- Write alternate-work-site rules people can follow at home: device lock, no household sharing of equipment, handling for paper CUI, and where physical documents may not go.
- Lean on protections that travel with the device — full-disk encryption, VPN, managed configuration — so the site-specific burden stays small.
03.10.06 — Alternate Work Site
03.10 Physical Protection · NIST SP 800-171 Rev. 3
Requires determining the alternate work sites allowed for use by employees and employing organization-defined security requirements at those sites.
Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.
NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI ↗What this requirement is after
Home offices and other off-facility work locations are part of the environment, not an exception to it. The organization decides where CUI work may happen away from the facility and which protections apply there — screen privacy, locked storage, network expectations — instead of leaving remote work ungoverned.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- The alternate work site policy naming allowed sites and required safeguards
- Remote-work attestations or spot-check records where operated
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this came from in Rev. 2
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |