NIST SP 800-53 Rev 5
PE - Physical and Environmental Protection

NIST SP 800-53 Rev 5 NIST800-PE-3: PE-3 Physical Access Control

a. Enforce physical access authorizations at [Assignment: organization-defined entry and exit points to the facility where the system resides] by: 1. Verifying individual access authorizations before granting access to the facility; and 2. Controlling ingress and egress to the facility using [Selection (one or more): [Assignment: organization-defined physical access control systems or devices]; guards]; b. Maintain physical access audit logs for [Assignment: organization-defined entry or exit points]; c. Control access to areas within the facility designated as publicly accessible by implementing the following controls: [Assignment: organization-defined physical access controls]; d. Escort visitors and control visitor activity [Assignment: organization-defined circumstances requiring visitor escorts and control of visitor activity]; e. Secure keys, combinations, and other physical access devices; f. Inventory [Assignment: organization-defined physical access devices] every [Assignment: organization-defined frequency]; and g. Change combinations and keys [Assignment: organization-defined frequency] and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 89 controls across 45 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 6 controls

  • 7.1 Physical security perimeters
  • 7.2 Physical entry
  • 7.3 Securing offices, rooms and facilities
  • 7.5 Protecting against physical and environmental threats
  • 7.6 Working in secure areas
  • 7.7 Clear desk and clear screen

CMMC 2.0 · 5 controls

HIPAA Security Rule · 5 controls

ISO 27001:2022 · 5 controls

  • 7.1 Physical security perimeters
  • 7.2 Physical entry
  • 7.3 Securing offices, rooms and facilities
  • 7.6 Working in secure areas
  • 7.7 Clear desk and clear screen

NIST SP 800-66 Rev 2 · 5 controls

PCI DSS 4.0 · 5 controls

  • 9.2.1 9.2.1 Facility entry controls for CDE systems
  • 9.2.2 9.2.2 Controls on publicly accessible network jacks
  • 9.3.1 9.3.1 Personnel physical access procedures for the CDE
  • 9.3.2 9.3.2 Visitor access procedures for the CDE
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups

CMMC 2.0 Level 1 · 4 controls

C5 (Germany) · 3 controls

  • C5-PS-01 Physical Security and Environmental Control Requirements
  • C5-PS-03 Perimeter Protection
  • C5-PS-04 Physical site access control

ISO 27701:2019 · 2 controls

  • 6.8 Physical and environmental security
  • 6.8.1 Secure areas

ISO/IEC 27011:2024 · 2 controls

  • 27011-7.1 Physical security perimeters
  • 27011-7.3 Equipment protection

NIST SP 800-171 · 2 controls

NIST SP 800-187 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • SEMD-PS-1 Critical Infrastructure Protection
  • SEMD-PS-2 Site Security Measures
  • 58.43 Animal Care Facilities
  • ANSSI-HYG-26 Control and Protect Access to Server Rooms and Technical Areas

API 1164 · 1 control

  • API1164-14 Physical Security
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)
  • CFTC-SS-6 Physical Security and Environmental Controls Category
  • CJIS-14 Physical Protection

FedRAMP High · 1 control

  • PE-3 Physical Access Control

FedRAMP Moderate · 1 control

  • PE-3 Physical Access Control
  • ISO28001-PS-01 Facility Security

ISO/IEC 27010:2015 · 1 control

  • 27010-11.1 Physical Protection

ISO/IEC 27400:2022 · 1 control

  • 27400-5.2 IoT Risk Assessment
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • PE-3 PE-3 Physical Access Control
  • PE-3 PE-3 Physical Access Control
  • PE-3 PE-3 Physical Access Control
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • SOC-CY-S1 Logical and Physical Access Controls
  • SSAE18-CC6.4 CC6.4 - Physical Access Restrictions
  • SOCI-CIRMP-PHYSICAL CIRMP hazard vector: Physical security and natural hazards
  • UKGAMBLE-4 Resilience and Incident Response

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PE - Physical and Environmental Protection

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-PE-3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 89 it maps to, and the evidence behind each claim, over MCP and REST.