NIST 800-53 REV 5 • PHYSICAL AND ENVIRONMENTAL PROTECTION

PE-18(1)Facility Site

CMMC Practice Mapping

No direct CMMC mapping

NIST 800-171 Mapping

No direct NIST 800-171 mapping

Related Controls

No related controls listed

Practitioner Notes

This enhancement considers the security of the facility site itself — its geographic location and surrounding environment — when planning where to locate system components.

Example 1: When selecting a new facility or data center location, evaluate the risk from natural hazards (flood zone, earthquake zone, tornado alley), proximity to high-risk targets (military bases, chemical plants), and crime rates in the area. Document this risk assessment.

Example 2: Review FEMA flood maps and local hazard assessments before leasing or purchasing a facility. Avoid locations in 100-year flood plains. Consider proximity to emergency services (fire station, hospital). Include site risk factors in your risk management documentation.