Site access and the perimeter should be clearly delineated: a defined boundary removes ambiguity about unauthorised entry and makes an intruder's intent plain. Even public sites can control access by organising traffic flows and separating parking from other vehicles; fewer entry and exit points make them easier to watch; controlling where and how much parking and delivery takes place manages the risk from people or vehicles not fully searched (for example a separate lot for pre-screened vehicles frees resources for higher-risk areas); and keeping deliveries apart from other traffic makes delivery vehicles and staff easier to observe. At minimum, site access should be monitored, if not controlled.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.