Policy and Procedures PE-1
Physical and Environmental Protection · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PE-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Physical and Environmental Protection family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PE-1 (Policy and Procedures) is the written foundation for the whole Physical and Environmental Protection family. It says you have an approved policy that explains why you protect the place your system lives, who is responsible, and how the rules are carried out — plus the procedures that turn the policy into day-to-day action. It is a Low-baseline control, and every other PE control leans on it.
What good looks like
- Have a written, approved policy that covers purpose, scope, roles, responsibilities, and how it lines up with any laws or rules that apply.
- Name an owner — a specific person or role responsible for keeping the policy and procedures current.
- Pair the policy with procedures that say how each rule is actually carried out.
- Distribute the policy to the people it applies to, so it is not just sitting in a drawer.
- Review and update the policy on a set schedule (for example, yearly) and after any big change or incident.
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
How to move it toward Implemented
- Write a one- to two-page physical protection policy for the room or rack where the lab server sits: purpose, who is responsible, and what the access and environmental rules are.
- Add a short procedures section that spells out the routine tasks — who unlocks the room, how visitors are handled, and how the access list is reviewed.
- Put a review date and an owner at the top, and set a calendar reminder to revisit it yearly.
- Attach the signed policy-and-procedures document as hardening evidence on the asset, naming
PE-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.