# PE-03 Physical Access Control

NIST SP 800-53 control. Family: PE Physical and Environmental Protection. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Enforce physical access authorizations at [Assignment: organization-defined entry and exit points to the facility where the system resides] by: 1. Verifying individual access authorizations before granting access to the facility; and 2. Controlling ingress and egress to the facility using [Selection (one or more): [Assignment: organization-defined physical access control systems or devices]; guards]; b. Maintain physical access audit logs for [Assignment: organization-defined entry or exit points]; c. Control access to areas within the facility designated as publicly accessible by implementing the following controls: [Assignment: organization-defined physical access controls]; d. Escort visitors and control visitor activity [Assignment: organization-defined circumstances requiring visitor escorts and control of visitor activity]; e. Secure keys, combinations, and other physical access devices; f. Inventory [Assignment: organization-defined physical access devices] every [Assignment: organization-defined frequency]; and g. Change combinations and keys [Assignment: organization-defined frequency] and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.
Guidance: Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors. Physical access controls for publicly accessible areas may include physical access control logs/records, guards, or physical access devices and barriers to prevent movement from publicly accessible areas to non-public areas. Organizations determine the types of guards needed, including professional security staff, system users, or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include facility access points, interior access points to systems that require supplemental access controls, or both. Components of systems may be in areas designated as publicly accessible with organizations controlling access to the components.

## Enhancements (7)
- PE-03(01) System Access. Baselines: high
- PE-03(02) Facility and Systems
- PE-03(03) Continuous Guards
- PE-03(04) Lockable Casings
- PE-03(05) Tamper Protection
- PE-03(07) Physical Barriers
- PE-03(08) Access Control Vestibules
Withdrawn by NIST: PE-03(06) (now in CA-08).
Each enhancement's statement: /api/v1/controls/PE-03?fields=enhancements

## Patterns that use it (8)
- Critical (1): SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (5): SP-002 Server Module; SP-023 Industrial Control Systems; SP-026 PCI Full Environment; SP-051 Tokenised Asset Security Architecture (draft); SP-053 Zero-Knowledge Proof Architecture (draft)
- Standard (2): SP-013 Data Security Pattern; SP-037 Privileged User Management

## Clauses by framework (64 frameworks)
- iso_27001_2022: A.7.1, A.7.2, A.7.3, A.7.4, A.7.6. OSA's own, not in NIST's crosswalk: A.7.6
- iso_27002_2022: 7.1, 7.2, 7.3, 7.6
- cobit_2019: DSS01, DSS05
- pci_dss_v4: 9.2, 9.3, 9.5
- nist_csf_2: DE.CM-02, PR.AA-06
- soc2_tsc: CC6.4
- bsi_grundschutz: INF.1, INF.2
- anssi: Hygiene.37, SecNumCloud.12.2
- osfi_b13: B-13.3.2
- finma_circular: IV.B.d(59)
- gdpr: Art.32(1)(b)
- dora: Art.9(1)
- bio2: 7.1, 7.2, 7.3, 7.6
- rbi_csf: Annex1.3, ITGRCA.18
- fisc: FISC.F1
- lgpd_bcb: LGPD.Art.46
- hkma_tme1: TME1.5.1, TME1.11.1, TME1.11.3
- mlps_2: 8.1.1.2, 8.1.1.3, 8.1.10.1, 8.4, 8.5
- dnb_good_practice: DNB.21.1, DNB.21.2
- swift_cscf: SWIFT.3.1, SWIFT.5.2
- cbb_tm: TM-10
- nca_ecc: 1-11, 5-1
- qatar_nia: PS
- sama_csf: 3.7
- uae_ia: T6
- bog_cisd: CISD-XIV
- bom_ctrm: 3.5
- cbe_csf: CTO-10
- cbn_csf: Part10
- popia: s19
- sa_js2: JS2-PE
- bot_cyber: Ch2.8
- cpmi_pfmi: CG.PR
- eba_ict: 3.4.3
- ecb_croe: CROE.2.3.6
- ffiec_is: II.C.8, II.C.13(a)
- hipaa_sr: §164.310(a)(1), §164.310(a)(2)(i), §164.310(a)(2)(ii), §164.310(a)(2)(iii), §164.310(c)
- iosco_cyber: PROT-5
- sebi_cscrf: PR.PE
- cmmc_2: PE
- nerc_cip: CIP-006-6, CIP-014-3
- nrc_73_54: RG5.71-B-PE
- ferc_cip: Order 850, Order 888
- api_1164: Sec 14
- awia: AWWA Sec 3
- iaea_nss: Sec 10
- pci_pts: A, D, I
- fips_140: FIPS 140-3 §7.7
- tiber_eu: TIBER.CONF
- pci_hsm: 2, 6, 7
- isae_3402: Clause 4
- hitrust_csf: 08.a
- iso_27799: 11.1
- lloyds_ms: PHYS.1
- naic_ds: 4B
- pra_ss1_23: P-IT.3
- solvency_ii: EIOPA-ICT-4.5
- csa_ccm_v4: DCS-03, DCS-07, DCS-09
- csa_aicm: DCS-03, DCS-07, DCS-09
- ccss_v9: 1.01.1, 1.01.7, 1.03.6, 1.05.5
- basel_sco60: SCO60.61, SCO60.62, SCO60.64
- bssc: KMS-03, KMS-05, KMS-09, NOS-09
- sec_custody_digital: SEC-CD-02, SEC-CD-06, SEC-CD-08, SEC-CD-16
- dpdpa: Rules.6(1)(b)
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PE-03
- Clauses only: /api/v1/controls/PE-03?fields=mappings
- Page for people: /controls/pe-03/
