{"data":{"id":"PE-05","name":"Access Control for Output Devices","family":"PE","family_name":"Physical and Environmental Protection","withdrawn":false,"description":"Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output.","supplemental_guidance":"Controlling physical access to output devices includes placing output devices in locked rooms or other secured areas with keypad or card reader access controls and allowing access to authorized individuals only, placing output devices in locations that can be monitored by personnel, installing monitor or screen filters, and using headphones. Examples of output devices include monitors, printers, scanners, audio devices, facsimile machines, and copiers.","enhancements":[{"id":"PE-05(01)","name":"Access to Output by Authorized Individuals","withdrawn":true,"incorporated_into":["PE-05"]},{"id":"PE-05(02)","name":"Link to Individual Identity","statement":"Link individual identity to receipt of output from output devices.","baselines":[]},{"id":"PE-05(03)","name":"Marking Output Devices","withdrawn":true,"incorporated_into":["PE-22"]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"PE-05","name":"Access Control for Output Devices","description":"Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output.","discussion":"Controlling physical access to output devices includes placing output devices in locked rooms or other secured areas with keypad or card reader access controls and allowing access to authorized individuals only, placing output devices in locations that can be monitored by personnel, installing monitor or screen filters, and using headphones. Examples of output devices include monitors, printers, scanners, audio devices, facsimile machines, and copiers.","related_controls":["PE-02","PE-03","PE-04","PE-18"],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Parameter for specifying output devices Incorporates withdrawn control PE-05(1)"}},"compliance_mappings":{"iso_27001_2022":["A.7.2","A.7.3","A.7.7"],"iso_27002_2022":["7.3","7.7"],"cobit_2019":["DSS01","DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.AA-06"],"cis_controls_v8":[],"soc2_tsc":["PI1.4"],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["INF.1","INF.2"],"anssi":["Hygiene.37","SecNumCloud.12.2"],"osfi_b13":["B-13.3.2"],"finma_circular":[],"gdpr":["Art.32(1)(b)"],"dora":[],"bio2":["7.3","7.7"],"rbi_csf":["Annex1.3","ITGRCA.18"],"fisc":["FISC.F1"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":["8.1.1.3"],"dnb_good_practice":["DNB.21.1"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-10"],"nca_ecc":["1-11"],"qatar_nia":["PS"],"sama_csf":["3.7"],"uae_ia":["T6"],"bog_cisd":["CISD-XIV"],"bom_ctrm":["3.5"],"cbe_csf":["CTO-10"],"cbn_csf":["Part10"],"sa_js2":["JS2-PE"],"bot_cyber":["Ch2.8"],"eba_ict":["3.4.3"],"ecb_croe":["CROE.2.3.6"],"ffiec_is":["II.C.8"],"hipaa_sr":["§164.310(a)(1)"],"iosco_cyber":["PROT-5"],"sebi_cscrf":["PR.PE"],"cmmc_2":["PE"],"nerc_cip":["CIP-006-6"],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":["A"],"fips_140":["FIPS 140-3 §7.7"],"cbest":[],"tiber_eu":[],"pci_hsm":["7"],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["08.a"],"iso_27799":["9.4","11.1"],"lloyds_ms":["PHYS.1"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.5"],"owasp_masvs_v2":[],"csa_ccm_v4":["DCS-06","DCS-15"],"csa_aicm":["DCS-06","DCS-15"],"ccss_v9":[],"mica":[],"basel_sco60":["SCO60.61","SCO60.64"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.7.2, A.7.7 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.AA-06 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-002"]}}