Facility and Systems
LOW MODERATE HIGHRequirements NIST SOURCE
Perform security checks [frequency] at the physical perimeter of the facility or system for exfiltration of information or removal of system components.
Discussion (NIST Supplemental Guidance)
Organizations determine the extent, frequency, and/or randomness of security checks to adequately mitigate risk associated with exfiltration.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for PE-3(2) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- the frequency at which to perform security checks at the physical perimeter of the facility or system for exfiltration of information or removal of system components is defined;
- security checks are performed <PE-03(02)_ODP frequency> at the physical perimeter of the facility or system for exfiltration of information or removal of system components.
Examine
[SELECT FROM: Physical and environmental protection policy; procedures addressing physical access control; physical access control logs or records; records of security checks; security audit reports; security inspection reports; facility layout documentation; system entry and exit points; system security plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with physical access control responsibilities; organizational personnel with information security responsibilities].
Test
[SELECT FROM: Organizational processes for physical access control to the facility and/or system; mechanisms supporting and/or implementing physical access control for the facility or system; mechanisms supporting and/or implementing security checks for the unauthorized exfiltration of information].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for PE-3(2). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Physical and environmental protection policy
- system security plan
Testing
- Organizational processes for physical access control to the facility and/or system
- mechanisms supporting and/or implementing physical access control for the facility or system
- mechanisms supporting and/or implementing security checks for the unauthorized exfiltration of information
Other Records
- procedures addressing physical access control
- physical access control logs or records
- records of security checks
- security audit reports
- security inspection reports
- facility layout documentation
- system entry and exit points
- other relevant documents or records