PE-02 Physical Access Authorizations

Physical and Environmental Protection

Low Moderate High

Description

The organization develops and keeps current a list of personnel with authorized access to the facility where the information system resides (except for those areas within the facility officially designated as publicly accessible) and issues appropriate authorization credentials. Designated officials within the organization review and approve the access list and authorization credentials [Assignment: organization-defined frequency, at least annually].\n

Supplemental Guidance

Appropriate authorization credentials include, for example, badges, identification cards, and smart cards. The organization promptly removes from the access list personnel no longer requiring access to the facility where the information system resides.\n

Enhancements

(0) None.\n

Compliance Mappings

ISO 27002:2022

5.155.187.1

COBIT 2019

DSS05.05

NIST CSF 2.0

PR.AAPR.AA-06

SOC 2 TSC

CC6.4CC6.4-POF1CC6.4-POF2

ISO 17799 (legacy)

9.1.29.1.6

COBIT 4.1 (legacy)

DS12.3