NIST SP 800-66 Rev 2
Physical

NIST SP 800-66 Rev 2 164.310(c): Workstation Security (Standard)

Implement physical safeguards for workstations accessing ePHI to restrict access to authorized users. NIST recommends positioning, privacy screens, cable locks, and clear-desk policy.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 51 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 6 controls

  • 5.15 Access control
  • 7.3 Securing offices, rooms and facilities
  • 7.6 Working in secure areas
  • 7.7 Clear desk and clear screen
  • 7.8 Equipment siting and protection
  • 8.1 User endpoint devices

NIST SP 800-53 Rev 5 · 6 controls

ISO 27001:2022 · 5 controls

  • 7.6 Working in secure areas
  • 7.7 Clear desk and clear screen
  • 7.8 Equipment siting and protection
  • 7.9 Security of assets off-premises
  • 8.1 User end point devices

ISO 27701:2019 · 4 controls

PCI DSS 4.0 · 4 controls

  • 9.2.1 9.2.1 Facility entry controls for CDE systems
  • 9.2.2 9.2.2 Controls on publicly accessible network jacks
  • 9.3.1 9.3.1 Personnel physical access procedures for the CDE
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups

FedRAMP High · 3 controls

  • PE-17 Alternate Work Site
  • PE-3 Physical Access Control
  • PE-5 Access Control for Output Devices (PE-5)

FedRAMP Moderate · 3 controls

  • PE-17 Alternate Work Site
  • PE-3 Physical Access Control
  • PE-5 Access Control for Output Devices (PE-5)

NIST SP 800-171 Rev 3 · 3 controls

  • ASBv3-GS-9 Define and implement endpoint security strategy
  • ASBv3-PA-6 Use privileged access workstations

CIS Controls v8 · 2 controls

  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices

CMMC 2.0 · 2 controls

  • ANSSI-HYG-30 Apply Physical Protection Measures to Mobile Devices
  • AUCDR-IS-2 Secure the network and systems within the data environment

C5 (Germany) · 1 control

  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk

SOC 2 · 1 control

  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets

UK Cyber Essentials · 1 control

  • CE-SC.9 Device Unlocking Credentials and Brute-Force Protection

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Physical

Query this from an agent

The graph holds this control, the 51 it maps to, and the evidence behind each claim, over MCP and REST.