← Controls / PE

PE-03 Physical Access Control

Physical and Environmental Protection

Low Moderate High

Description

a. Enforce physical access authorizations at [Assignment: organization-defined entry and exit points to the facility where the system resides] by: 1. Verifying individual access authorizations before granting access to the facility; and 2. Controlling ingress and egress to the facility using [Selection (one or more): [Assignment: organization-defined physical access control systems or devices]; guards]; b. Maintain physical access audit logs for [Assignment: organization-defined entry or exit points]; c. Control access to areas within the facility designated as publicly accessible by implementing the following controls: [Assignment: organization-defined physical access controls]; d. Escort visitors and control visitor activity [Assignment: organization-defined circumstances requiring visitor escorts and control of visitor activity]; e. Secure keys, combinations, and other physical access devices; f. Inventory [Assignment: organization-defined physical access devices] every [Assignment: organization-defined frequency]; and g. Change combinations and keys [Assignment: organization-defined frequency] and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.

Supplemental Guidance

Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors. Physical access controls for publicly accessible areas may include physical access control logs/records, guards, or physical access devices and barriers to prevent movement from publicly accessible areas to non-public areas. Organizations determine the types of guards needed, including professional security staff, system users, or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include facility access points, interior access points to systems that require supplemental access controls, or both. Components of systems may be in areas designated as publicly accessible with organizations controlling access to the components.

Changes from Rev 4

Parameter from 'security safeguards' to 'physical access controls' Parameter changed from 'monitoring' to 'control of visitor activity' Discussion expanded to address physical access controls for publicly accessible areas

Enhancements (7)

What NIST adds to this control. Select one to read its statement.

PE-03(01) System Access High

Enforce physical access authorizations to the system in addition to the physical access controls for the facility at [Assignment: organization-defined physical spaces containing one or more components of the system].

PE-03(02) Facility and Systems

Perform security checks [Assignment: organization-defined frequency] at the physical perimeter of the facility or system for exfiltration of information or removal of system components.

PE-03(03) Continuous Guards

Employ guards to control [Assignment: organization-defined physical access points] to the facility where the system resides 24 hours per day, 7 days per week.

PE-03(04) Lockable Casings

Use lockable physical casings to protect [Assignment: organization-defined system components] from unauthorized physical access.

PE-03(05) Tamper Protection

Employ [Assignment: organization-defined anti-tamper technologies] to [Selection (one or more): detect; prevent] physical tampering or alteration of [Assignment: organization-defined hardware components] within the system.

PE-03(07) Physical Barriers

Limit access using physical barriers.

PE-03(08) Access Control Vestibules

Employ access control vestibules at [Assignment: organization-defined locations within the facility].

Withdrawn by NIST:

  • PE-03(06) Facility Penetration Testing, now in CA-08

Compliance Mappings

ISO 27001:2022

A.7.1A.7.2A.7.3A.7.4A.7.6

ISO 27002:2022

7.17.27.37.6

COBIT 2019

DSS01DSS05

NIST CSF 2.0

DE.CM-02PR.AA-06

SOC 2 TSC

CC6.4

PCI DSS v4.0.1

9.29.39.5

CSA CCM v4

DCS-03DCS-07DCS-09

CSA AICM v1

DCS-03DCS-07DCS-09

BSI IT-Grundschutz

INF.1INF.2

ANSSI

Hygiene.37SecNumCloud.12.2

FINMA Circular 2023/1

IV.B.d(59)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(b)

EU DORA

Art.9(1)

BIO2

7.17.27.37.6

RBI CSF

Annex1.3ITGRCA.18

FISC Security Guidelines

FISC.F1

LGPD + BCB 4893

LGPD.Art.46

HKMA TM-E-1

TME1.5.1TME1.11.1TME1.11.3

MLPS 2.0

8.1.1.28.1.1.38.1.10.18.48.5

DNB Good Practice

DNB.21.1DNB.21.2

SWIFT CSCF

SWIFT.3.1SWIFT.5.2

SAMA CSF

3.7

NCA ECC

1-115-1

UAE IA

T6

CBB TM

TM-10

Qatar NIA

PS

CBE CSF

CTO-10

SA JS2

JS2-PE

CBN CSF

Part10

BoG CISD

CISD-XIV

POPIA

s19

BoM CTRM

3.5

IOSCO Cyber Resilience

PROT-5

CPMI-IOSCO PFMI

CG.PR

FFIEC IS

II.C.8II.C.13(a)

HIPAA Security Rule

§164.310(a)(1)§164.310(a)(2)(i)§164.310(a)(2)(ii)§164.310(a)(2)(iii)§164.310(c)

ECB CROE

CROE.2.3.6

EBA ICT Guidelines

3.4.3

SEBI CSCRF

PR.PE

BOT Cyber Resilience

Ch2.8

CMMC 2.0

PE

NERC CIP

CIP-006-6CIP-014-3

10 CFR 73.54

RG5.71-B-PE

FERC CIP Orders

Order 850Order 888

API 1164

Sec 14

AWIA

AWWA Sec 3

IAEA NSS 17-T

Sec 10

PCI PTS v6

ADI

FIPS 140-3

FIPS 140-3 §7.7

TIBER-EU

TIBER.CONF

PCI HSM

267

ISAE 3402

Clause 4

Solvency II

EIOPA-ICT-4.5

Lloyd's Minimum Standards

PHYS.1

NAIC Insurance Data Security

4B

PRA SS1/23

P-IT.3

HITRUST CSF v11

08.a

ISO 27799

11.1

CCSS v9.0

1.01.11.01.71.03.61.05.5

Basel SCO60

SCO60.61SCO60.62SCO60.64

BSSC Standards

KMS-03KMS-05KMS-09NOS-09

SEC Custody (Digital Assets)

SEC-CD-02SEC-CD-06SEC-CD-08SEC-CD-16

India DPDPA

Rules.6(1)(b)

ISO 17799 (legacy)

9.1.19.1.29.1.59.1.610.5.1

COBIT 4.1 (legacy)

DS12.2