Control statement
- a.Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides;
- b.Issue authorization credentials for facility access;
- c.Review the access list detailing authorized facility access by individuals [Organization-defined: frequency] ; and
- d.Remove individuals from the facility access list when access is no longer required.
Discussion
Physical access authorizations apply to employees and visitors. Individuals with permanent physical access authorization credentials are not considered visitors. Authorization credentials include ID badges, identification cards, and smart cards. Organizations determine the strength of authorization credentials needed consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Physical access authorizations may not be necessary to access certain areas within facilities that are designated as publicly accessible.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Physical Access Authorizations as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to physical access, facility protection, environmental safeguards, and visitor accountability.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- badge and visitor logs
- physical access reviews
- facility diagrams and sensor records
- environmental and power test results
Common failure patterns
- logical security assumptions invalidated by physical access
- tailgating and visitor exceptions normalized
- critical infrastructure not included in access reviews
- environmental alarms not integrated into response
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- PE-02a.
- PE-02a.[01]a list of individuals with authorized access to the facility where the system resides has been developed;
- PE-02a.[02]the list of individuals with authorized access to the facility where the system resides has been approved;
- PE-02a.[03]the list of individuals with authorized access to the facility where the system resides has been maintained;
- PE-02b.authorization credentials are issued for facility access;
- PE-02c.the access list detailing authorized facility access by individuals is reviewed [Organization-defined: frequency];
- PE-02d.individuals are removed from the facility access list when access is no longer required.
Examine
- Physical and environmental protection policy
- procedures addressing physical access authorizations
- authorized personnel access list
- authorization credentials
- physical access list reviews
- physical access termination records and associated documentation
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access authorization responsibilities
- organizational personnel with physical access to system facility
- organizational personnel with information security responsibilities
Test
- Organizational processes for physical access authorizations
- mechanisms supporting and/or implementing physical access authorizations
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
PE-2(1) — Access by Position or Role
Authorize physical access to the facility where the system resides based on position or role.
Official discussion
Role-based facility access includes access by authorized permanent and regular/routine maintenance personnel, duty officers, and emergency medical staff.
Assessment objectives and methods
physical access to the facility where the system resides is authorized based on position or role.
Examine
- Physical and environmental protection policy
- procedures addressing physical access authorizations
- physical access control logs or records
- list of positions/roles and corresponding physical access authorizations
- system entry and exit points
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access authorization responsibilities
- organizational personnel with physical access to system facility
- organizational personnel with information security responsibilities
Test
- Organizational processes for physical access authorizations
- mechanisms supporting and/or implementing physical access authorizations
Related controls
PE-2(2) — Two Forms of Identification
Require two forms of identification from the following forms of identification for visitor access to the facility where the system resides: [Organization-defined: list of acceptable forms of identification].
Official discussion
Acceptable forms of identification include passports, REAL ID-compliant drivers’ licenses, and Personal Identity Verification (PIV) cards. For gaining access to facilities using automated mechanisms, organizations may use PIV cards, key cards, PINs, and biometrics.
Organization-defined parameters (1)
Assessment objectives and methods
two forms of identification are required from [Organization-defined: list of acceptable forms of identification] for visitor access to the facility where the system resides.
Examine
- Physical and environmental protection policy
- procedures addressing physical access authorizations
- list of acceptable forms of identification for visitor access to the facility where the system resides
- access authorization forms
- access credentials
- physical access control logs or records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access authorization responsibilities
- organizational personnel with physical access to the system facility
- organizational personnel with information security responsibilities
Test
- Organizational processes for physical access authorizations
- mechanisms supporting and/or implementing physical access authorizations
Related controls
PE-2(3) — Restrict Unescorted Access
Restrict unescorted access to the facility where the system resides to personnel with [Organization-defined: pe-02.03_odp.01].
Official discussion
Individuals without required security clearances, access approvals, or need to know are escorted by individuals with appropriate physical access authorizations to ensure that information is not exposed or otherwise compromised.
Organization-defined parameters (2)
Assessment objectives and methods
unescorted access to the facility where the system resides is restricted to personnel with [Organization-defined: pe-02.03_odp.01].
Examine
- Physical and environmental protection policy
- procedures addressing physical access authorizations
- authorized personnel access list
- security clearances
- access authorizations
- access credentials
- physical access control logs or records
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access authorization responsibilities
- organizational personnel with physical access to the system facility
- organizational personnel with information security responsibilities
Test
- Organizational processes for physical access authorizations
- mechanisms supporting and/or implementing physical access authorizations
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.