NIST SP 800-66 Rev 2 164.310(a)(2)(ii): Facility Security Plan (Addressable)
Implement policies to safeguard facility and equipment from unauthorized physical access, tampering, and theft. NIST recommends documented zones, controls, and inspection regime.
What else in your programme already covers this
This control maps to 57 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-PE-16 Delivery and Removal. Authorize and control [organization-defined] entering and exiting the facility; and Maintain records of the system components
NIST800-PE-18 Location of System Components. Position system components within the facility to minimize potential damage from [organization-defined] and to minimize the opportunity for unauthorized access
NIST800-PE-23 Facility Location. Plan the location or site of the facility where the system resides considering physical and environmental hazards; and For existing facilities, consider the physical and environmental hazards in the organizational risk management
9.2.1 Appropriate facility entry controls are in place to restrict physical access to systems in the CDE
9.2.1.1 Individual physical access to sensitive areas within the CDE is monitored with either video cameras or physical access control mechanisms (or both) as follows: • Entry and exit points to/from sensitive areas within the
9.3.1 Procedures are implemented for authorizing and managing physical access of personnel to the CDE, including: • Identifying personnel. • Managing changes to an individual's physical access requirements. • Revoking or terminating personnel identification. •
9.3.2 Procedures are implemented for authorizing and managing visitor access to the CDE, including: • Visitors are authorized before entering. • Visitors are escorted at all times. • Visitors are clearly identified and given a
SOC2-CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives