NIST 800-53 REV 5 • PHYSICAL AND ENVIRONMENTAL PROTECTION
PE-18(1) — Facility Site
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
No related controls listed
Practitioner Notes
This enhancement considers the security of the facility site itself — its geographic location and surrounding environment — when planning where to locate system components.
Example 1: When selecting a new facility or data center location, evaluate the risk from natural hazards (flood zone, earthquake zone, tornado alley), proximity to high-risk targets (military bases, chemical plants), and crime rates in the area. Document this risk assessment.
Example 2: Review FEMA flood maps and local hazard assessments before leasing or purchasing a facility. Avoid locations in 100-year flood plains. Consider proximity to emergency services (fire station, hospital). Include site risk factors in your risk management documentation.