Physical Protection (PE)¶
Domain: Physical Protection (PE)
Requirements in this domain: 6
Assessment Objectives in this domain: 16
PE.L2-3.10.1¶
PE.L2-3.10.1[a]¶
Assessment Objective
authorized individuals allowed physical access are identified.
Collection Approach: Artifact
Potential Evidence Examples
Current authorized-personnel access list naming individuals permitted physical access to the facility/space housing the CUI system.
Assessment Guide – Further Discussion
Are lists of personnel with authorized access developed and maintained, and are appropriate authorization credentials issued [a]?
PE.L2-3.10.1[b]¶
Assessment Objective
physical access to organizational systems is limited to authorized individuals.
Collection Approach: Physical Review
Potential Evidence Examples
Badge-reader access log or a live card-swipe test demonstrating physical access to the facility is limited to individuals on the authorized access list (e.g., an unauthorized badge is denied).
Assessment Guide – Further Discussion
Has the facility/building manager designated building areas as “sensitive” and designed physical security protections (e.g., guards, locks, cameras, card readers) to limit physical access to the area to only authorized employees [b,c,d]?
PE.L2-3.10.1[c]¶
Assessment Objective
physical access to equipment is limited to authorized individuals.
Collection Approach: Physical Review
Potential Evidence Examples
Badge-reader access log or live card-swipe test specific to the area(s) housing system equipment (e.g., server room), demonstrating access is limited to authorized individuals.
Assessment Guide – Further Discussion
- Has the facility/building manager designated building areas as “sensitive” and designed physical security protections (e.g., guards, locks, cameras, card readers) to limit physical access to the area to only authorized employees [b,c,d]?
- Are output devices such as printers placed in areas where their use does not expose data to unauthorized individuals [c]?
PE.L2-3.10.1[d]¶
Assessment Objective
physical access to operating environments is limited to authorized individuals.
Collection Approach: Physical Review
Potential Evidence Examples
Badge-reader access log or live card-swipe test specific to the operating environment (e.g., data center, network closet), demonstrating access is limited to authorized individuals.
Assessment Guide – Further Discussion
Has the facility/building manager designated building areas as “sensitive” and designed physical security protections (e.g., guards, locks, cameras, card readers) to limit physical access to the area to only authorized employees [b,c,d]?
PE.L2-3.10.2¶
PE.L2-3.10.2[a]¶
Assessment Objective
the physical facility where that system resides is protected.
Collection Approach: Physical Review
Potential Evidence Examples
Physical inspection or photos of perimeter security measures protecting the facility (e.g., locked exterior doors, gates, fencing, security guards).
PE.L2-3.10.2[b]¶
Assessment Objective
the support infrastructure for that system is protected.
Collection Approach: Physical Review
Potential Evidence Examples
Physical inspection or photos of physical barriers protecting the support infrastructure specifically (e.g., locked server room door, restricted network closet, secured telecom room).
PE.L2-3.10.2[c]¶
Assessment Objective
the physical facility where that system resides is monitored.
Collection Approach: Physical Review
Potential Evidence Examples
Evidence of facility monitoring (e.g., CCTV camera coverage list/footage retention policy, guard post log, or physical access system audit trail) showing the facility is actively monitored.
Assessment Guide – Further Discussion
Is physical access monitored to detect and respond to physical security incidents [c,d]?
PE.L2-3.10.2[d]¶
Assessment Objective
the support infrastructure for that system is monitored.
Collection Approach: Physical Review
Potential Evidence Examples
Evidence of support-infrastructure monitoring specifically — e.g., CCTV coverage of the server room/network closet, or access-system alerts for that space.
Assessment Guide – Further Discussion
Is physical access monitored to detect and respond to physical security incidents [c,d]?
PE.L2-3.10.3¶
PE.L2-3.10.3[a]¶
Assessment Objective
visitors are escorted.
Collection Approach: Physical Review
Potential Evidence Examples
Visitor Management Policy/SOP describing the escort requirement for visitors from entry to exit, paired with a sampled visitor log showing an escort was assigned/recorded.
Assessment Guide – Further Discussion
Are personnel required to accompany visitors to areas in a facility with physical access to organizational systems [a]?
PE.L2-3.10.3[b]¶
Assessment Objective
visitor activity is monitored.
Collection Approach: Physical Review
Potential Evidence Examples
Visitor Management Policy/SOP describing how visitor activity is monitored while on-site, paired with a sampled visitor log or sign-in/sign-out sheet.
Assessment Guide – Further Discussion
- Are visitors clearly distinguishable from regular personnel [b]?
- Is visitor activity monitored (e.g., use of cameras or guards, reviews of secure areas upon visitor departure, review of visitor audit logs) [b]?
PE.L2-3.10.4¶
PE.L2-3.10.4[a]¶
Assessment Objective
audit logs of physical access are maintained.
Collection Approach: Artifact
Potential Evidence Examples
Badge system audit-log export or report showing physical access events (who, where, when) are captured and retained for the facility/spaces in scope.
Assessment Guide – Further Discussion
- Are logs of physical access to sensitive areas (both authorized access and visitor access) maintained per retention requirements [a]?
- Are visitor access records retained for as long as required [a]?
PE.L2-3.10.5¶
PE.L2-3.10.5[a]¶
Assessment Objective
physical access devices are identified.
Collection Approach: Document
Potential Evidence Examples
Document describing the physical access control devices in use (e.g., badge readers, electronic locks, mechanical keys, guard force) and where each is deployed.
Assessment Guide – Further Discussion
Are lists or inventories of physical access devices maintained (e.g., keys, facility badges, key cards) [a]?
PE.L2-3.10.5[b]¶
Assessment Objective
physical access devices are controlled.
Collection Approach: Physical Review
Potential Evidence Examples
Inventory record for physical access devices (e.g., a key/badge issuance log) showing devices are tracked and accounted for.
Assessment Guide – Further Discussion
Is access to physical access devices limited (e.g., granted to, and accessible only by, authorized individuals) [b]?
PE.L2-3.10.5[c]¶
Assessment Objective
physical access devices are managed.
Collection Approach: Physical Review
Potential Evidence Examples
Description or list of the security safeguards managing physical access devices (e.g., key-control procedures, badge-deactivation process, camera oversight of device locations).
Assessment Guide – Further Discussion
Are physical access devices managed (e.g., revoking key card access when necessary, changing locks as needed, maintaining access control devices and systems) [c]?
PE.L2-3.10.6¶
PE.L2-3.10.6[a]¶
Assessment Objective
safeguarding measures for CUI are defined for alternate work sites.
Collection Approach: Document
Potential Evidence Examples
Telework Agreement, Acceptable Use Policy, or Alternate Worksite SOP defining the physical/logical/technical safeguards required to protect CUI at alternate work sites (e.g., locked home office, privacy screen, VPN-only access), supported by user acknowledgment/training records.
PE.L2-3.10.6[b]¶
Assessment Objective
safeguarding measures for CUI are enforced for alternate work sites.
Collection Approach: Artifact
Potential Evidence Examples
Evidence the alternate-worksite safeguards are enforced — e.g., a signed telework agreement on file, VPN/technical-control configuration requiring compliant access, or a documented compliance check/attestation.
Assessment Guide – Further Discussion
- Do all alternate sites where CUI data is stored or processed meet the same physical security requirements as the main site [b]?
- Does the alternate processing site provide information security measures equivalent to those of the primary site [b]?