Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.AA-06 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AA-06: Physical access to assets is managed, monitored, and enforced commensurate with risk Physical access to assets is managed, monitored, and enforced commensurate with risk
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 129 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
5.15 Access control 7.1 Physical security perimeters 7.10 Storage media 7.2 Physical entry 7.3 Securing offices, rooms and facilities 7.4 Physical security monitoring 7.6 Working in secure areas 7.7 Clear desk and clear screen 8.1 User endpoint devices 5.15 Access control 5.33 Protection of records 7.1 Physical security perimeters 7.2 Physical entry 7.3 Securing offices, rooms and facilities 7.4 Physical security monitoring 7.6 Working in secure areas 8.3 Information access restriction 9.2.1 9.2.1 Facility entry controls for CDE systems 9.2.1.1 9.2.1.1 Monitoring of entry to sensitive areas 9.2.2 9.2.2 Controls on publicly accessible network jacks 9.3.1 9.3.1 Personnel physical access procedures for the CDE 9.3.1.1 9.3.1.1 Personnel access to sensitive areas controlled 9.3.2 9.3.2 Visitor access procedures for the CDE 9.3.3 9.3.3 Visitor badges returned or deactivated 9.3.4 9.3.4 Visitor logs for facility and sensitive areas CM-5 Access Restrictions for Change MP-5 Media Transport PE-16 Delivery and Removal PE-2 Physical Access Authorizations PE-3 Physical Access Control PE-6 Monitoring Physical Access PE-8 Visitor Access Records CM-5 Access Restrictions for Change MP-5 Media Transport PE-16 Delivery and Removal PE-2 Physical Access Authorizations PE-3 Physical Access Control PE-6 Monitoring Physical Access PE-8 Visitor Access Records ISM-0810 Security zones for classified systems ISM-1053 Zoned rooms for classified infrastructure ISM-1074 Controlling keys to secure areas C5-PS-01 Physical Security and Environmental Control Requirements C5-PS-03 Perimeter Protection C5-PS-04 Physical site access control ANSSI-HYG-26 Control and Protect Access to Server Rooms and Technical Areas ANSSI-HYG-30 Apply Physical Protection Measures to Mobile Devices 27011-7.1 Physical security perimeters 27011-7.3 Equipment protection PR.AC-2 PR.AC-2: Physical access to assets is managed and protected PR.PT-4 PR.PT-4: Communications and control networks are protected PR.AC-2 PR.AC-2: Physical access to assets is managed and protected PR.PT-4 PR.PT-4: Communications and control networks are protected SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets SEMD-PS-1 Critical Infrastructure Protection SEMD-PS-2 Site Security Measures 58.43 Animal Care Facilities AWWA-2.4 Physical Access Controls AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV) CFTC-SS-6 Physical Security and Environmental Controls Category CJIS-14 Physical Protection ISO28001-PS-01 Facility Security 27010-11.1 Physical Protection 27400-5.2 IoT Risk Assessment Art.21.2.i Human resources security, access control policies and asset management NISTPF-5 Protect-P Access Control (PR.AC-P) NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access SOC-CY-S1 Logical and Physical Access Controls SSAE18-CC6.4 CC6.4 - Physical Access Restrictions SOCI-CIRMP-PHYSICAL CIRMP hazard vector: Physical security and natural hazards GT-2 Physical Security Threats UKGAMBLE-4 Resilience and Incident Response Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AA-06 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 129 it maps to, and the evidence behind each claim, over MCP and REST.