Show/Hide Toolbars

ABCI Consultants

Guidance for NIST 800-171 Assessment & Compliance

Navigation: PE-FAMILY: PHYSICAL AND ENVIRONMENTAL PROTECTION

PE-3(2) PHYSICAL ACCESS CONTROL  |  FACILITY/INFORMATION SYSTEM BOUNDARIES

Scroll Prev Top Next More

Applicable

(Y)es / (N)o

(C)onfidentiality

(I)ntegrity

(A)vailability

RPN

(C+I+A)

(S)atisfactory

L1

M2

H3

L1

M2

H3

L1

M2

H3

(O)ther than satisfactory +##

 

 

 

 

 

 

 

 

 

 

 

 

###

pe-3(2)

physical access control  | facility/information system boundaries

 

assessment objective:

Determine if the organization:  

pe-3(2)[1]

defines the frequency to perform security checks at the physical boundary of the facility or information system for:

pe-3(2)[1][a]

unauthorized exfiltration of information; or

pe-3(2)[1][b]

removal of information system components; and

pe-3(2)[2]

performs security checks with the organization-defined frequency at the physical boundary of the facility or information system for:

pe-3(2)[2][a]

unauthorized exfiltration of information; or

pe-3(2)[2][b]

removal of information system components.

potential assessment methods and objects:

Examine: [select from: Physical and environmental protection policy; procedures addressing physical access control; physical access control logs or records; records of security checks; security audit reports; security inspection reports; facility layout documentation; information system entry and exit points; other relevant documents or records].

Interview: [select from: Organizational personnel with physical access control responsibilities; organizational personnel with information security responsibilities].

Test: [select from: Organizational processes for physical access control to the facility and/or information system; automated mechanisms supporting and/or implementing physical access control for the facility or information system; automated mechanisms supporting and/or implementing security checks for unauthorized exfiltration of information].

Hosted by ABCI Consultants for Information Security Management Systems | Implementations, Training and Assessments for Compliance | (800) 644-2056