Control statement
- a.Enforce physical access authorizations at [Organization-defined: entry and exit points] by:
- 1.Verifying individual access authorizations before granting access to the facility; and
- 2.Controlling ingress and egress to the facility using [Organization-defined: pe-03_odp.02];
- b.Maintain physical access audit logs for [Organization-defined: entry or exit points];
- c.Control access to areas within the facility designated as publicly accessible by implementing the following controls: [Organization-defined: physical access controls];
- d.Escort visitors and control visitor activity [Organization-defined: circumstances];
- e.Secure keys, combinations, and other physical access devices;
- f.Inventory [Organization-defined: physical access devices] every [Organization-defined: frequency] ; and
- g.Change combinations and keys [Organization-defined: organization-defined frequency] and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.
Discussion
Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors. Physical access controls for publicly accessible areas may include physical access control logs/records, guards, or physical access devices and barriers to prevent movement from publicly accessible areas to non-public areas. Organizations determine the types of guards needed, including professional security staff, system users, or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include facility access points, interior access points to systems that require supplemental access controls, or both. Components of systems may be in areas designated as publicly accessible with organizations controlling access to the components.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Physical Access Control as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to physical access, facility protection, environmental safeguards, and visitor accountability.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- badge and visitor logs
- physical access reviews
- facility diagrams and sensor records
- environmental and power test results
Common failure patterns
- logical security assumptions invalidated by physical access
- tailgating and visitor exceptions normalized
- critical infrastructure not included in access reviews
- environmental alarms not integrated into response
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- PE-03a.
- PE-03a.01physical access authorizations are enforced at [Organization-defined: entry and exit points] by verifying individual access authorizations before granting access to the facility;
- PE-03a.02physical access authorizations are enforced at [Organization-defined: entry and exit points] by controlling ingress and egress to the facility using [Organization-defined: pe-03_odp.02];
- PE-03b.physical access audit logs are maintained for [Organization-defined: entry or exit points];
- PE-03c.access to areas within the facility designated as publicly accessible are maintained by implementing [Organization-defined: physical access controls];
- PE-03d.
- PE-03d.[01]visitors are escorted;
- PE-03d.[02]visitor activity is controlled [Organization-defined: circumstances];
- PE-03e.
- PE-03e.[01]keys are secured;
- PE-03e.[02]combinations are secured;
- PE-03e.[03]other physical access devices are secured;
- PE-03f.[Organization-defined: physical access devices] are inventoried [Organization-defined: frequency];
- PE-03g.
- PE-03g.[01]combinations are changed [Organization-defined: frequency] , when combinations are compromised, or when individuals possessing the combinations are transferred or terminated;
- PE-03g.[02]keys are changed [Organization-defined: frequency] , when keys are lost, or when individuals possessing the keys are transferred or terminated.
Examine
- Physical and environmental protection policy
- procedures addressing physical access control
- physical access control logs or records
- inventory records of physical access control devices
- system entry and exit points
- records of key and lock combination changes
- storage locations for physical access control devices
- physical access control devices
- list of security safeguards controlling access to designated publicly accessible areas within facility
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access control responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for physical access control
- mechanisms supporting and/or implementing physical access control
- physical access control devices
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related NIST SP 800-171 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
PE-3(1) — System Access
Enforce physical access authorizations to the system in addition to the physical access controls for the facility at [Organization-defined: physical spaces].
Official discussion
Control of physical access to the system provides additional physical security for those areas within facilities where there is a concentration of system components.
Organization-defined parameters (1)
Assessment objectives and methods
- PE-03(01)[01]physical access authorizations to the system are enforced;
- PE-03(01)[02]physical access controls are enforced for the facility at [Organization-defined: physical spaces].
Examine
- Physical and environmental protection policy
- procedures addressing physical access control
- physical access control logs or records
- physical access control devices
- access authorizations
- access credentials
- system entry and exit points
- list of areas within the facility containing concentrations of system components or system components requiring additional physical protection
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access authorization responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for physical access control to the information system/components
- mechanisms supporting and/or implementing physical access control for facility areas containing system components
PE-3(2) — Facility and Systems
Perform security checks [Organization-defined: frequency] at the physical perimeter of the facility or system for exfiltration of information or removal of system components.
Official discussion
Organizations determine the extent, frequency, and/or randomness of security checks to adequately mitigate risk associated with exfiltration.
Organization-defined parameters (1)
Assessment objectives and methods
security checks are performed [Organization-defined: frequency] at the physical perimeter of the facility or system for exfiltration of information or removal of system components.
Examine
- Physical and environmental protection policy
- procedures addressing physical access control
- physical access control logs or records
- records of security checks
- security audit reports
- security inspection reports
- facility layout documentation
- system entry and exit points
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access control responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for physical access control to the facility and/or system
- mechanisms supporting and/or implementing physical access control for the facility or system
- mechanisms supporting and/or implementing security checks for the unauthorized exfiltration of information
Related controls
PE-3(3) — Continuous Guards
Employ guards to control [Organization-defined: physical access points] to the facility where the system resides 24 hours per day, 7 days per week.
Official discussion
Employing guards at selected physical access points to the facility provides a more rapid response capability for organizations. Guards also provide the opportunity for human surveillance in areas of the facility not covered by video surveillance.
Organization-defined parameters (1)
Assessment objectives and methods
guards are employed to control [Organization-defined: physical access points] to the facility where the system resides 24 hours per day, 7 days per week.
Examine
- Physical and environmental protection policy
- procedures addressing physical access control
- physical access control logs or records
- physical access control devices
- facility surveillance records
- facility layout documentation
- system entry and exit points
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access control responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for physical access control to the facility where the system resides
- mechanisms supporting and/or implementing physical access control for the facility where the system resides
Related controls
PE-3(4) — Lockable Casings
Use lockable physical casings to protect [Organization-defined: system components] from unauthorized physical access.
Official discussion
The greatest risk from the use of portable devices—such as smart phones, tablets, and notebook computers—is theft. Organizations can employ lockable, physical casings to reduce or eliminate the risk of equipment theft. Such casings come in a variety of sizes, from units that protect a single notebook computer to full cabinets that can protect multiple servers, computers, and peripherals. Lockable physical casings can be used in conjunction with cable locks or lockdown plates to prevent the theft of the locked casing containing the computer equipment.
Organization-defined parameters (1)
Assessment objectives and methods
lockable physical casings are used to protect [Organization-defined: system components] from unauthorized access.
Examine
- Physical and environmental protection policy
- procedures addressing physical access control
- list of system components requiring protection through lockable physical casings
- lockable physical casings
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access control responsibilities
- organizational personnel with information security responsibilities
Test
- Lockable physical casings
PE-3(5) — Tamper Protection
Employ [Organization-defined: anti-tamper technologies] to [Organization-defined: pe-03.05_odp.02] physical tampering or alteration of [Organization-defined: hardware components] within the system.
Official discussion
Organizations can implement tamper detection and prevention at selected hardware components or implement tamper detection at some components and tamper prevention at other components. Detection and prevention activities can employ many types of anti-tamper technologies, including tamper-detection seals and anti-tamper coatings. Anti-tamper programs help to detect hardware alterations through counterfeiting and other supply chain-related risks.
Organization-defined parameters (3)
Assessment objectives and methods
[Organization-defined: anti-tamper technologies] are employed to [Organization-defined: pe-03.05_odp.02] physical tampering or alteration of [Organization-defined: hardware components] within the system.
Examine
- Physical and environmental protection policy
- procedures addressing physical access control
- list of security safeguards to detect/prevent physical tampering or alteration of system hardware components
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access control responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes to detect/prevent physical tampering or alteration of system hardware components
- mechanisms/security safeguards supporting and/or implementing the detection/prevention of physical tampering/alternation of system hardware components
Related controls
PE-3(6) — Facility Penetration Testing
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
PE-3(7) — Physical Barriers
Limit access using physical barriers.
Official discussion
Physical barriers include bollards, concrete slabs, jersey walls, and hydraulic active vehicle barriers.
Assessment objectives and methods
physical barriers are used to limit access.
Examine
- Physical and environmental protection policy
- procedures addressing physical access control
- list of physical barriers to limit access to the system
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access control responsibilities
- organizational personnel with information security responsibilities
PE-3(8) — Access Control Vestibules
Employ access control vestibules at [Organization-defined: locations].
Official discussion
An access control vestibule is part of a physical access control system that typically provides a space between two sets of interlocking doors. Vestibules are designed to prevent unauthorized individuals from following authorized individuals into facilities with controlled access. This activity, also known as piggybacking or tailgating, results in unauthorized access to the facility. Interlocking door controllers can be used to limit the number of individuals who enter controlled access points and to provide containment areas while authorization for physical access is verified. Interlocking door controllers can be fully automated (i.e., controlling the opening and closing of the doors) or partially automated (i.e., using security guards to control the number of individuals entering the containment area).
Organization-defined parameters (1)
Assessment objectives and methods
access control vestibules are employed at [Organization-defined: locations].
Examine
- Physical and environmental protection policy
- procedures addressing physical access control
- list of access control vestibules and locations
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access control responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for vestibules to prevent unauthorized access.
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.