💼 PE-3 PHYSICAL ACCESS CONTROL
- ID:
/frameworks/nist-sp-800-53-r4/pe/03
Stats​
not available
Description​
The organization: PE-3a. Enforces physical access authorizations at [Assignment: organization-defined entry/exit points to the facility where the information system resides] by; PE-3a.1. Verifying individual access authorizations before granting access to the facility; and PE-3a.2. Controlling ingress/egress to the facility using [Selection (one or more): [Assignment: organization-defined physical access control systems/devices]; guards]; PE-3b. Maintains physical access audit logs for [Assignment: organization-defined entry/exit points]; PE-3c. Provides [Assignment: organization-defined security safeguards] to control access to areas within the facility officially designated as publicly accessible; PE-3d. Escorts visitors and monitors visitor activity [Assignment: organization-defined circumstances requiring visitor escorts and monitoring]; PE-3e. Secures keys, combinations, and other physical access devices; PE-3f. Inventories [Assignment: organization-defined physical access devices] every [Assignment: organization-defined frequency]; and PE-3g. Changes combinations and keys [Assignment: organization-defined frequency] and/or when keys are lost, combinations are compromised, or individuals are transferred or terminated.
Similar​
- Internal
- ID:
dec-c-5dcea422
- ID:
Similar Sections (Give Policies To)​
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 NIST CSF v1.1 → 💼 DE.CM-2: The physical environment is monitored to detect potential cybersecurity events | no data | ||||
| 💼 NIST CSF v1.1 → 💼 DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed | 19 | 24 | no data | ||
| 💼 NIST CSF v1.1 → 💼 DE.DP-3: Detection processes are tested | 13 | 14 | no data | ||
| 💼 NIST CSF v1.1 → 💼 PR.AC-2: Physical access to assets is managed and protected | no data |
Sub Sections​
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 PE-3 (1) INFORMATION SYSTEM ACCESS | no data | ||||
| 💼 PE-3 (2) FACILITY _ INFORMATION SYSTEM BOUNDARIES | no data | ||||
| 💼 PE-3 (3) CONTINUOUS GUARDS _ ALARMS _ MONITORING | no data | ||||
| 💼 PE-3 (4) LOCKABLE CASINGS | no data | ||||
| 💼 PE-3 (5) TAMPER PROTECTION | no data | ||||
| 💼 PE-3 (6) FACILITY PENETRATION TESTING | no data |