# PE-04 Access Control for Transmission

NIST SP 800-53 control. Family: PE Physical and Environmental Protection. Function: preventative. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls].
Guidance: Security controls applied to system distribution and transmission lines prevent accidental damage, disruption, and physical tampering. Such controls may also be necessary to prevent eavesdropping or modification of unencrypted transmissions. Security controls used to control physical access to system distribution and transmission lines include disconnected or locked spare jacks, locked wiring closets, protection of cabling by conduit or cable trays, and wiretapping sensors.

## Patterns that use it (2)
- Important (1): SP-054 CBDC and Digital Currency Infrastructure (draft)
- Standard (1): SP-023 Industrial Control Systems

## Clauses by framework (46 frameworks)
- iso_27001_2022: A.7.1, A.7.2, A.7.12. OSA's own, not in NIST's crosswalk: A.7.1
- iso_27002_2022: 7.1, 7.12
- cobit_2019: DSS01, DSS05
- nist_csf_2: PR.AA-06
- bsi_grundschutz: INF.1, INF.2
- anssi: Hygiene.26, Hygiene.37, SecNumCloud.12.2
- osfi_b13: B-13.3.2
- finma_circular: IV.C(62)
- gdpr: Art.32(1)(b)
- bio2: 7.1, 7.12
- rbi_csf: Annex1.3, ITGRCA.18
- fisc: FISC.F1
- hkma_tme1: TME1.5.1
- dnb_good_practice: DNB.21.1
- cbb_tm: TM-10
- nca_ecc: 1-11
- qatar_nia: PS
- sama_csf: 3.7
- uae_ia: T6
- bog_cisd: CISD-XIV
- bom_ctrm: 3.5
- cbe_csf: CTO-10
- cbn_csf: Part10
- sa_js2: JS2-PE
- bot_cyber: Ch2.8
- eba_ict: 3.4.3
- ecb_croe: CROE.2.3.6
- ffiec_is: II.C.8
- hipaa_sr: §164.310(a)(1)
- iosco_cyber: PROT-5
- sebi_cscrf: PR.PE
- cmmc_2: PE
- nerc_cip: CIP-006-6
- nrc_73_54: RG5.71-B-PE
- ieee_1686: 5.9
- api_1164: Sec 14
- pci_pts: A, C
- fips_140: FIPS 140-3 §7.7
- pci_hsm: 7
- hitrust_csf: 08.a
- iso_27799: 11.1
- lloyds_ms: PHYS.1
- solvency_ii: EIOPA-ICT-4.5
- csa_ccm_v4: DCS-12
- csa_aicm: DCS-12
- basel_sco60: SCO60.63
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PE-04
- Clauses only: /api/v1/controls/PE-04?fields=mappings
- Page for people: /controls/pe-04/
