Physical Access Authorizations PE-2
Physical and Environmental Protection · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PE-2 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Physical and Environmental Protection family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PE-2 (Physical Access Authorizations) is about keeping a deliberate list of who is allowed into the place the system lives, and why. You approve people onto the list, issue whatever credential lets them in, review the list on a schedule, and take people off when they no longer need access. It is a Low-baseline control.
What good looks like
- Keep an approved list of every person allowed into the room or facility where the server sits.
- Issue a credential — a key, badge, or door code — only after access is approved.
- Tie each entry to a reason (their role or task), not just a name.
- Review the list on a schedule to catch people who no longer belong on it.
- Remove access promptly when someone leaves, changes roles, or no longer needs it.
Framework mapping
- NIST CSF 2.0 — PR.AA-06 — Physical access to assets is managed, monitored, and enforced commensurate with risk
How to move it toward Implemented
- Create a simple authorized-access list (a spreadsheet or a dated text file) naming each person, their reason for access, and the date approved.
- Note which credential each person holds — key number, badge, or door code — so you can account for every way in.
- Set a review cadence (for example, quarterly), and record the date each time you check the list and remove anyone who no longer needs in.
- Attach the dated authorized-access list as hardening evidence on the asset, naming
PE-2in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.