03.10.06: Alternate Work Site
Control Familly: Physical Protection
SPRS: N/A
Top Ten Failed Requirement: N/A
Supporting Publications:
SP 800-46 [14]
SP 800-114 [20]
Referenced in: N/A
Control Type: N/A
CPCSC Level 2: 03.10.06
CMMC Level(s): N/A
Derived From: NIST SP 800-53r5
PE-17
a. Determine alternate work sites allowed for use by employees.
b. Employ the following security requirements at alternate work sites: [Assignment: organization-defined security requirements].
Discussion:
Alternate work sites include the private residences of employees or other facilities designated by the organization. Alternate work sites can provide readily available alternate locations during contingency operations. Organizations can define different security requirements for specific alternate work sites or types of sites, depending on the work-related activities conducted at the sites.
Assessment Methods and Objectives
Examine [SELECT FROM: physical protection policy and procedures; procedures for alternate work sites for personnel; list of security requirements for alternate work sites; assessments of security requirements at alternate work sites; system security plan; other relevant documents or records]
Interview [SELECT FROM: personnel approving the use of alternate work sites; personnel using alternate work sites; personnel assessing security requirements at alternate work sites; personnel with information security responsibilities]
Test [SELECT FROM: processes for security at alternate work sites; mechanisms for supporting alternate work sites; security requirements employed at alternate work sites; means of communication between personnel at alternate work sites and security personnel]
NIST SP 800-171A r3 Determining Statements Determine if:
A.03.10.06.ODP[01]: security requirements to be employed at alternate work sites are defined.
A.03.10.06.a: alternate work sites allowed for use by employees are determined.
A.03.10.06.b: the following security requirements are employed at alternate work sites: <A.03.10.06.ODP[01]: security requirements>.
The Security Requirements
NIST SP 800-171r3 (USA) & ITSP.10.171 (Canada)
3.5. Identification and Authentication
3.12. Security Assessment and Monitoring
3.13. System and Communications Protection
3.14. System and Information Integrity
3.16. System and Services Acquisition
3.17. Supply Chain Risk Management
CMMC 3.0 - N/A
CPCSC - N/A