{"data":{"id":"PE-16","name":"Delivery and Removal","family":"PE","family_name":"Physical and Environmental Protection","withdrawn":false,"description":"a. Authorize and control [Assignment: organization-defined types of system components] entering and exiting the facility; and\nb. Maintain records of the system components.","supplemental_guidance":"Enforcing authorizations for entry and exit of system components may require restricting access to delivery areas and isolating the areas from the system and media libraries.","enhancements":[],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"PE-16","name":"Delivery and Removal","description":"a. Authorize and control [Assignment: organization-defined types of system components] entering and exiting the facility; and\nb. Maintain records of the system components.","discussion":"Enforcing authorizations for entry and exit of system components may require restricting access to delivery areas and isolating the areas from the system and media libraries.","related_controls":["CM-03","CM-08","MA-02","MA-03","MP-05","PE-20","SR-02","SR-03","SR-04","SR-06"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Changes control text by removing 'monitors'"}},"compliance_mappings":{"iso_27001_2022":["A.5.10","A.7.2","A.7.10"],"iso_27002_2022":[],"cobit_2019":["DSS01","DSS05"],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":["A1.2"],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["INF.1","INF.2"],"anssi":["Hygiene.37","SecNumCloud.12.2"],"osfi_b13":["B-13.2.1"],"finma_circular":[],"gdpr":["Art.32(1)(b)"],"dora":[],"bio2":[],"rbi_csf":["Annex1.1"],"fisc":["FISC.F3"],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"qatar_nia":["AM","PS"],"sama_csf":["3.9"],"uae_ia":["T6"],"bog_cisd":["CISD-XIV"],"ffiec_is":["II.C.8","II.C.13(d)"],"hipaa_sr":["§164.310(d)(2)(iii)"],"cmmc_2":["PE"],"nerc_cip":["CIP-006-6"],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["08.b","09.f"],"iso_27799":[],"lloyds_ms":["PHYS.1"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":["DCS-02"],"csa_aicm":["DCS-02"],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-02","review_notes":"2026-10-02: iso_27001_2022 clauses taken from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR, v1.0.0). OSA had none.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-002"]}}