cable routes, and environmental monitoring sensors confirms whether protections match the documented controls. Gaps between policy and implementation, such as unlocked electrical panels or untested generators, are common findings.
What are the control enhancements for PE-09?
PE-09 includes enhancements that address redundant cabling and automatic voltage controls for specific high-availability environments. These enhancements go beyond the base control by requiring organizations to implement backup cabling paths and voltage regulation mechanisms that activate without manual intervention. Whether an enhancement applies depends on your system’s impact level and the specific availability requirements documented in your security plan.