PE-16 Delivery and Removal
Physical and Environmental Protection
Low Moderate High
Description
a. Authorize and control [Assignment: organization-defined types of system components] entering and exiting the facility; and b. Maintain records of the system components.
Supplemental Guidance
Enforcing authorizations for entry and exit of system components may require restricting access to delivery areas and isolating the areas from the system and media libraries.
Changes from Rev 4
Changes control text by removing 'monitors'
Patterns that use this control (1)
Grouped by the emphasis each pattern gives it.
Standard (1)
Compliance Mappings
ISO 27001:2022
A.5.10A.7.2A.7.10
COBIT 2019
DSS01DSS05
SOC 2 TSC
A1.2
CSA CCM v4
DCS-02
CSA AICM v1
DCS-02
BSI IT-Grundschutz
INF.1INF.2
ANSSI
Hygiene.37SecNumCloud.12.2
OSFI B-13
B-13.2.1
EU GDPR
Art.32(1)(b)
RBI CSF
Annex1.1
FISC Security Guidelines
FISC.F3
SAMA CSF
3.9
UAE IA
T6
Qatar NIA
AMPS
BoG CISD
CISD-XIV
FFIEC IS
II.C.8II.C.13(d)
HIPAA Security Rule
§164.310(d)(2)(iii)
CMMC 2.0
PE
NERC CIP
CIP-006-6
Lloyd's Minimum Standards
PHYS.1
HITRUST CSF v11
08.b09.f
ISO 17799 (legacy)
9.1.69.2.710.7.1
COBIT 4.1 (legacy)
DS12.2