|
controlPE-2
Physical Access Authorizations (PE-2)
Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides; Issue authorization credentials for facility access; Review the access list detailing authorized facility access by individuals [organization-defined] ; and Remove individuals from the facility access list when access is no longer required.
Security Baselines
LOWMODERATEHIGH
physical-securityenvironmentalfacilities
Why These Connect
Maps To4
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports26
These related controls work together — a change to one may affect the others.
Enhances3
These enhancements add specific capabilities or refinements to the base control.
Related Controls(18)
AC-2Account Management (AC-2)
LMH
AU-9Protection of Audit Information (AU-9)LMH
IA-2Identification and Authentication (Organizational Users) (IA-2)LMH
IA-4Identifier Management (IA-4)LMH
IA-5Authenticator Management (IA-5)LMH
MA-5Maintenance Personnel (MA-5)LMH
MP-2Media Access (MP-2)LMH
AT-3Role-based Training (AT-3)LMH
PE-3Physical Access Control (PE-3)LMH
PE-4Access Control for Transmission (PE-4)MH
PE-5Access Control for Output Devices (PE-5)MH
PE-8Visitor Access Records (PE-8)LMH
PM-12Insider Threat Program (PM-12)PS-3Personnel Screening (PS-3)LMH
PS-4Personnel Termination (PS-4)LMH
PS-5Personnel Transfer (PS-5)LMH
PS-6Access Agreements (PS-6)LMH
PS-2Position Risk Designation (PS-2)LMH
Cross-Framework Mappings(4)
PR.AA-06PR.AA-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule4 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
PR.AA-06PR.AA-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5