Skip to content

Physical Protection (PE)

Domain: Physical Protection (PE)
Requirements in this domain: 6
Assessment Objectives in this domain: 16


PE.L2-3.10.1

PE.L2-3.10.1[a]

Assessment Objective

authorized individuals allowed physical access are identified.

Collection Approach: Artifact

Potential Evidence Examples

Current authorized-personnel access list naming individuals permitted physical access to the facility/space housing the CUI system.

Assessment Guide – Further Discussion

Are lists of personnel with authorized access developed and maintained, and are appropriate authorization credentials issued [a]?


PE.L2-3.10.1[b]

Assessment Objective

physical access to organizational systems is limited to authorized individuals.

Collection Approach: Physical Review

Potential Evidence Examples

Badge-reader access log or a live card-swipe test demonstrating physical access to the facility is limited to individuals on the authorized access list (e.g., an unauthorized badge is denied).

Assessment Guide – Further Discussion

Has the facility/building manager designated building areas as “sensitive” and designed physical security protections (e.g., guards, locks, cameras, card readers) to limit physical access to the area to only authorized employees [b,c,d]?


PE.L2-3.10.1[c]

Assessment Objective

physical access to equipment is limited to authorized individuals.

Collection Approach: Physical Review

Potential Evidence Examples

Badge-reader access log or live card-swipe test specific to the area(s) housing system equipment (e.g., server room), demonstrating access is limited to authorized individuals.

Assessment Guide – Further Discussion

  • Has the facility/building manager designated building areas as “sensitive” and designed physical security protections (e.g., guards, locks, cameras, card readers) to limit physical access to the area to only authorized employees [b,c,d]?
  • Are output devices such as printers placed in areas where their use does not expose data to unauthorized individuals [c]?

PE.L2-3.10.1[d]

Assessment Objective

physical access to operating environments is limited to authorized individuals.

Collection Approach: Physical Review

Potential Evidence Examples

Badge-reader access log or live card-swipe test specific to the operating environment (e.g., data center, network closet), demonstrating access is limited to authorized individuals.

Assessment Guide – Further Discussion

Has the facility/building manager designated building areas as “sensitive” and designed physical security protections (e.g., guards, locks, cameras, card readers) to limit physical access to the area to only authorized employees [b,c,d]?


PE.L2-3.10.2

PE.L2-3.10.2[a]

Assessment Objective

the physical facility where that system resides is protected.

Collection Approach: Physical Review

Potential Evidence Examples

Physical inspection or photos of perimeter security measures protecting the facility (e.g., locked exterior doors, gates, fencing, security guards).


PE.L2-3.10.2[b]

Assessment Objective

the support infrastructure for that system is protected.

Collection Approach: Physical Review

Potential Evidence Examples

Physical inspection or photos of physical barriers protecting the support infrastructure specifically (e.g., locked server room door, restricted network closet, secured telecom room).


PE.L2-3.10.2[c]

Assessment Objective

the physical facility where that system resides is monitored.

Collection Approach: Physical Review

Potential Evidence Examples

Evidence of facility monitoring (e.g., CCTV camera coverage list/footage retention policy, guard post log, or physical access system audit trail) showing the facility is actively monitored.

Assessment Guide – Further Discussion

Is physical access monitored to detect and respond to physical security incidents [c,d]?


PE.L2-3.10.2[d]

Assessment Objective

the support infrastructure for that system is monitored.

Collection Approach: Physical Review

Potential Evidence Examples

Evidence of support-infrastructure monitoring specifically — e.g., CCTV coverage of the server room/network closet, or access-system alerts for that space.

Assessment Guide – Further Discussion

Is physical access monitored to detect and respond to physical security incidents [c,d]?


PE.L2-3.10.3

PE.L2-3.10.3[a]

Assessment Objective

visitors are escorted.

Collection Approach: Physical Review

Potential Evidence Examples

Visitor Management Policy/SOP describing the escort requirement for visitors from entry to exit, paired with a sampled visitor log showing an escort was assigned/recorded.

Assessment Guide – Further Discussion

Are personnel required to accompany visitors to areas in a facility with physical access to organizational systems [a]?


PE.L2-3.10.3[b]

Assessment Objective

visitor activity is monitored.

Collection Approach: Physical Review

Potential Evidence Examples

Visitor Management Policy/SOP describing how visitor activity is monitored while on-site, paired with a sampled visitor log or sign-in/sign-out sheet.

Assessment Guide – Further Discussion

  • Are visitors clearly distinguishable from regular personnel [b]?
  • Is visitor activity monitored (e.g., use of cameras or guards, reviews of secure areas upon visitor departure, review of visitor audit logs) [b]?

PE.L2-3.10.4

PE.L2-3.10.4[a]

Assessment Objective

audit logs of physical access are maintained.

Collection Approach: Artifact

Potential Evidence Examples

Badge system audit-log export or report showing physical access events (who, where, when) are captured and retained for the facility/spaces in scope.

Assessment Guide – Further Discussion

  • Are logs of physical access to sensitive areas (both authorized access and visitor access) maintained per retention requirements [a]?
  • Are visitor access records retained for as long as required [a]?

PE.L2-3.10.5

PE.L2-3.10.5[a]

Assessment Objective

physical access devices are identified.

Collection Approach: Document

Potential Evidence Examples

Document describing the physical access control devices in use (e.g., badge readers, electronic locks, mechanical keys, guard force) and where each is deployed.

Assessment Guide – Further Discussion

Are lists or inventories of physical access devices maintained (e.g., keys, facility badges, key cards) [a]?


PE.L2-3.10.5[b]

Assessment Objective

physical access devices are controlled.

Collection Approach: Physical Review

Potential Evidence Examples

Inventory record for physical access devices (e.g., a key/badge issuance log) showing devices are tracked and accounted for.

Assessment Guide – Further Discussion

Is access to physical access devices limited (e.g., granted to, and accessible only by, authorized individuals) [b]?


PE.L2-3.10.5[c]

Assessment Objective

physical access devices are managed.

Collection Approach: Physical Review

Potential Evidence Examples

Description or list of the security safeguards managing physical access devices (e.g., key-control procedures, badge-deactivation process, camera oversight of device locations).

Assessment Guide – Further Discussion

Are physical access devices managed (e.g., revoking key card access when necessary, changing locks as needed, maintaining access control devices and systems) [c]?


PE.L2-3.10.6

PE.L2-3.10.6[a]

Assessment Objective

safeguarding measures for CUI are defined for alternate work sites.

Collection Approach: Document

Potential Evidence Examples

Telework Agreement, Acceptable Use Policy, or Alternate Worksite SOP defining the physical/logical/technical safeguards required to protect CUI at alternate work sites (e.g., locked home office, privacy screen, VPN-only access), supported by user acknowledgment/training records.


PE.L2-3.10.6[b]

Assessment Objective

safeguarding measures for CUI are enforced for alternate work sites.

Collection Approach: Artifact

Potential Evidence Examples

Evidence the alternate-worksite safeguards are enforced — e.g., a signed telework agreement on file, VPN/technical-control configuration requiring compliant access, or a documented compliance check/attestation.

Assessment Guide – Further Discussion

  • Do all alternate sites where CUI data is stored or processed meet the same physical security requirements as the main site [b]?
  • Does the alternate processing site provide information security measures equivalent to those of the primary site [b]?