{"data":{"id":"PE-07","name":"Visitor Control","family":"PE","family_name":"Physical and Environmental Protection","withdrawn":true,"incorporated_into":["PE-02","PE-03"],"description":"The organization controls physical access to the information system by authenticating visitors before authorizing access to the facility where the information system resides other than areas designated as publicly accessible.","supplemental_guidance":"Government contractors and others with permanent authorization credentials are not considered visitors. Personal Identity Verification (PIV) credentials for federal employees and contractors conform to FIPS 201, and the issuing organizations for the PIV credentials are accredited in accordance with the provisions of NIST Special Publication 800-79.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"PE-07","name":"Visitor Control","description":"","discussion":"","related_controls":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.7.6"],"iso_27002_2022":["7.2","7.6"],"cobit_2019":["DSS01","DSS05"],"pci_dss_v4":["9.2","9.3"],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["INF.1","INF.2"],"anssi":["Hygiene.37","SecNumCloud.12.2"],"osfi_b13":["B-13.3.2"],"finma_circular":[],"gdpr":[],"dora":[],"bio2":["7.2","7.6"],"rbi_csf":[],"fisc":["FISC.F1"],"lgpd_bcb":[],"hkma_tme1":["TME1.5.1"],"mlps_2":[],"dnb_good_practice":["DNB.21.2"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-10"],"qatar_nia":["PS"],"uae_ia":["T6"],"bog_cisd":["CISD-XIV"],"bom_ctrm":["3.5"],"cbe_csf":["CTO-10"],"ffiec_is":["II.C.8"],"hipaa_sr":["§164.310(a)(1)"],"cmmc_2":["PE"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["08.a"],"iso_27799":["11.1"],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-02: recorded as withdrawn in SP 800-53 Rev 5, incorporated into PE-02, PE-03, from NIST's Rev 5.2.0 catalogue. 2026-10-03: baselines LMH to ---, withdrawn in Rev 5 and in no baseline of NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-026"]}}