Authorised Economic Operator (AEO) Programmes - Global Standards
AEO Conditions and Requirements (SAFE Annex IV)

Authorised Economic Operator (AEO) Programmes - Global Standards AEO-5: Premises Security

The operator implements security measures and procedures to secure buildings and to monitor and control exterior and interior perimeters, in accordance with its business model and risk analysis.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 54 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 5 controls

ISO 27001:2022 · 4 controls

  • 7.1 Physical security perimeters
  • 7.2 Physical entry
  • 7.3 Securing offices, rooms and facilities
  • 7.4 Physical security monitoring

ISO 27002:2022 · 4 controls

  • 7.1 Physical security perimeters
  • 7.2 Physical entry
  • 7.3 Securing offices, rooms and facilities
  • 7.4 Physical security monitoring

CMMC 2.0 · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

PCI DSS 4.0 · 3 controls

  • 9.2.1 9.2.1 Facility entry controls for CDE systems
  • 9.2.1.1 9.2.1.1 Monitoring of entry to sensitive areas
  • 9.3.1 9.3.1 Personnel physical access procedures for the CDE

FedRAMP High · 2 controls

  • PE-3 Physical Access Control
  • PE-6 Monitoring Physical Access

FedRAMP Moderate · 2 controls

  • PE-3 Physical Access Control
  • PE-6 Monitoring Physical Access

HIPAA Security Rule · 2 controls

  • NIST-CSF-DE.CM-02 The physical environment is monitored to find potentially adverse events
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk

NIST SP 800-66 Rev 2 · 2 controls

  • ACQS-7-3 Worker Screening
  • ASBv3-GS-9 Define and implement endpoint security strategy
  • CJIS-3 Personnel Security

FDA 21 CFR Part 11 · 1 control

  • Part11.10 Controls for closed systems (21 CFR §11.10)
  • ICAO-ANX17-Chap4-AccessControl-AirsideRestricted-Personnel-Background ICAO Annex 17 Chapter 4 - Access Control + Airside + Security Restricted Area + Personnel Background Checks + Vetting

ISO 27799:2025 · 1 control

  • ISO27799-07 Workforce security and clearance procedures
  • ISO28001-PI-01 Personnel Security Screening

ISO/IEC 27010:2015 · 1 control

  • 27010-7.1 Information Classification for Sharing

MARS-E · 1 control

  • MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring

NIST SP 800-66 · 1 control

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • PASONE-3 Personnel Security, Vetting, Awareness, and Training
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight

SOC 2 · 1 control

  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • SOCI-CIRMP-PERSONNEL CIRMP hazard vector: Personnel
  • UKGAMBLE-4 Resilience and Incident Response

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AEO Conditions and Requirements (SAFE Annex IV)

Query this from an agent

The graph holds this control, the 54 it maps to, and the evidence behind each claim, over MCP and REST.