{"data":{"id":"PE-06","name":"Monitoring Physical Access","family":"PE","family_name":"Physical and Environmental Protection","withdrawn":false,"description":"a. Monitor physical access to the facility where the system resides to detect and respond to physical security incidents;\nb. Review physical access logs [Assignment: organization-defined frequency] and upon occurrence of [Assignment: organization-defined events or potential indications of events]; and\nc. Coordinate results of reviews and investigations with the organizational incident response capability.","supplemental_guidance":"Physical access monitoring includes publicly accessible areas within organizational facilities. Examples of physical access monitoring include the employment of guards, video surveillance equipment (i.e., cameras), and sensor devices. Reviewing physical access logs can help identify suspicious activity, anomalous events, or potential threats. The reviews can be supported by audit logging controls, such as AU-02, if the access logs are part of an automated system. Organizational incident response capabilities include investigations of physical security incidents and responses to the incidents. Incidents include security violations or suspicious physical access activities. Suspicious physical access activities include accesses outside of normal work hours, repeated accesses to areas not normally accessed, accesses for unusual lengths of time, and out-of-sequence accesses.","enhancements":[{"id":"PE-06(01)","name":"Intrusion Alarms and Surveillance Equipment","statement":"Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment.","baselines":["moderate","high"]},{"id":"PE-06(02)","name":"Automated Intrusion Recognition and Responses","statement":"Recognize [Assignment: organization-defined classes or types of intrusions] and initiate [Assignment: organization-defined response actions] using [Assignment: organization-defined automated mechanisms].","baselines":[]},{"id":"PE-06(03)","name":"Video Surveillance","statement":"a. Employ video surveillance of [Assignment: organization-defined operational areas];\nb. Review video recordings [Assignment: organization-defined frequency]; and\nc. Retain video recordings for [Assignment: organization-defined time period].","baselines":[]},{"id":"PE-06(04)","name":"Monitoring Physical Access to Systems","statement":"Monitor physical access to the system in addition to the physical access monitoring of the facility at [Assignment: organization-defined physical spaces containing one or more components of the system].","baselines":["high"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"PE-06","name":"Monitoring Physical Access","description":"a. Monitor physical access to the facility where the system resides to detect and respond to physical security incidents;\nb. Review physical access logs [Assignment: organization-defined frequency] and upon occurrence of [Assignment: organization-defined events or potential indications of events]; and\nc. Coordinate results of reviews and investigations with the organizational incident response capability.","discussion":"Physical access monitoring includes publicly accessible areas within organizational facilities. Examples of physical access monitoring include the employment of guards, video surveillance equipment (i.e., cameras), and sensor devices. Reviewing physical access logs can help identify suspicious activity, anomalous events, or potential threats. The reviews can be supported by audit logging controls, such as AU-02, if the access logs are part of an automated system. Organizational incident response capabilities include investigations of physical security incidents and responses to the incidents. Incidents include security violations or suspicious physical access activities. Suspicious physical access activities include accesses outside of normal work hours, repeated accesses to areas not normally accessed, accesses for unusual lengths of time, and out-of-sequence accesses.","related_controls":["AU-02","AU-06","AU-09","AU-12","CA-07","CP-10","IR-04","IR-08"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.7.2","A.7.4","A.8.16"],"iso_27002_2022":["7.2","7.4"],"cobit_2019":["DSS01","DSS05"],"pci_dss_v4":["9.2"],"nist_csf_2":["DE.CM-02","PR.AA-06"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["INF.1","INF.2"],"anssi":["Hygiene.37","Hygiene.39","SecNumCloud.12.2"],"osfi_b13":["B-13.3.2","B-13.3.3"],"finma_circular":["IV.C(66)"],"gdpr":["Art.32(1)(b)","Art.32(1)(d)"],"dora":[],"bio2":["7.2","7.4"],"rbi_csf":["Annex1.3","ITGRCA.18"],"fisc":["FISC.F1"],"lgpd_bcb":[],"hkma_tme1":["TME1.5.1","TME1.11.1","TME1.11.3"],"mlps_2":["8.1.1.2","8.1.1.3","8.1.10.1"],"dnb_good_practice":["DNB.21.1","DNB.21.2"],"cra":[],"swift_cscf":["SWIFT.3.1"],"cbb_tm":["TM-10"],"nca_ecc":["1-11"],"qatar_nia":["PS"],"sama_csf":["3.7"],"uae_ia":["T6"],"bog_cisd":["CISD-XIV"],"bom_ctrm":["3.5"],"cbe_csf":["CD-1","CTO-10"],"cbn_csf":["Part10"],"sa_js2":["JS2-PE"],"bot_cyber":["Ch2.8"],"cpmi_pfmi":["CG.PR"],"eba_ict":["3.4.3"],"ecb_croe":["CROE.2.3.6"],"ffiec_is":["II.C.8"],"hipaa_sr":["§164.310(a)(1)","§164.310(a)(2)(ii)","§164.310(a)(2)(iii)"],"iosco_cyber":["PROT-5"],"sebi_cscrf":["PR.PE"],"cmmc_2":["PE"],"nerc_cip":["CIP-006-6","CIP-014-3"],"nrc_73_54":["RG5.71-B-PE"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":["Sec 14"],"awia":[],"iaea_nss":["Sec 10"],"pci_pts":["A","I"],"fips_140":["FIPS 140-3 §7.7"],"cbest":[],"tiber_eu":[],"pci_hsm":["6","7"],"common_criteria":[],"isae_3402":["Clause 4"],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["08.a"],"iso_27799":["11.1"],"lloyds_ms":["PHYS.1"],"naic_ds":["4B"],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.5"],"owasp_masvs_v2":[],"csa_ccm_v4":["DCS-07","DCS-10","DCS-11"],"csa_aicm":["DCS-07","DCS-10","DCS-11"],"ccss_v9":["1.01.1"],"mica":[],"basel_sco60":["SCO60.62"],"bssc":["NOS-09"],"sec_custody_digital":["SEC-CD-08","SEC-CD-16"],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.8.16 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"detective","used_by_patterns":["SP-002","SP-023"]}}