unified
UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards
Physical access to facilities, data centers, and protected assets is authorized, badged, logged, monitored, and revoked on separation, commensurate with risk. Environmental protections including power conditioning and backup, fire detection and suppression, and temperature and humidity control safeguard systems, and physical access and environmental events are reviewed.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Physical & Environmental Security
- type
- preventive
- category
- physical
Details
- unified_id
- UC-ACCESS-19
- title
- Restrict physical access and maintain environmental safeguards
- statement
- Physical access to facilities, data centers, and protected assets is authorized, badged, logged, monitored, and revoked on separation, commensurate with risk. Environmental protections including power conditioning and backup, fire detection and suppression, and temperature and humidity control safeguard systems, and physical access and environmental events are reviewed.
- domain
- Physical & Environmental Security
- control_type
- preventive
- control_category
- physical
- members
- framework
- nist-csf-2
- control_id
- PR.AA-06
- coverage
- full
- relationship
- superset_of
- framework
- soc1
- control_id
- SOC1-10
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards mitigates Physical and cyber-physical attacks on facilities and infrastructure
- strength
- related
- rationale
- Access authorization plus review of physical/environmental events deters and detects an adversary physically reaching and sabotaging infrastructure.
- Facility Access Administration & Monitoring operates UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards
- UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards maps_to PR.AA-06 — Identity Management, Authentication, and Access Control: Physical access to assets is managed, monitored, and enforced commensurate with risk
- framework
- nist-csf-2
- control_id
- PR.AA-06
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards mitigates Environmental degradation of equipment (dust, humidity, temperature, EMI)
- strength
- primary
- rationale
- Temperature/humidity control and power conditioning directly prevent equipment degradation from thermal and voltage variation.
- UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards mitigates Inadequate protection against fire, flood and physical hazards
- strength
- primary
- rationale
- Operating fire detection and suppression directly mitigates the fire hazard to systems that is the core gap this risk names.
- UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards mitigates Loss of essential services (power, HVAC, telecoms)
- strength
- primary
- rationale
- Power conditioning and backup directly sustain systems through power disruption, reducing loss-of-power impact.
- UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards mitigates Inadequate physical protection and access controls
- strength
- primary
- rationale
- Authorizing, badging, logging, monitoring, and revoking physical access is the direct control preventing unauthorized entry to facilities and secure areas.
- UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards mitigates Theft of equipment, media or unattended devices
- strength
- primary
- rationale
- Restricting and revoking physical access keeps unauthorized persons away from equipment and media, directly preventing on-site theft.
- ISO 27001 SoA Review & Controls Assessment oversees UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards
- UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards maps_to SOC1-10 — Physical security and environmental controls — controls provide reasonable assurance that physical access to facilities and data centers is restricted and that environmental protections safeguard systems.
- framework
- soc1
- control_id
- SOC1-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- SSAE 18 (current AICPA SOC suite)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards