Control statement
- a.Monitor physical access to the facility where the system resides to detect and respond to physical security incidents;
- b.Review physical access logs [Organization-defined: frequency] and upon occurrence of [Organization-defined: events] ; and
- c.Coordinate results of reviews and investigations with the organizational incident response capability.
Discussion
Physical access monitoring includes publicly accessible areas within organizational facilities. Examples of physical access monitoring include the employment of guards, video surveillance equipment (i.e., cameras), and sensor devices. Reviewing physical access logs can help identify suspicious activity, anomalous events, or potential threats. The reviews can be supported by audit logging controls, such as [AU-2](#au-2) , if the access logs are part of an automated system. Organizational incident response capabilities include investigations of physical security incidents and responses to the incidents. Incidents include security violations or suspicious physical access activities. Suspicious physical access activities include accesses outside of normal work hours, repeated accesses to areas not normally accessed, accesses for unusual lengths of time, and out-of-sequence accesses.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Monitoring Physical Access as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to physical access, facility protection, environmental safeguards, and visitor accountability.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- badge and visitor logs
- physical access reviews
- facility diagrams and sensor records
- environmental and power test results
Common failure patterns
- logical security assumptions invalidated by physical access
- tailgating and visitor exceptions normalized
- critical infrastructure not included in access reviews
- environmental alarms not integrated into response
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- PE-06a.physical access to the facility where the system resides is monitored to detect and respond to physical security incidents;
- PE-06b.
- PE-06b.[01]physical access logs are reviewed [Organization-defined: frequency];
- PE-06b.[02]physical access logs are reviewed upon occurrence of [Organization-defined: events];
- PE-06c.
- PE-06c.[01]results of reviews are coordinated with organizational incident response capabilities;
- PE-06c.[02]results of investigations are coordinated with organizational incident response capabilities.
Examine
- Physical and environmental protection policy
- procedures addressing physical access monitoring
- physical access logs or records
- physical access monitoring records
- physical access log reviews
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with physical access monitoring responsibilities
- organizational personnel with incident response responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for monitoring physical access
- mechanisms supporting and/or implementing physical access monitoring
- mechanisms supporting and/or implementing the review of physical access logs
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
PE-6(1) — Intrusion Alarms and Surveillance Equipment
Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment.
Official discussion
Physical intrusion alarms can be employed to alert security personnel when unauthorized access to the facility is attempted. Alarm systems work in conjunction with physical barriers, physical access control systems, and security guards by triggering a response when these other forms of security have been compromised or breached. Physical intrusion alarms can include different types of sensor devices, such as motion sensors, contact sensors, and broken glass sensors. Surveillance equipment includes video cameras installed at strategic locations throughout the facility.
Assessment objectives and methods
- PE-06(01)[01]physical access to the facility where the system resides is monitored using physical intrusion alarms;
- PE-06(01)[02]physical access to the facility where the system resides is monitored using physical surveillance equipment.
Examine
- Physical and environmental protection policy
- procedures addressing physical access monitoring
- physical access logs or records
- physical access monitoring records
- physical access log reviews
- system security plan
- privacy plan
- privacy impact assessment
- privacy risk assessment documentation
- other relevant documents or records
Interview
- Organizational personnel with physical access monitoring responsibilities
- organizational personnel with incident response responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for monitoring physical intrusion alarms and surveillance equipment
- mechanisms supporting and/or implementing physical access monitoring
- mechanisms supporting and/or implementing physical intrusion alarms and surveillance equipment
PE-6(2) — Automated Intrusion Recognition and Responses
Recognize [Organization-defined: classes or types of intrusions] and initiate [Organization-defined: response actions] using [Organization-defined: automated mechanisms].
Official discussion
Response actions can include notifying selected organizational personnel or law enforcement personnel. Automated mechanisms implemented to initiate response actions include system alert notifications, email and text messages, and activating door locking mechanisms. Physical access monitoring can be coordinated with intrusion detection systems and system monitoring capabilities to provide integrated threat coverage for the organization.
Organization-defined parameters (3)
Assessment objectives and methods
- PE-06(02)[01][Organization-defined: classes or types of intrusions] are recognized;
- PE-06(02)[02][Organization-defined: response actions] are initiated using [Organization-defined: automated mechanisms].
Examine
- Physical and environmental protection policy
- procedures addressing physical access monitoring
- system design documentation
- system configuration settings and associated documentation
- system audit records
- list of response actions to be initiated when specific classes/types of intrusions are recognized
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with physical access monitoring responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for monitoring physical access
- automated mechanisms supporting and/or implementing physical access monitoring
- automated mechanisms supporting and/or implementing recognition of classes/types of intrusions and initiation of a response
Related controls
PE-6(3) — Video Surveillance
- (a)Employ video surveillance of [Organization-defined: operational areas];
- (b)Review video recordings [Organization-defined: frequency] ; and
- (c)Retain video recordings for [Organization-defined: time period].
Official discussion
Video surveillance focuses on recording activity in specified areas for the purposes of subsequent review, if circumstances so warrant. Video recordings are typically reviewed to detect anomalous events or incidents. Monitoring the surveillance video is not required, although organizations may choose to do so. There may be legal considerations when performing and retaining video surveillance, especially if such surveillance is in a public location.
Organization-defined parameters (3)
Assessment objectives and methods
- PE-06(03)(a)video surveillance of [Organization-defined: operational areas] is employed;
- PE-06(03)(b)video recordings are reviewed [Organization-defined: frequency];
- PE-06(03)(c)video recordings are retained for [Organization-defined: time period].
Examine
- Physical and environmental protection policy
- procedures addressing physical access monitoring
- video surveillance equipment used to monitor operational areas
- video recordings of operational areas where video surveillance is employed
- video surveillance equipment logs or records
- system security plan
- privacy plan
- privacy impact assessment
- privacy risk assessment documentation
- other relevant documents or records
Interview
- Organizational personnel with physical access monitoring responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for monitoring physical access
- mechanisms supporting and/or implementing physical access monitoring
- mechanisms supporting and/or implementing video surveillance
PE-6(4) — Monitoring Physical Access to Systems
Monitor physical access to the system in addition to the physical access monitoring of the facility at [Organization-defined: physical spaces].
Official discussion
Monitoring physical access to systems provides additional monitoring for those areas within facilities where there is a concentration of system components, including server rooms, media storage areas, and communications centers. Physical access monitoring can be coordinated with intrusion detection systems and system monitoring capabilities to provide comprehensive and integrated threat coverage for the organization.
Organization-defined parameters (1)
Assessment objectives and methods
physical access to the system is monitored in addition to the physical access monitoring of the facility at [Organization-defined: physical spaces].
Examine
- Physical and environmental protection policy
- procedures addressing physical access monitoring
- physical access control logs or records
- physical access control devices
- access authorizations
- access credentials
- list of areas within the facility containing concentrations of system components or system components requiring additional physical access monitoring
- system security plan
- privacy plan
- privacy impact assessment
- privacy risk assessment documentation
- other relevant documents or records
Interview
- Organizational personnel with physical access monitoring responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Organizational processes for monitoring physical access to the system
- mechanisms supporting and/or implementing physical access monitoring for facility areas containing system components
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.