Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

PE-3 — Physical Access Control

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

8Enhancements
11Parameters
3Baseline memberships
3Assessment methods

PE — Physical and Environmental Protection · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Enforce physical access authorizations at [Organization-defined: entry and exit points] by:
    1. 1.Verifying individual access authorizations before granting access to the facility; and
    2. 2.Controlling ingress and egress to the facility using [Organization-defined: pe-03_odp.02];
  2. b.Maintain physical access audit logs for [Organization-defined: entry or exit points];
  3. c.Control access to areas within the facility designated as publicly accessible by implementing the following controls: [Organization-defined: physical access controls];
  4. d.Escort visitors and control visitor activity [Organization-defined: circumstances];
  5. e.Secure keys, combinations, and other physical access devices;
  6. f.Inventory [Organization-defined: physical access devices] every [Organization-defined: frequency] ; and
  7. g.Change combinations and keys [Organization-defined: organization-defined frequency] and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.
Official NIST discussion

Discussion

Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors. Physical access controls for publicly accessible areas may include physical access control logs/records, guards, or physical access devices and barriers to prevent movement from publicly accessible areas to non-public areas. Organizations determine the types of guards needed, including professional security staff, system users, or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include facility access points, interior access points to systems that require supplemental access controls, or both. Components of systems may be in areas designated as publicly accessible with organizations controlling access to the components.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined frequency
entry and exit pointsentry and exit points to the facility in which the system resides are defined;
pe-03_odp.02
systems or devicesphysical access control systems or devices used to control ingress and egress to the facility are defined (if selected);
entry or exit pointsentry or exit points for which physical access logs are maintained are defined;
physical access controlsphysical access controls to control access to areas within the facility designated as publicly accessible are defined;
circumstancescircumstances requiring visitor escorts and control of visitor activity are defined;
physical access devicesphysical access devices to be inventoried are defined;
frequencyfrequency at which to inventory physical access devices is defined;
frequencyfrequency at which to change combinations is defined;
frequencyfrequency at which to change keys is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Physical Access Control as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to physical access, facility protection, environmental safeguards, and visitor accountability.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • badge and visitor logs
  • physical access reviews
  • facility diagrams and sensor records
  • environmental and power test results

Common failure patterns

  • logical security assumptions invalidated by physical access
  • tailgating and visitor exceptions normalized
  • critical infrastructure not included in access reviews
  • environmental alarms not integrated into response

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PE-03a.
    1. PE-03a.01physical access authorizations are enforced at [Organization-defined: entry and exit points] by verifying individual access authorizations before granting access to the facility;
    2. PE-03a.02physical access authorizations are enforced at [Organization-defined: entry and exit points] by controlling ingress and egress to the facility using [Organization-defined: pe-03_odp.02];
  2. PE-03b.physical access audit logs are maintained for [Organization-defined: entry or exit points];
  3. PE-03c.access to areas within the facility designated as publicly accessible are maintained by implementing [Organization-defined: physical access controls];
  4. PE-03d.
    1. PE-03d.[01]visitors are escorted;
    2. PE-03d.[02]visitor activity is controlled [Organization-defined: circumstances];
  5. PE-03e.
    1. PE-03e.[01]keys are secured;
    2. PE-03e.[02]combinations are secured;
    3. PE-03e.[03]other physical access devices are secured;
  6. PE-03f.[Organization-defined: physical access devices] are inventoried [Organization-defined: frequency];
  7. PE-03g.
    1. PE-03g.[01]combinations are changed [Organization-defined: frequency] , when combinations are compromised, or when individuals possessing the combinations are transferred or terminated;
    2. PE-03g.[02]keys are changed [Organization-defined: frequency] , when keys are lost, or when individuals possessing the keys are transferred or terminated.

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access control
  • physical access control logs or records
  • inventory records of physical access control devices
  • system entry and exit points
  • records of key and lock combination changes
  • storage locations for physical access control devices
  • physical access control devices
  • list of security safeguards controlling access to designated publicly accessible areas within facility
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with physical access control responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for physical access control
  • mechanisms supporting and/or implementing physical access control
  • physical access control devices
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official CUI requirement crosswalk

Related NIST SP 800-171 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

PE-3(1) — System Access

High

Enforce physical access authorizations to the system in addition to the physical access controls for the facility at [Organization-defined: physical spaces].

Official discussion

Control of physical access to the system provides additional physical security for those areas within facilities where there is a concentration of system components.

Organization-defined parameters (1)
physical spacesphysical spaces containing one or more components of the system are defined;
Assessment objectives and methods
  1. PE-03(01)[01]physical access authorizations to the system are enforced;
  2. PE-03(01)[02]physical access controls are enforced for the facility at [Organization-defined: physical spaces].

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access control
  • physical access control logs or records
  • physical access control devices
  • access authorizations
  • access credentials
  • system entry and exit points
  • list of areas within the facility containing concentrations of system components or system components requiring additional physical protection
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with physical access authorization responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for physical access control to the information system/components
  • mechanisms supporting and/or implementing physical access control for facility areas containing system components
Official NIST control enhancement

PE-3(2) — Facility and Systems

Perform security checks [Organization-defined: frequency] at the physical perimeter of the facility or system for exfiltration of information or removal of system components.

Official discussion

Organizations determine the extent, frequency, and/or randomness of security checks to adequately mitigate risk associated with exfiltration.

Organization-defined parameters (1)
frequencythe frequency at which to perform security checks at the physical perimeter of the facility or system for exfiltration of information or removal of system components is defined;
Assessment objectives and methods

security checks are performed [Organization-defined: frequency] at the physical perimeter of the facility or system for exfiltration of information or removal of system components.

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access control
  • physical access control logs or records
  • records of security checks
  • security audit reports
  • security inspection reports
  • facility layout documentation
  • system entry and exit points
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with physical access control responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for physical access control to the facility and/or system
  • mechanisms supporting and/or implementing physical access control for the facility or system
  • mechanisms supporting and/or implementing security checks for the unauthorized exfiltration of information
Related controls
Official NIST control enhancement

PE-3(3) — Continuous Guards

Employ guards to control [Organization-defined: physical access points] to the facility where the system resides 24 hours per day, 7 days per week.

Official discussion

Employing guards at selected physical access points to the facility provides a more rapid response capability for organizations. Guards also provide the opportunity for human surveillance in areas of the facility not covered by video surveillance.

Organization-defined parameters (1)
physical access pointsphysical access points to the facility where the system resides are defined;
Assessment objectives and methods

guards are employed to control [Organization-defined: physical access points] to the facility where the system resides 24 hours per day, 7 days per week.

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access control
  • physical access control logs or records
  • physical access control devices
  • facility surveillance records
  • facility layout documentation
  • system entry and exit points
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with physical access control responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for physical access control to the facility where the system resides
  • mechanisms supporting and/or implementing physical access control for the facility where the system resides
Related controls
Official NIST control enhancement

PE-3(4) — Lockable Casings

Use lockable physical casings to protect [Organization-defined: system components] from unauthorized physical access.

Official discussion

The greatest risk from the use of portable devices—such as smart phones, tablets, and notebook computers—is theft. Organizations can employ lockable, physical casings to reduce or eliminate the risk of equipment theft. Such casings come in a variety of sizes, from units that protect a single notebook computer to full cabinets that can protect multiple servers, computers, and peripherals. Lockable physical casings can be used in conjunction with cable locks or lockdown plates to prevent the theft of the locked casing containing the computer equipment.

Organization-defined parameters (1)
system componentssystem components to be protected from unauthorized physical access are defined;
Assessment objectives and methods

lockable physical casings are used to protect [Organization-defined: system components] from unauthorized access.

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access control
  • list of system components requiring protection through lockable physical casings
  • lockable physical casings
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with physical access control responsibilities
  • organizational personnel with information security responsibilities

Test

  • Lockable physical casings
Official NIST control enhancement

PE-3(5) — Tamper Protection

Employ [Organization-defined: anti-tamper technologies] to [Organization-defined: pe-03.05_odp.02] physical tampering or alteration of [Organization-defined: hardware components] within the system.

Official discussion

Organizations can implement tamper detection and prevention at selected hardware components or implement tamper detection at some components and tamper prevention at other components. Detection and prevention activities can employ many types of anti-tamper technologies, including tamper-detection seals and anti-tamper coatings. Anti-tamper programs help to detect hardware alterations through counterfeiting and other supply chain-related risks.

Organization-defined parameters (3)
anti-tamper technologiesanti-tamper technologies to be employed are defined;
pe-03.05_odp.02
hardware componentshardware components to be protected from physical tampering or alteration are defined;
Assessment objectives and methods

[Organization-defined: anti-tamper technologies] are employed to [Organization-defined: pe-03.05_odp.02] physical tampering or alteration of [Organization-defined: hardware components] within the system.

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access control
  • list of security safeguards to detect/prevent physical tampering or alteration of system hardware components
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with physical access control responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes to detect/prevent physical tampering or alteration of system hardware components
  • mechanisms/security safeguards supporting and/or implementing the detection/prevention of physical tampering/alternation of system hardware components
Related controls
Official NIST control enhancement

PE-3(6) — Facility Penetration Testing

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

PE-3(7) — Physical Barriers

Limit access using physical barriers.

Official discussion

Physical barriers include bollards, concrete slabs, jersey walls, and hydraulic active vehicle barriers.

Assessment objectives and methods

physical barriers are used to limit access.

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access control
  • list of physical barriers to limit access to the system
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with physical access control responsibilities
  • organizational personnel with information security responsibilities
Official NIST control enhancement

PE-3(8) — Access Control Vestibules

Employ access control vestibules at [Organization-defined: locations].

Official discussion

An access control vestibule is part of a physical access control system that typically provides a space between two sets of interlocking doors. Vestibules are designed to prevent unauthorized individuals from following authorized individuals into facilities with controlled access. This activity, also known as piggybacking or tailgating, results in unauthorized access to the facility. Interlocking door controllers can be used to limit the number of individuals who enter controlled access points and to provide containment areas while authorization for physical access is verified. Interlocking door controllers can be fully automated (i.e., controlling the opening and closing of the doors) or partially automated (i.e., using security guards to control the number of individuals entering the containment area).

Organization-defined parameters (1)
locationslocations within the facility where access control vestibules are to be employed are defined;
Assessment objectives and methods

access control vestibules are employed at [Organization-defined: locations].

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access control
  • list of access control vestibules and locations
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with physical access control responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for vestibules to prevent unauthorized access.
Source record

Authoritative sources