{"data":{"id":"PE-04","name":"Access Control for Transmission","family":"PE","family_name":"Physical and Environmental Protection","withdrawn":false,"description":"Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls].","supplemental_guidance":"Security controls applied to system distribution and transmission lines prevent accidental damage, disruption, and physical tampering. Such controls may also be necessary to prevent eavesdropping or modification of unencrypted transmissions. Security controls used to control physical access to system distribution and transmission lines include disconnected or locked spare jacks, locked wiring closets, protection of cabling by conduit or cable trays, and wiretapping sensors.","enhancements":[],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"PE-04","name":"Access Control for Transmission","description":"Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls].","discussion":"Security controls applied to system distribution and transmission lines prevent accidental damage, disruption, and physical tampering. Such controls may also be necessary to prevent eavesdropping or modification of unencrypted transmissions. Security controls used to control physical access to system distribution and transmission lines include disconnected or locked spare jacks, locked wiring closets, protection of cabling by conduit or cable trays, and wiretapping sensors.","related_controls":["AT-03","IA-04","MP-02","MP-04","PE-02","PE-03","PE-05","PE-09","SC-07","SC-08"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Access Control for Transmission Medium' Changes parameter text from 'safeguards' to 'controls' Discussion includes additional examples"}},"compliance_mappings":{"iso_27001_2022":["A.7.1","A.7.2","A.7.12"],"iso_27002_2022":["7.1","7.12"],"cobit_2019":["DSS01","DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.AA-06"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["INF.1","INF.2"],"anssi":["Hygiene.26","Hygiene.37","SecNumCloud.12.2"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.C(62)"],"gdpr":["Art.32(1)(b)"],"dora":[],"bio2":["7.1","7.12"],"rbi_csf":["Annex1.3","ITGRCA.18"],"fisc":["FISC.F1"],"lgpd_bcb":[],"hkma_tme1":["TME1.5.1"],"mlps_2":[],"dnb_good_practice":["DNB.21.1"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-10"],"nca_ecc":["1-11"],"qatar_nia":["PS"],"sama_csf":["3.7"],"uae_ia":["T6"],"bog_cisd":["CISD-XIV"],"bom_ctrm":["3.5"],"cbe_csf":["CTO-10"],"cbn_csf":["Part10"],"sa_js2":["JS2-PE"],"bot_cyber":["Ch2.8"],"eba_ict":["3.4.3"],"ecb_croe":["CROE.2.3.6"],"ffiec_is":["II.C.8"],"hipaa_sr":["§164.310(a)(1)"],"iosco_cyber":["PROT-5"],"sebi_cscrf":["PR.PE"],"cmmc_2":["PE"],"nerc_cip":["CIP-006-6"],"nrc_73_54":["RG5.71-B-PE"],"tsa_psd":[],"ieee_1686":["5.9"],"ferc_cip":[],"doe_c2m2":[],"api_1164":["Sec 14"],"awia":[],"iaea_nss":[],"pci_pts":["A","C"],"fips_140":["FIPS 140-3 §7.7"],"cbest":[],"tiber_eu":[],"pci_hsm":["7"],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["08.a"],"iso_27799":["11.1"],"lloyds_ms":["PHYS.1"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.5"],"owasp_masvs_v2":[],"csa_ccm_v4":["DCS-12"],"csa_aicm":["DCS-12"],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.63"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.7.2 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.AA-06 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-023","SP-054"]}}