Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.10.06OFFICIAL TITLEPENDING NIST SME REVIEW

03.10.06Alternate Work Site

03.10 Physical Protection · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires determining the alternate work sites allowed for use by employees and employing organization-defined security requirements at those sites.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Home offices and other off-facility work locations are part of the environment, not an exception to it. The organization decides where CUI work may happen away from the facility and which protections apply there — screen privacy, locked storage, network expectations — instead of leaving remote work ungoverned.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Write alternate-work-site rules people can follow at home: device lock, no household sharing of equipment, handling for paper CUI, and where physical documents may not go.
  • Lean on protections that travel with the device — full-disk encryption, VPN, managed configuration — so the site-specific burden stays small.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The alternate work site policy naming allowed sites and required safeguards
  • Remote-work attestations or spot-check records where operated
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated