Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: PE-FAMILY: PHYSICAL AND ENVIRONMENTAL PROTECTION

PE-3(1) PHYSICAL ACCESS CONTROL  |  INFORMATION SYSTEM ACCESS

Scroll Prev Top Next More

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

pe-3(1)

physical access control  | information system access

 

assessment objective:

Determine if the organization:  

pe-3(1)[1]

defines physical spaces containing one or more components of the information system; and

pe-3(1)[2]

enforces physical access authorizations to the information system in addition to the physical access controls for the facility at organization-defined physical spaces containing one or more components of the information system.

potential assessment methods and objects:

Examine: [select from: Physical and environmental protection policy; procedures addressing physical access control; physical access control logs or records; physical access control devices; access authorizations; access credentials; information system entry and exit points; list of areas within the facility containing concentrations of information system components or information system components requiring additional physical protection; other relevant documents or records].

Interview: [select from: Organizational personnel with physical access authorization responsibilities; organizational personnel with information security responsibilities].

Test: [select from: Organizational processes for physical access control to the information system/components; automated mechanisms supporting and/or implementing physical access control for facility areas containing information system components].

 

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056