| name | PE-11(2)_alternate-power-supply-self-contained |
| description | Provide an alternate power supply for the system that is activated [organization-defined] and that is: Self-contained; Not reliant on external power g |
| category | configuration |
| version | 5.2.0 |
| author | cyberstrike-official |
| tags | ["nist","sp800-53","rev5","pe-11-2","pe","enhancement"] |
| tech_stack | ["any"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | ["PE-11"] |
| severity_boost | {} |
PE-11(2) Alternate Power Supply — Self-contained
Enhancement of: PE-11
High-Level Description
Family: Physical and Environmental Protection (PE)
Framework: NIST SP 800-53 Rev 5
The provision of a long-term, self-contained power supply can be satisfied by using one or more generators with sufficient capacity to meet the needs of the organization.
What to Check
How to Test
Step 1: Review Documentation
Examine the System Security Plan (SSP) and related artifacts for PE-11(2) implementation details. Verify the organization has documented how this control is satisfied.
Step 2: Validate Implementation
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
Step 3: Test Operating Effectiveness
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
Tools
| Tool | Purpose | Usage |
|---|
| Manual Review | Documentation and interview-based | N/A |
Remediation Guide
Control Statement
Provide an alternate power supply for the system that is activated [organization-defined] and that is:
Self-contained;
Not reliant on external power generation; and
Capable of maintaining [organization-defined] in the event of an extended loss of the primary power source.
Implementation Guidance
The provision of a long-term, self-contained power supply can be satisfied by using one or more generators with sufficient capacity to meet the needs of the organization.
Risk Assessment