← Controls / PE

PE-05 Access Control for Output Devices

Physical and Environmental Protection

Moderate High

Description

Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output.

Supplemental Guidance

Controlling physical access to output devices includes placing output devices in locked rooms or other secured areas with keypad or card reader access controls and allowing access to authorized individuals only, placing output devices in locations that can be monitored by personnel, installing monitor or screen filters, and using headphones. Examples of output devices include monitors, printers, scanners, audio devices, facsimile machines, and copiers.

Changes from Rev 4

Parameter for specifying output devices Incorporates withdrawn control PE-05(1)

Enhancements (1)

What NIST adds to this control. Select one to read its statement.

PE-05(02) Link to Individual Identity

Link individual identity to receipt of output from output devices.

Withdrawn by NIST:

  • PE-05(01) Access to Output by Authorized Individuals, now in PE-05
  • PE-05(03) Marking Output Devices, now in PE-22

Patterns that use this control (1)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

A.7.2A.7.3A.7.7

ISO 27002:2022

7.37.7

COBIT 2019

DSS01DSS05

NIST CSF 2.0

PR.AA-06

SOC 2 TSC

PI1.4

CSA CCM v4

DCS-06DCS-15

CSA AICM v1

DCS-06DCS-15

BSI IT-Grundschutz

INF.1INF.2

ANSSI

Hygiene.37SecNumCloud.12.2

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(b)

BIO2

7.37.7

RBI CSF

Annex1.3ITGRCA.18

FISC Security Guidelines

FISC.F1

MLPS 2.0

8.1.1.3

DNB Good Practice

DNB.21.1

SAMA CSF

3.7

NCA ECC

1-11

UAE IA

T6

CBB TM

TM-10

Qatar NIA

PS

CBE CSF

CTO-10

SA JS2

JS2-PE

CBN CSF

Part10

BoG CISD

CISD-XIV

BoM CTRM

3.5

IOSCO Cyber Resilience

PROT-5

FFIEC IS

II.C.8

HIPAA Security Rule

§164.310(a)(1)

ECB CROE

CROE.2.3.6

EBA ICT Guidelines

3.4.3

SEBI CSCRF

PR.PE

BOT Cyber Resilience

Ch2.8

CMMC 2.0

PE

NERC CIP

CIP-006-6

PCI PTS v6

A

FIPS 140-3

FIPS 140-3 §7.7

PCI HSM

7

Solvency II

EIOPA-ICT-4.5

Lloyd's Minimum Standards

PHYS.1

HITRUST CSF v11

08.a

ISO 27799

9.411.1

Basel SCO60

SCO60.61SCO60.64

ISO 17799 (legacy)

9.1.211.3.3

COBIT 4.1 (legacy)

DS12.2