unified

UC-PHYS-01 — Restrict physical access to facilities and secure areas

Define physical security perimeters and secure areas, and authorize, issue, and periodically review physical access credentials so only authorized personnel can enter facilities, offices, and sensitive locations such as data centers and backup media storage. Enforce entry controls at every access point, escort and log visitors, and apply defined rules for working in secure areas. Maintain physical access audit logs for entries and exits at controlled access points, and secure, inventory, and rotate physical access devices such as keys, combinations, and badges when compromised or when personnel change. Revoke or adjust physical access promptly upon termination or role change.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Physical & Environmental Security
type
preventive
category
physical

Details

unified_id
UC-PHYS-01
title
Restrict physical access to facilities and secure areas
statement
Define physical security perimeters and secure areas, and authorize, issue, and periodically review physical access credentials so only authorized personnel can enter facilities, offices, and sensitive locations such as data centers and backup media storage. Enforce entry controls at every access point, escort and log visitors, and apply defined rules for working in secure areas. Maintain physical access audit logs for entries and exits at controlled access points, and secure, inventory, and rotate physical access devices such as keys, combinations, and badges when compromised or when personnel change. Revoke or adjust physical access promptly upon termination or role change.
domain
Physical & Environmental Security
control_type
preventive
control_category
physical
members
  • framework
    nist-800-53
    control_id
    PE-2
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    PE-3
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.7.1
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.7.2
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.7.3
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.7.6
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC6.4
    coverage
    full
    relationship
    superset_of
  • framework
    hipaa
    control_id
    HIPAA-164.310
    coverage
    partial
    delta
    also covers workstation use/security and device and media controls
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections