# PE-05 Access Control for Output Devices

NIST SP 800-53 control. Family: PE Physical and Environmental Protection. Function: preventative. Baselines: moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output.
Guidance: Controlling physical access to output devices includes placing output devices in locked rooms or other secured areas with keypad or card reader access controls and allowing access to authorized individuals only, placing output devices in locations that can be monitored by personnel, installing monitor or screen filters, and using headphones. Examples of output devices include monitors, printers, scanners, audio devices, facsimile machines, and copiers.

## Enhancements (1)
- PE-05(02) Link to Individual Identity
Withdrawn by NIST: PE-05(01) (now in PE-05); PE-05(03) (now in PE-22).
Each enhancement's statement: /api/v1/controls/PE-05?fields=enhancements

## Patterns that use it (1)
- Standard (1): SP-002 Server Module

## Clauses by framework (43 frameworks)
- iso_27001_2022: A.7.2, A.7.3, A.7.7
- iso_27002_2022: 7.3, 7.7
- cobit_2019: DSS01, DSS05
- nist_csf_2: PR.AA-06
- soc2_tsc: PI1.4
- bsi_grundschutz: INF.1, INF.2
- anssi: Hygiene.37, SecNumCloud.12.2
- osfi_b13: B-13.3.2
- gdpr: Art.32(1)(b)
- bio2: 7.3, 7.7
- rbi_csf: Annex1.3, ITGRCA.18
- fisc: FISC.F1
- mlps_2: 8.1.1.3
- dnb_good_practice: DNB.21.1
- cbb_tm: TM-10
- nca_ecc: 1-11
- qatar_nia: PS
- sama_csf: 3.7
- uae_ia: T6
- bog_cisd: CISD-XIV
- bom_ctrm: 3.5
- cbe_csf: CTO-10
- cbn_csf: Part10
- sa_js2: JS2-PE
- bot_cyber: Ch2.8
- eba_ict: 3.4.3
- ecb_croe: CROE.2.3.6
- ffiec_is: II.C.8
- hipaa_sr: §164.310(a)(1)
- iosco_cyber: PROT-5
- sebi_cscrf: PR.PE
- cmmc_2: PE
- nerc_cip: CIP-006-6
- pci_pts: A
- fips_140: FIPS 140-3 §7.7
- pci_hsm: 7
- hitrust_csf: 08.a
- iso_27799: 9.4, 11.1
- lloyds_ms: PHYS.1
- solvency_ii: EIOPA-ICT-4.5
- csa_ccm_v4: DCS-06, DCS-15
- csa_aicm: DCS-06, DCS-15
- basel_sco60: SCO60.61, SCO60.64
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PE-05
- Clauses only: /api/v1/controls/PE-05?fields=mappings
- Page for people: /controls/pe-05/
