Book:Comprehensive Guide to Developing and Implementing a Cybersecurity Plan/A simplified description of NIST Special Publication 800-53 controls, with ties to LIMSpec/Physical and environmental protection

From LIMSWiki
Jump to navigationJump to search

Appendix 1.11 Physical and environmental protection

PE-1 Policy and procedures

This control recommends the organization develop, document, disseminate, review, and update physical and environmental protection policies and procedures. It asks organizations to not only address the purpose, scope, roles, responsibilities, and enforcement of physical and environmental protection action but also to address how those policies and procedures will be implemented, reviewed, and updated.

Additional resources:

PE-2 Physical access authorizations

This control recommends the organization develop, approve, and maintain a list of individuals who are vetted and authorized to access the facilities where the system physically resides. Those individuals should be issued credentials to access the facility, and those credentials should be reviewed at a defined frequency. Those individuals who no longer require access to the facility should be removed from the physical access list promptly.

Additional resources:

  • No LIMSpec comp (organizational policy rather than system specification)

PE-3 Physical access control

This control recommends the organization enact physical access controls through the facility where the system physically resides. Those controls include verifying individual access authorization before allowing admittance, using access control devices or personnel, maintaining physical access audit logs, providing security safeguards for accessing controlled areas from public areas, escorting visitors, monitoring visitor activity, securing keys and passwords controls, inventorying physical access devices regularly, and changing keys and password controls when circumstances require.

Additional resources:

PE-3 (1) Physical access control: System access

This control enhancement recommends the organization provide, in addition to overall facility access control, a mechanism for physically securing areas within the facility that house critical information system components.

Additional resources:

PE-6 Monitoring physical access

This control recommends the organization monitor the areas within the facility that house critical information system components for detecting and responding to physical security incidents. The organization should also review physical access logs at a determined frequency or when a security event (or possibility of a security event) is identified. Individuals with responsibility for monitoring the system's physical locations should also coordinate with the incident response team in reviews and investigations.

Additional resources:

PE-6 (1) Monitoring physical access: Intrusion alarms and surveillance equipment

This control enhancement recommends the organization monitor physical intrusion alarms and surveillance equipment.

Additional resources:

PE-6 (4) Monitoring physical access: Monitoring physical access to systems

This control enhancement recommends the organization provide, in addition to overall facility monitoring, a means of monitoring areas within the facility that house critical system components.

Additional resources:

PE-8 Visitor access records

This control recommends the organization retain visitor access records to the facility housing the physical information system for a designated period of time, reviewing those records at a defined frequency.

Additional resources:

  • No LIMSpec comp (organizational policy rather than system specification)

PE-12 Emergency lighting

This control recommends the organization ensure the facility housing the physical information system employs and maintains automatic emergency lighting capable of activating off of its own independent power supply during a power outage or other type of disruption.

Additional resources:

  • No LIMSpec comp (organizational policy rather than system specification)

PE-13 Fire protection

This control recommends the organization ensure the facility housing the physical information system employs and maintains fire suppression and detection systems capable of activating off of its own independent power supply during a fire incident.

Additional resources:

  • No LIMSpec comp (organizational policy rather than system specification)

PE-14 Environmental controls

This control recommends the organization maintain temperature, humidity, and other environmental conditions in the facility housing the physical information system at a defined set of acceptable levels, monitoring those levels at a defined frequency.

Additional resources:

  • No LIMSpec comp (organizational policy rather than system specification)

PE-15 Water damage protection

This control recommends the organization ensure the facility housing the physical information system has emergency water shutoff or isolation valves that are accessible, functional, and clearly marked and known to personnel, with the goal of protecting the system components from water leakage.

Additional resources:

  • No LIMSpec comp (organizational policy rather than system specification)

PE-16 Delivery and removal

This control recommends the organization ensure any pick-up or drop-off activities of information system components at the facility housing the physical information system are authorized, monitored, and controlled, preferably isolating such activities outside of areas where critical system components or media are located.

Additional resources:

  • No LIMSpec comp (organizational policy rather than system specification)

References