Physical Protection (PE)¶
PE.L2-3.10.1 – Limit Physical Access [CUI Data]¶
Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 46.
Determine if:
- [a] authorized individuals allowed physical access are identified;
- [b] physical access to organizational systems is limited to authorized individuals;
- [c] physical access to equipment is limited to authorized individuals; and
- [d] physical access to operating environments is limited to authorized individuals.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 46.
Examine: [SELECT FROM: Physical and environmental protection policy; procedures addressing physical access authorizations; system security plan; authorized personnel access list; authorization credentials; physical access list reviews; physical access termination records and associated documentation; other relevant documents or records].
Interview: [SELECT FROM: Personnel with physical access authorization responsibilities; personnel with physical access to system facility; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for physical access authorizations; mechanisms supporting or implementing physical access authorizations].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 32.
This requirement applies to employees, individuals with permanent physical access authorization credentials, and visitors. Authorized individuals have credentials that include badges, identification cards, and smart cards. Organizations determine the strength of authorization credentials needed consistent with applicable laws, directives, policies, regulations, standards, procedures, and guidelines. This requirement applies only to areas within facilities that have not been designated as publicly accessible. Limiting physical access to equipment may include placing equipment in locked rooms or other secured areas and allowing access to authorized individuals only, and placing equipment in locations that can be monitored by organizational personnel. Computing devices, external disk drives, networking devices, monitors, printers, copiers, scanners, facsimile machines, and audio devices are examples of equipment.
Further Discussion¶
This addresses the company’s physical space (e.g., office, testing environments, equipment rooms), technical assets, and non-technical assets that need to be protected from unauthorized physical access. Specific environments are limited to authorized employees, and access is controlled with badges, electronic locks, physical key locks, etc. Output devices, such as printers, are placed in areas where their use does not expose data to unauthorized individuals. Lists of personnel with authorized access are developed and maintained, and personnel are issued appropriate authorization credentials.
Examples¶
- You manage a DoD project that requires special equipment used only by project team members [b,c]. You work with the facilities manager to put locks on the doors to the areas where the equipment is stored and used [b,c,d]. Project team members are the only individuals issued with keys to the space. This restricts access to only those employees who work on the DoD project and require access to that equipment.
Potential Assessment Considerations¶
- Are lists of personnel with authorized access developed and maintained, and are appropriate authorization credentials issued [a]?
- Has the facility/building manager designated building areas as “sensitive” and designed physical security protections (e.g., guards, locks, cameras, card readers) to limit physical access to the area to only authorized employees [b,c,d]?
- Are output devices such as printers placed in areas where their use does not expose data to unauthorized individuals [c]?
Key References¶
- NIST SP 800-171 Rev. 2 3.10.1
- FAR Clause 52.204-21 b.1.viii
PE.L2-3.10.2 – Monitor Facility¶
Protect and monitor the physical facility and support infrastructure for organizational systems.
Assessment Objectives¶
Determine if:
- [a] the physical facility where organizational systems reside is protected;
- [b] the support infrastructure for organizational systems is protected;
- [c] the physical facility where organizational systems reside is monitored; and
- [d] the support infrastructure for organizational systems is monitored.
Potential Assessment Methods and Objects¶
Examine: [SELECT FROM: Physical and environmental protection policy; procedures addressing physical access monitoring; system security plan; physical access logs or records; physical access monitoring records; physical access log reviews; other relevant documents or records].
Interview: [SELECT FROM: Personnel with physical access monitoring responsibilities; personnel with incident response responsibilities; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for monitoring physical access; mechanisms supporting or implementing physical access monitoring; mechanisms supporting or implementing the review of physical access logs].
Discussion¶
Monitoring of physical access includes publicly accessible areas within organizational facilities. This can be accomplished, for example, by the employment of guards; the use of sensor devices; or the use of video surveillance equipment such as cameras. Examples of support infrastructure include system distribution, transmission, and power lines. Security controls applied to the support infrastructure prevent accidental damage, disruption, and physical tampering. Such controls may also be necessary to prevent eavesdropping or modification of unencrypted transmissions. Physical access controls to support infrastructure include locked wiring closets; disconnected or locked spare jacks; protection of cabling by conduit or cable trays; and wiretapping sensors.
Further Discussion¶
The infrastructure inside of a facility, such as power and network cables, is protected so that visitors and unauthorized employees cannot access it. The protection is also monitored by security guards, video cameras, sensors, or alarms.
Examples¶
- You are responsible for protecting your IT facilities. You install video cameras at each entrance and exit, connect them to a video recorder, and show the camera feeds on a display at the reception desk [c,d]. You also make sure there are secure locks on all entrances, exits, and windows to the facilities [a,b].
Potential Assessment Considerations¶
- Is physical access monitored to detect and respond to physical security incidents [c, d]?
Key References¶
- NIST SP 800-171 Rev 2 3.10.2
PE.L2-3.10.3 – Escort Visitors [CUI Data]¶
Escort visitors and monitor visitor activity.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 47.
Determine if:
- [a] visitors are escorted; and
- [b] visitor activity is monitored.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 47.
Examine: [SELECT FROM: Physical and environmental protection policy; procedures addressing physical access control; system security plan; physical access control logs or records; inventory records of physical access control devices; system entry and exit points; records of key and lock combination changes; storage locations for physical access control devices; physical access control devices; list of security safeguards controlling access to designated publicly accessible areas within facility; other relevant documents or records].
Interview: [SELECT FROM: Personnel with physical access control responsibilities; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for physical access control; mechanisms supporting or implementing physical access control; physical access control devices].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 32.
Individuals with permanent physical access authorization credentials are not considered visitors. Audit logs can be used to monitor visitor activity.
Further Discussion¶
Do not allow visitors, even those people you know well, to walk around your facility without an escort. Make sure that all non-employees wear special visitor badges and/or are escorted by an employee at all times while on the property.
Examples¶
- Coming back from a meeting, you see the friend of a coworker walking down the hallway near your office. You know this person well and trust them, but are not sure why they are in the building. You stop to talk, and the person explains that they are meeting a coworker for lunch, but cannot remember where the lunchroom is. You walk the person back to the reception area to get a visitor badge and wait until someone can escort them to the lunch room [a]. You report this incident and the company decides to install a badge reader at the main door so visitors cannot enter without an escort [a].
Potential Assessment Considerations¶
- Are personnel required to accompany visitors to areas in a facility with physical access to organizational systems [a]?
- Are visitors clearly distinguishable from regular personnel [b]?
- Is visitor activity monitored (e.g., use of cameras or guards, reviews of secure areas upon visitor departure, review of visitor audit logs) [b]?
Key References¶
- NIST SP 800-171 Rev. 2 3.10.3
- FAR Clause 52.204-21 Partial b.1.ix
PE.L2-3.10.4 – Physical Access Logs [CUI Data]¶
Maintain audit logs of physical access.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 47.
Determine if:
- [a] audit logs of physical access are maintained.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 47.
Examine: [SELECT FROM: Physical and environmental protection policy; procedures addressing physical access control; system security plan; physical access control logs or records; inventory records of physical access control devices; system entry and exit points; records of key and lock combination changes; storage locations for physical access control devices; physical access control devices; list of security safeguards controlling access to designated publicly accessible areas within facility; other relevant documents or records].
Interview: [SELECT FROM: Personnel with physical access control responsibilities; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for physical access control; mechanisms supporting or implementing physical access control; physical access control devices].
Discussion¶
Source: NIST SP 800-171 Rev. 2, pp. 32-33.
Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural (e.g., written log of individuals accessing the facility), automated (e.g., capturing ID provided by a PIV card), or some combination thereof. Physical access points can include facility access points, interior access points to systems or system components requiring supplemental access controls, or both. System components (e.g., workstations, notebook computers) may be in areas designated as publicly accessible with organizations safeguarding access to such devices.
Further Discussion¶
Make sure you have a record of who accesses your facility (e.g., office, plant, factory). You can do this in writing by having employees and visitors sign in and sign out or by electronic means such as badge readers. Whatever means you use, you need to retain the access records for the time period that your company has defined.
Examples¶
- You and your coworkers like to have friends and family join you for lunch at the office on Fridays. Your small company has just signed a contract with the DoD, however, and you now need to document who enters and leaves your facility. You work with the reception staff to ensure that all non-employees sign in at the reception area and sign out when they leave [a]. You retain those paper sign-in sheets in a locked filing cabinet for one year. Employees receive badges or key cards that enable tracking and logging access to company facilities.
Potential Assessment Considerations¶
- Are logs of physical access to sensitive areas (both authorized access and visitor access) maintained per retention requirements [a]?
- Are visitor access records retained for as long as required [a]?
Key References¶
- NIST SP 800-171 Rev. 2 3.10.4
- FAR Clause 52.204-21 Partial b.1.ix
PE.L2-3.10.5 – Manage Physical Access [CUI Data]¶
Control and manage physical access devices.
Assessment Objectives¶
Source: NIST SP 800-171A, pp. 47-48.
Determine if:
- [a] physical access devices are identified;
- [b] physical access devices are controlled; and
- [c] physical access devices are managed.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, pp. 47-48.
Examine: [SELECT FROM: Physical and environmental protection policy; procedures addressing physical access control; system security plan; physical access control logs or records; inventory records of physical access control devices; system entry and exit points; records of key and lock combination changes; storage locations for physical access control devices; physical access control devices; list of security safeguards controlling access to designated publicly accessible areas within facility; other relevant documents or records].
Interview: [SELECT FROM: Personnel with physical access control responsibilities; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for physical access control; mechanisms supporting or implementing physical access control; physical access control devices].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 33.
Physical access devices include keys, locks, combinations, and card readers.
Further Discussion¶
Identifying and controlling physical access devices (e.g., locks, badges, key cards) is just as important as monitoring and limiting who is able to physically access certain equipment. Physical access devices are only strong protection if you know who has them and what access they allow. Physical access devices can be managed using manual or automatic processes such a list of who is assigned what key, or updating the badge access system as personnel change roles.
Examples¶
- You are a facility manager. A team member retired today and returns their company keys to you. The project on which they were working requires access to areas that contain equipment with CUI. You receive the keys, check your electronic records against the serial numbers on the keys to ensure all have been returned, and mark each key returned [c].
Potential Assessment Considerations¶
- Are lists or inventories of physical access devices maintained (e.g., keys, facility badges, key cards) [a]?
- Is access to physical access devices limited (e.g., granted to, and accessible only by, authorized individuals) [b]?
- Are physical access devices managed (e.g., revoking key card access when necessary, changing locks as needed, maintaining access control devices and systems) [c]?
Key References¶
- NIST SP 800-171 Rev. 2 3.10.5
- FAR Clause 52.204-21 Partial b.1.ix
PE.L2-3.10.6 – Alternative Work Sites¶
Enforce safeguarding measures for CUI at alternate work sites.
Assessment Objectives¶
Source: NIST SP 800-171A, p. 48.
Determine if:
- [a] safeguarding measures for CUI are defined for alternate work sites; and
- [b] safeguarding measures for CUI are enforced for alternate work sites.
Potential Assessment Methods and Objects¶
Source: NIST SP 800-171A, p. 48.
Examine: [SELECT FROM: Physical and environmental protection policy; procedures addressing alternate work sites for personnel; system security plan; list of safeguards required for alternate work sites; assessments of safeguards at alternate work sites; other relevant documents or records].
Interview: [SELECT FROM: Personnel approving use of alternate work sites; personnel using alternate work sites; personnel assessing controls at alternate work sites; personnel with information security responsibilities].
Test: [SELECT FROM: Organizational processes for security at alternate work sites; mechanisms supporting alternate work sites; safeguards employed at alternate work sites; means of communications between personnel at alternate work sites and security personnel].
Discussion¶
Source: NIST SP 800-171 Rev. 2, p. 33.
Alternate work sites may include government facilities or the private residences of employees. Organizations may define different security requirements for specific alternate work sites or types of sites depending on the work-related activities conducted at those sites. NIST SP 800-46 and NIST SP 800-114 provide guidance on enterprise and user security when teleworking.
Further Discussion¶
Many people work from home or travel as part of their job. Define and implement safeguards to account for protection of information beyond the enterprise perimeter. Safeguards may include physical protections, such as locked file drawers, as well as electronic protections such as encryption, audit logging, and proper access controls.
Examples¶
- Many of your company’s project managers work remotely as they often travel to sponsor locations or even work from home. Because the projects on which they work require access to CUI, you must ensure the same level of protection is afforded as when they work in the office. You ensure that each laptop is deployed with patch management and anti-virus software protection [b]. Because data may be stored on the local hard drive, you have enabled full-disk encryption on their laptops [b]. When a remote staff member needs access to the internal network you require VPN connectivity that also disconnects the laptop from the remote network (i.e., prevents split tunneling) [b]. The VPN requires multifactor authentication to verify remote users are who they claim to be [b].
Potential Assessment Considerations¶
- Do all alternate sites where CUI data is stored or processed meet the same physical security requirements as the main site [b]?
- Does the alternate processing site provide information security measures equivalent to those of the primary site [b]?
Key References¶
- NIST SP 800-171 Rev. 2 3.10.6