Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PE-6 — Monitoring Physical Access

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

4Enhancements
2Parameters
3Baseline memberships
3Assessment methods

PE — Physical and Environmental Protection · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Monitor physical access to the facility where the system resides to detect and respond to physical security incidents;
  2. b.Review physical access logs [Organization-defined: frequency] and upon occurrence of [Organization-defined: events] ; and
  3. c.Coordinate results of reviews and investigations with the organizational incident response capability.
Official NIST discussion

Discussion

Physical access monitoring includes publicly accessible areas within organizational facilities. Examples of physical access monitoring include the employment of guards, video surveillance equipment (i.e., cameras), and sensor devices. Reviewing physical access logs can help identify suspicious activity, anomalous events, or potential threats. The reviews can be supported by audit logging controls, such as [AU-2](#au-2) , if the access logs are part of an automated system. Organizational incident response capabilities include investigations of physical security incidents and responses to the incidents. Incidents include security violations or suspicious physical access activities. Suspicious physical access activities include accesses outside of normal work hours, repeated accesses to areas not normally accessed, accesses for unusual lengths of time, and out-of-sequence accesses.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

frequencythe frequency at which to review physical access logs is defined;
eventsevents or potential indication of events requiring physical access logs to be reviewed are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Monitoring Physical Access as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to physical access, facility protection, environmental safeguards, and visitor accountability.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • badge and visitor logs
  • physical access reviews
  • facility diagrams and sensor records
  • environmental and power test results

Common failure patterns

  • logical security assumptions invalidated by physical access
  • tailgating and visitor exceptions normalized
  • critical infrastructure not included in access reviews
  • environmental alarms not integrated into response

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PE-06a.physical access to the facility where the system resides is monitored to detect and respond to physical security incidents;
  2. PE-06b.
    1. PE-06b.[01]physical access logs are reviewed [Organization-defined: frequency];
    2. PE-06b.[02]physical access logs are reviewed upon occurrence of [Organization-defined: events];
  3. PE-06c.
    1. PE-06c.[01]results of reviews are coordinated with organizational incident response capabilities;
    2. PE-06c.[02]results of investigations are coordinated with organizational incident response capabilities.

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access monitoring
  • physical access logs or records
  • physical access monitoring records
  • physical access log reviews
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with physical access monitoring responsibilities
  • organizational personnel with incident response responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for monitoring physical access
  • mechanisms supporting and/or implementing physical access monitoring
  • mechanisms supporting and/or implementing the review of physical access logs
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

PE-6(1) — Intrusion Alarms and Surveillance Equipment

ModerateHigh

Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment.

Official discussion

Physical intrusion alarms can be employed to alert security personnel when unauthorized access to the facility is attempted. Alarm systems work in conjunction with physical barriers, physical access control systems, and security guards by triggering a response when these other forms of security have been compromised or breached. Physical intrusion alarms can include different types of sensor devices, such as motion sensors, contact sensors, and broken glass sensors. Surveillance equipment includes video cameras installed at strategic locations throughout the facility.

Assessment objectives and methods
  1. PE-06(01)[01]physical access to the facility where the system resides is monitored using physical intrusion alarms;
  2. PE-06(01)[02]physical access to the facility where the system resides is monitored using physical surveillance equipment.

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access monitoring
  • physical access logs or records
  • physical access monitoring records
  • physical access log reviews
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel with physical access monitoring responsibilities
  • organizational personnel with incident response responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for monitoring physical intrusion alarms and surveillance equipment
  • mechanisms supporting and/or implementing physical access monitoring
  • mechanisms supporting and/or implementing physical intrusion alarms and surveillance equipment
Official NIST control enhancement

PE-6(2) — Automated Intrusion Recognition and Responses

Recognize [Organization-defined: classes or types of intrusions] and initiate [Organization-defined: response actions] using [Organization-defined: automated mechanisms].

Official discussion

Response actions can include notifying selected organizational personnel or law enforcement personnel. Automated mechanisms implemented to initiate response actions include system alert notifications, email and text messages, and activating door locking mechanisms. Physical access monitoring can be coordinated with intrusion detection systems and system monitoring capabilities to provide integrated threat coverage for the organization.

Organization-defined parameters (3)
classes or types of intrusionsclasses or types of intrusions to be recognized by automated mechanisms are defined;
response actionsresponse actions to be initiated by automated mechanisms when organization-defined classes or types of intrusions are recognized are defined;
automated mechanismsautomated mechanisms used to recognize classes or types of intrusions and initiate response actions (defined in [PE-06(02)_ODP](#pe-06.02_odp.02)) are defined;
Assessment objectives and methods
  1. PE-06(02)[01][Organization-defined: classes or types of intrusions] are recognized;
  2. PE-06(02)[02][Organization-defined: response actions] are initiated using [Organization-defined: automated mechanisms].

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access monitoring
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • list of response actions to be initiated when specific classes/types of intrusions are recognized
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • Organizational personnel with physical access monitoring responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for monitoring physical access
  • automated mechanisms supporting and/or implementing physical access monitoring
  • automated mechanisms supporting and/or implementing recognition of classes/types of intrusions and initiation of a response
Related controls
Official NIST control enhancement

PE-6(3) — Video Surveillance

  1. (a)Employ video surveillance of [Organization-defined: operational areas];
  2. (b)Review video recordings [Organization-defined: frequency] ; and
  3. (c)Retain video recordings for [Organization-defined: time period].
Official discussion

Video surveillance focuses on recording activity in specified areas for the purposes of subsequent review, if circumstances so warrant. Video recordings are typically reviewed to detect anomalous events or incidents. Monitoring the surveillance video is not required, although organizations may choose to do so. There may be legal considerations when performing and retaining video surveillance, especially if such surveillance is in a public location.

Organization-defined parameters (3)
operational areasoperational areas where video surveillance is to be employed are defined;
frequencyfrequency at which to review video recordings is defined;
time periodtime period for which to retain video recordings is defined;
Assessment objectives and methods
  1. PE-06(03)(a)video surveillance of [Organization-defined: operational areas] is employed;
  2. PE-06(03)(b)video recordings are reviewed [Organization-defined: frequency];
  3. PE-06(03)(c)video recordings are retained for [Organization-defined: time period].

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access monitoring
  • video surveillance equipment used to monitor operational areas
  • video recordings of operational areas where video surveillance is employed
  • video surveillance equipment logs or records
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel with physical access monitoring responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for monitoring physical access
  • mechanisms supporting and/or implementing physical access monitoring
  • mechanisms supporting and/or implementing video surveillance
Official NIST control enhancement

PE-6(4) — Monitoring Physical Access to Systems

High

Monitor physical access to the system in addition to the physical access monitoring of the facility at [Organization-defined: physical spaces].

Official discussion

Monitoring physical access to systems provides additional monitoring for those areas within facilities where there is a concentration of system components, including server rooms, media storage areas, and communications centers. Physical access monitoring can be coordinated with intrusion detection systems and system monitoring capabilities to provide comprehensive and integrated threat coverage for the organization.

Organization-defined parameters (1)
physical spacesphysical spaces containing one or more components of the system are defined;
Assessment objectives and methods

physical access to the system is monitored in addition to the physical access monitoring of the facility at [Organization-defined: physical spaces].

Examine

  • Physical and environmental protection policy
  • procedures addressing physical access monitoring
  • physical access control logs or records
  • physical access control devices
  • access authorizations
  • access credentials
  • list of areas within the facility containing concentrations of system components or system components requiring additional physical access monitoring
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel with physical access monitoring responsibilities
  • organizational personnel with information security and privacy responsibilities

Test

  • Organizational processes for monitoring physical access to the system
  • mechanisms supporting and/or implementing physical access monitoring for facility areas containing system components
Source record

Authoritative sources