NIST 800-53 Rev 5

424 controls available

PE-3lowmoderatehigh

Physical Access Control

Physical and Environmental Protection

Control Statement

Enforce physical access authorizations at {{ insert: param, pe-03_odp.01 }} by: Verifying individual access authorizations before granting access to the facility; and Controlling ingress and egress to the facility using {{ insert: param, pe-03_odp.02 }}; Maintain physical access audit logs for {{ insert: param, pe-03_odp.04 }}; Control access to areas within the facility designated as publicly accessible by implementing the following controls: {{ insert: param, pe-03_odp.05 }}; Escort visitors and control visitor activity {{ insert: param, pe-03_odp.06 }}; Secure keys, combinations, and other physical access devices; Inventory {{ insert: param, pe-03_odp.07 }} every {{ insert: param, pe-03_odp.08 }} ; and Change combinations and keys {{ insert: param, pe-3_prm_9 }} and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.

Discussion

Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors. Physical access controls for publicly accessible areas may include physical access control logs/records, guards, or physical access devices and barriers to prevent movement from publicly accessible areas to non-public areas. Organizations determine the types of guards needed, including professional security staff, system users, or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include facility access points, interior access points to systems that require supplemental access controls, or both. Components of systems may be in areas designated as publicly accessible with organizations controlling access to the components.

Framework
NIST SP 800-53 Rev 5
Family
Physical and Environmental Protection
Baselines
low, moderate, high

Related Frameworks

26 paths across 2 frameworks
NIST 800-1713 mappings
3.10.3
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.10.4
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
3.10.5
1.00
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI23 mappings
CCI-000919
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000920
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000921
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000923
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000924
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000925
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000926
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-000927
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002915
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002916
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002917
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002918
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002919
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002920
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002921
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002922
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002923
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002924
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-002925
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004240
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004241
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004242
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-004243
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

1 STIG reach this control through 38 CCIs. Expand a row to see the responsible NICE and O*NET roles.

Network Device

1 STIG