PR.AA-06: Physical access to assets is managed, monitored, and enforced commensurate with risk
Threats Addressed:
Subcategory is new to this version of the framework and incorporates the following items from the previous version: PR.AC-2: Physical access to assets is managed and protected, PR.PT-4: Communications and control networks are protected.
Description
[csf.tools Note: Subcategories do not have detailed descriptions. However NIST has provided the following implementation examples.]
Implementation Examples
1st: 1st Party Risk
3rd: 3rd Party Risk
Ex1: Use security guards, security cameras, locked entrances, alarm systems, and other physical controls to monitor facilities and restrict access
Ex2: Employ additional physical security controls for areas that contain high-risk assets
Ex3: Escort guests, vendors, and other third parties within areas that contain business-critical assets
Related Controls
NIST Special Publication 800-53 Revision 5.2.0
PE-2: Physical Access Authorizations
Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides; Issue authorization credentials for facility access; Review the access list detailing authorized facility access by individuals [Assignment: organization-defined frequency] ; and Remove individuals from the facility access list when access is no longer required.
PE-3: Physical Access Control
Enforce physical access authorizations at [Assignment: organization-defined entry and exit points] by: Verifying individual access authorizations before granting access to the facility; and Controlling ingress and egress to the facility using [Assignment (one or more): [Assignment: organization-defined systems or devices] , guards]; Maintain physical access audit logs for [Assignment: organization-defined entry or exit points]; Control…
PE-4: Access Control for Transmission
Control physical access to [Assignment: organization-defined system distribution and transmission lines] within organizational facilities using [Assignment: organization-defined security controls].
PE-5: Access Control for Output Devices
Control physical access to output from [Assignment: organization-defined output devices] to prevent unauthorized individuals from obtaining the output.
PE-6: Monitoring Physical Access
Monitor physical access to the facility where the system resides to detect and respond to physical security incidents; Review physical access logs [Assignment: organization-defined frequency] and upon occurrence of [Assignment: organization-defined events] ; and Coordinate results of reviews and investigations with the organizational incident response capability.
PE-8: Visitor Access Records
Maintain visitor access records to the facility where the system resides for [Assignment: organization-defined time period]; Review visitor access records [Assignment: organization-defined frequency] ; and Report anomalies in visitor access records to [Assignment: organization-defined personnel].
PE-18: Location of System Components
Position system components within the facility to minimize potential damage from [Assignment: organization-defined physical and environmental hazards] and to minimize the opportunity for unauthorized access.
PE-19: Information Leakage
Protect the system from information leakage due to electromagnetic signals emanations.
PE-20: Asset Monitoring and Tracking
Employ [Assignment: organization-defined asset location technologies] to track and monitor the location and movement of [Assignment: organization-defined assets] within [Assignment: organization-defined controlled areas].
NIST SP 800-171 Revision 3.0
03.10.01: Physical Access Authorizations
Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides. Issue authorization credentials for facility access. Review the facility access list [Assignment: organization-defined frequency]. Remove individuals from the facility access list when access is no longer required.
03.10.02: Monitoring Physical Access
Monitor physical access to the facility where the system resides to detect and respond to physical security incidents. Review physical access logs [Assignment: organization-defined frequency] and upon occurrence of [Assignment: organization-defined events or potential indicators of events].
03.10.07: Physical Access Control
Enforce physical access authorizations at entry and exit points to the facility where the system resides by: Verifying individual physical access authorizations before granting access to the facility and Controlling ingress and egress with physical access control systems, devices, or guards. Maintain physical access audit logs for entry or exit points. Escort visitors, and control…
03.10.08: Access Control for Transmission
Control physical access to system distribution and transmission lines within organizational facilities.
Cloud Controls Matrix v4.0
DCS-03: Secure Area Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for maintaining a safe and secure working environment in offices, rooms, and facilities. Review and update the policies and procedures at least annually.
DCS-07: Controlled Access Points
Implement physical security perimeters to safeguard personnel, data, and information systems. Establish physical security perimeters between the administrative and business areas and the data storage and processing facilities areas.
DCS-09: Secure Area Authorization
Allow only authorized personnel access to secure areas, with all ingress and egress points restricted, documented, and monitored by physical access control mechanisms. Retain access control records on a periodic basis as deemed appropriate by the organization.
DCS-10: Surveillance System
Implement, maintain, and operate datacenter surveillance systems at the external perimeter and at all the ingress and egress points to detect unauthorized ingress and egress attempts.
DCS-12: Cabling Security
Define, implement and evaluate processes, procedures and technical measures that ensure a risk-based protection of power and telecommunication cables from a threat of interception, interference or damage at all facilities, offices and rooms.
DCS-14: Secure Utilities
Secure, monitor, maintain, and test utilities services for continual effectiveness at planned intervals.
HRS-04: Remote and Home Working Policy and Procedures
Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect information accessed, processed or stored at remote sites and locations. Review and update the policies and procedures at least annually.
LOG-12: Access Control Logs
Monitor and log physical access using an auditable access control system.
UEM-05: Endpoint Management
Define, implement and evaluate processes, procedures and technical measures to enforce policies and controls for all endpoints permitted to access systems and/or store, transmit, or process organizational data.
UEM-06: Automatic Lock Screen
Configure all relevant interactive-use endpoints to require an automatic lock screen.
UEM-14: Third-Party Endpoint Security Posture
Define, implement and evaluate processes, procedures and technical and/or contractual measures to maintain proper security of third-party endpoints with access to organizational assets.