Physical Access Control
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
- 1.Verifying individual access authorizations before granting access to the facility; and
- 2.Controlling ingress and egress to the facility using [one of: ; guards];
Requirement Context
This element is part of PE-3 — Physical Access Control. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PE-3 — Physical Access Control. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PE-3 — Physical Access Control. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PE-3 — Physical Access Control. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PE-3 — Physical Access Control. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PE-3 — Physical Access Control. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of PE-3 — Physical Access Control. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors. Physical access controls for publicly accessible areas may include physical access control logs/records, guards, or physical access devices and barriers to prevent movement from publicly accessible areas to non-public areas. Organizations determine the types of guards needed, including professional security staff, system users, or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include facility access points, interior access points to systems that require supplemental access controls, or both. Components of systems may be in areas designated as publicly accessible with organizations controlling access to the components.
Enhancements NIST SOURCE
PE-3(1) System Access LOW MODERATE ✓ HIGH
Enforce physical access authorizations to the system in addition to the physical access controls for the facility at [physical spaces].
Discussion
Control of physical access to the system provides additional physical security for those areas within facilities where there is a concentration of system components.
PE-3(2) Facility and Systems LOW MODERATE HIGH
Perform security checks [frequency] at the physical perimeter of the facility or system for exfiltration of information or removal of system components.
Discussion
Organizations determine the extent, frequency, and/or randomness of security checks to adequately mitigate risk associated with exfiltration.
PE-3(3) Continuous Guards LOW MODERATE HIGH
Employ guards to control [physical access points] to the facility where the system resides 24 hours per day, 7 days per week.
Discussion
Employing guards at selected physical access points to the facility provides a more rapid response capability for organizations. Guards also provide the opportunity for human surveillance in areas of the facility not covered by video surveillance.
PE-3(4) Lockable Casings LOW MODERATE HIGH
Use lockable physical casings to protect [system components] from unauthorized physical access.
Discussion
The greatest risk from the use of portable devices—such as smart phones, tablets, and notebook computers—is theft. Organizations can employ lockable, physical casings to reduce or eliminate the risk of equipment theft. Such casings come in a variety of sizes, from units that protect a single notebook computer to full cabinets that can protect multiple servers, computers, and peripherals. Lockable physical casings can be used in conjunction with cable locks or lockdown plates to prevent the theft of the locked casing containing the computer equipment.
PE-3(5) Tamper Protection LOW MODERATE HIGH
Employ [anti-tamper technologies] to [one of: detect; prevent] physical tampering or alteration of [hardware components] within the system.
Discussion
Organizations can implement tamper detection and prevention at selected hardware components or implement tamper detection at some components and tamper prevention at other components. Detection and prevention activities can employ many types of anti-tamper technologies, including tamper-detection seals and anti-tamper coatings. Anti-tamper programs help to detect hardware alterations through counterfeiting and other supply chain-related risks.
PE-3(6) Facility Penetration Testing WITHDRAWN
Withdrawn. Incorporated into CA-8.
PE-3(7) Physical Barriers LOW MODERATE HIGH
Limit access using physical barriers.
Discussion
Physical barriers include bollards, concrete slabs, jersey walls, and hydraulic active vehicle barriers.
PE-3(8) Access Control Vestibules LOW MODERATE HIGH
Employ access control vestibules at [locations].
Discussion
An access control vestibule is part of a physical access control system that typically provides a space between two sets of interlocking doors. Vestibules are designed to prevent unauthorized individuals from following authorized individuals into facilities with controlled access. This activity, also known as piggybacking or tailgating, results in unauthorized access to the facility. Interlocking door controllers can be used to limit the number of individuals who enter controlled access points and to provide containment areas while authorization for physical access is verified. Interlocking door controllers can be fully automated (i.e., controlling the opening and closing of the doors) or partially automated (i.e., using security guards to control the number of individuals entering the containment area).
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for PE-3 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- entry and exit points to the facility in which the system resides are defined;
- one or more of the following PARAMETER VALUES is/are selected: { <PE-03_ODP[03] systems or devices>; guards};
- physical access control systems or devices used to control ingress and egress to the facility are defined (if selected);
- entry or exit points for which physical access logs are maintained are defined;
- physical access controls to control access to areas within the facility designated as publicly accessible are defined;
- circumstances requiring visitor escorts and control of visitor activity are defined;
- physical access devices to be inventoried are defined;
- frequency at which to inventory physical access devices is defined;
- frequency at which to change combinations is defined;
- frequency at which to change keys is defined;
- physical access authorizations are enforced at <PE-03_ODP[01] entry and exit points> by verifying individual access authorizations before granting access to the facility;
- physical access authorizations are enforced at <PE-03_ODP[01] entry and exit points> by controlling ingress and egress to the facility using <PE-03_ODP[02] SELECTED PARAMETER VALUES>;
- physical access audit logs are maintained for <PE-03_ODP[04] entry or exit points>;
- access to areas within the facility designated as publicly accessible are maintained by implementing <PE-03_ODP[05] physical access controls>;
- visitors are escorted;
- visitor activity is controlled <PE-03_ODP[06] circumstances>;
- keys are secured;
- combinations are secured;
- other physical access devices are secured;
- <PE-03_ODP[07] physical access devices> are inventoried <PE-03_ODP[08] frequency>;
- combinations are changed <PE-03_ODP[09] frequency> , when combinations are compromised, or when individuals possessing the combinations are transferred or terminated;
- keys are changed <PE-03_ODP[10] frequency> , when keys are lost, or when individuals possessing the keys are transferred or terminated.
Examine
[SELECT FROM: Physical and environmental protection policy; procedures addressing physical access control; physical access control logs or records; inventory records of physical access control devices; system entry and exit points; records of key and lock combination changes; storage locations for physical access control devices; physical access control devices; list of security safeguards controlling access to designated publicly accessible areas within facility; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with physical access control responsibilities; organizational personnel with information security responsibilities].
Test
[SELECT FROM: Organizational processes for physical access control; mechanisms supporting and/or implementing physical access control; physical access control devices].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for PE-3. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Physical and environmental protection policy
- system security plan
Configuration
- inventory records of physical access control devices
Testing
- Organizational processes for physical access control
- mechanisms supporting and/or implementing physical access control
- physical access control devices
Other Records
- procedures addressing physical access control
- physical access control logs or records
- system entry and exit points
- records of key and lock combination changes
- storage locations for physical access control devices
- physical access control devices
- list of security safeguards controlling access to designated publicly accessible areas within facility
- other relevant documents or records