NIST SP 800-53 Rev 5
PE - Physical and Environmental Protection

NIST SP 800-53 Rev 5 NIST800-PE-23: Facility Location. Plan the location or site of the facility where the system resides considering physical and environmental hazards; and For existing facilities, consider the physical and environmental hazards in the organizational risk management

Facility Location. Plan the location or site of the facility where the system resides considering physical and environmental hazards; and For existing facilities, consider the physical and environmental hazards in the organizational risk management

What else in your programme already covers this

This control maps to 24 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 4 controls

  • 4.1 Understanding the organization and its context
  • 6.1.2 Addressing risks and opportunities
  • 8.2.3 Risk assessment
  • 8.3.2 Identification of strategies and solutions
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-PR.IR-02 The organization's technology assets are protected from environmental threats

HIPAA Security Rule · 3 controls

ISO 27001:2022 · 3 controls

  • 7.3 Securing offices, rooms and facilities
  • 7.5 Protecting against physical and environmental threats
  • 7.8 Equipment siting and protection

NIST SP 800-66 Rev 2 · 3 controls

FedRAMP High · 1 control

  • SA-9(5) External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or

FedRAMP Moderate · 1 control

  • SA-9(5) External System Services | Processing, Storage, and Service Location. Restrict the location of [Selection (one or more): information processing; information or data; system services] to [Assignment: organization-defined locations] based on [Assignment: organization-defined requirements or

ISO 27002:2022 · 1 control

  • 7.5 Protecting against physical and environmental threats

SOC 2 · 1 control

  • SOC2-CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PE - Physical and Environmental Protection

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-PE-23 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 300 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 24 it maps to, and the evidence behind each claim, over MCP and REST.