PE.L2-3.10.6 Alternative Work Sites
Enforce safeguarding measures for CUI at alternate work sites.
Source: NIST SP 800-171 Rev 2 3.10.6
Discussion: Alternate work sites may include government facilities or the private residences of employees. Organizations may define different security requirements for specific alternate work sites or types of sites depending on the work-related activities conducted at those sites. [SP 800-46] and [SP 800-114] provide guidance on enterprise and user security when teleworking.
Assessment Objectives:
Determine if:
- [a] safeguarding measures for CUI are defined for alternate work sites; and
- [b] safeguarding measures for CUI are enforced for alternate work sites.
Examine: [SELECT FROM: Physical and environmental protection policy; procedures addressing alternate work sites for personnel; security plan; list of safeguards required for alternate work sites; assessments of safeguards at alternate work sites; other relevant documents or records].
Interview: [SELECT FROM: Personnel approving use of alternate work sites; personnel using alternate work sites; personnel assessing controls at alternate work sites; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for security at alternate work sites; mechanisms supporting alternate work sites; safeguards employed at alternate work sites; means of communications between personnel at alternate work sites and security personnel].
SPRS Score: 1
POA&M Allowed: Yes