Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PE-14 — Environmental Controls

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

2Enhancements
4Parameters
3Baseline memberships
3Assessment methods

PE — Physical and Environmental Protection · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Maintain [Organization-defined: pe-14_odp.01] levels within the facility where the system resides at [Organization-defined: acceptable levels] ; and
  2. b.Monitor environmental control levels [Organization-defined: frequency].
Official NIST discussion

Discussion

The provision of environmental controls applies primarily to organizational facilities that contain concentrations of system resources (e.g., data centers, mainframe computer rooms, and server rooms). Insufficient environmental controls, especially in very harsh environments, can have a significant adverse impact on the availability of systems and system components that are needed to support organizational mission and business functions.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

pe-14_odp.01
environmental controlenvironmental control(s) for which to maintain a specified level in the facility where the system resides are defined (if selected);
acceptable levelsacceptable levels for environmental controls are defined;
frequencyfrequency at which to monitor environmental control levels is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Environmental Controls as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to physical access, facility protection, environmental safeguards, and visitor accountability.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • badge and visitor logs
  • physical access reviews
  • facility diagrams and sensor records
  • environmental and power test results

Common failure patterns

  • logical security assumptions invalidated by physical access
  • tailgating and visitor exceptions normalized
  • critical infrastructure not included in access reviews
  • environmental alarms not integrated into response

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PE-14a.[Organization-defined: pe-14_odp.01] levels are maintained at [Organization-defined: acceptable levels] within the facility where the system resides;
  2. PE-14b.environmental control levels are monitored [Organization-defined: frequency].

Examine

  • Physical and environmental protection policy
  • procedures addressing temperature and humidity control
  • temperature and humidity controls
  • facility housing the system
  • temperature and humidity controls documentation
  • temperature and humidity records
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for system environmental controls
  • organizational personnel with information security responsibilities

Test

  • Mechanisms supporting and/or implementing the maintenance and monitoring of temperature and humidity levels
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

PE-14(1) — Automatic Controls

Employ the following automatic environmental controls in the facility to prevent fluctuations potentially harmful to the system: [Organization-defined: automatic environmental controls].

Official discussion

The implementation of automatic environmental controls provides an immediate response to environmental conditions that can damage, degrade, or destroy organizational systems or systems components.

Organization-defined parameters (1)
automatic environmental controlsautomatic environmental controls to prevent fluctuations that are potentially harmful to the system are defined;
Assessment objectives and methods

[Organization-defined: automatic environmental controls] are employed in the facility to prevent fluctuations that are potentially harmful to the system.

Examine

  • Physical and environmental protection policy
  • procedures addressing temperature and humidity controls
  • facility housing the system
  • automated mechanisms for temperature and humidity
  • temperature and humidity controls
  • temperature and humidity documentation
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for system environmental controls
  • organizational personnel with information security responsibilities

Test

  • Automated mechanisms supporting and/or implementing temperature and humidity levels
Official NIST control enhancement

PE-14(2) — Monitoring with Alarms and Notifications

Employ environmental control monitoring that provides an alarm or notification of changes potentially harmful to personnel or equipment to [Organization-defined: personnel or roles].

Official discussion

The alarm or notification may be an audible alarm or a visual message in real time to personnel or roles defined by the organization. Such alarms and notifications can help minimize harm to individuals and damage to organizational assets by facilitating a timely incident response.

Organization-defined parameters (1)
personnel or rolespersonnel or roles to be notified by environmental control monitoring when environmental changes are potentially harmful to personnel or equipment is/are defined;
Assessment objectives and methods
  1. PE-14(02)[01]environmental control monitoring is employed;
  2. PE-14(02)[02]the environmental control monitoring capability provides an alarm or notification to [Organization-defined: personnel or roles] when changes are potentially harmful to personnel or equipment.

Examine

  • Physical and environmental protection policy
  • procedures addressing temperature and humidity monitoring
  • facility housing the system
  • logs or records of temperature and humidity monitoring
  • records of changes to temperature and humidity levels that generate alarms or notifications
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with responsibilities for system environmental controls
  • organizational personnel with information security responsibilities

Test

  • Mechanisms supporting and/or implementing temperature and humidity monitoring
Source record

Authoritative sources