NIST SP 800-53 Rev 5 MODERATE
PE Physical and Environmental Protection

NIST SP 800-53 Rev 5 MODERATE PE-16: Delivery and Removal

Authorize and control system components entering/exiting facility; maintain records.

What else in your programme already covers this

This control maps to 27 controls across 13 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-1.2 Address Unauthorized Assets
  • CIS-8.2 Collect Audit Logs
  • CIS-8.9 Centralize Audit Logs
  • NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk

SOC 2 · 4 controls

  • SOC2-C1.2 Confidential information is disposed of securely
  • SOC2-CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives
  • SOC2-CC6.7 Transmission of data is restricted to authorized users
  • SOC2-P4.3 Personal information is securely disposed of
  • CCM-DCS-01 Off-Site Equipment Disposal Policy and Procedures
  • CCM-DCS-02 Off-Site Transfer Authorization Policy and Procedures
  • CCM-DCS-07 Controlled Access Points

ISO 27001:2022 · 2 controls

  • 7.1 Physical security perimeters
  • 7.9 Security of assets off-premises

ISO 27002:2022 · 2 controls

  • 7.2 Physical entry
  • 7.9 Security of assets off-premises

PCI DSS 4.0 · 2 controls

  • 9.4.3 Media sent outside facility secured
  • 9.4.5 Inventory logs of electronic media

C5 (Germany) · 1 control

HIPAA Security Rule · 1 control

ISO 27701:2019 · 1 control

  • NIST800-PE-16 Delivery and Removal. Authorize and control [organization-defined] entering and exiting the facility; and Maintain records of the system components

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PE Physical and Environmental Protection

Query this from an agent

The graph holds this control, the 27 it maps to, and the evidence behind each claim, over MCP and REST.