# PE-07 Visitor Control

NIST SP 800-53 control. Family: PE Physical and Environmental Protection. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.
Withdrawn from SP 800-53 by NIST. Its content moved into PE-02, PE-03.

Statement: The organization controls physical access to the information system by authenticating visitors before authorizing access to the facility where the information system resides other than areas designated as publicly accessible.
Guidance: Government contractors and others with permanent authorization credentials are not considered visitors. Personal Identity Verification (PIV) credentials for federal employees and contractors conform to FIPS 201, and the issuing organizations for the PIV credentials are accredited in accordance with the provisions of NIST Special Publication 800-79.

## Patterns that use it (1)
- Standard (1): SP-026 PCI Full Environment

## Clauses by framework (22 frameworks)
- iso_27001_2022: A.7.6. OSA's own, not in NIST's crosswalk: A.7.6
- iso_27002_2022: 7.2, 7.6
- cobit_2019: DSS01, DSS05
- pci_dss_v4: 9.2, 9.3
- bsi_grundschutz: INF.1, INF.2
- anssi: Hygiene.37, SecNumCloud.12.2
- osfi_b13: B-13.3.2
- bio2: 7.2, 7.6
- fisc: FISC.F1
- hkma_tme1: TME1.5.1
- dnb_good_practice: DNB.21.2
- cbb_tm: TM-10
- qatar_nia: PS
- uae_ia: T6
- bog_cisd: CISD-XIV
- bom_ctrm: 3.5
- cbe_csf: CTO-10
- ffiec_is: II.C.8
- hipaa_sr: §164.310(a)(1)
- cmmc_2: PE
- hitrust_csf: 08.a
- iso_27799: 11.1
OSA's mapping for iso_27001_2022 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PE-07
- Clauses only: /api/v1/controls/PE-07?fields=mappings
- Page for people: /controls/pe-07/
