{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"physical","domain":"Physical & Environmental Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-PHYS-01","description":"Define physical security perimeters and secure areas, and authorize, issue, and periodically review physical access credentials so only authorized personnel can enter facilities, offices, and sensitive locations such as data centers and backup media storage. Enforce entry controls at every access point, escort and log visitors, and apply defined rules for working in secure areas. Maintain physical access audit logs for entries and exits at controlled access points, and secure, inventory, and rotate physical access devices such as keys, combinations, and badges when compromised or when personnel change. Revoke or adjust physical access promptly upon termination or role change.","details":{"control_category":"physical","control_type":"preventive","domain":"Physical & Environmental Security","guidance":[],"members":[{"control_id":"PE-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PE-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.7.1","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.7.2","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.7.3","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.7.6","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"CC6.4","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"HIPAA-164.310","coverage":"partial","delta":"also covers workstation use/security and device and media controls","framework":"hipaa","relationship":"intersects_with"}],"statement":"Define physical security perimeters and secure areas, and authorize, issue, and periodically review physical access credentials so only authorized personnel can enter facilities, offices, and sensitive locations such as data centers and backup media storage. Enforce entry controls at every access point, escort and log visitors, and apply defined rules for working in secure areas. Maintain physical access audit logs for entries and exits at controlled access points, and secure, inventory, and rotate physical access devices such as keys, combinations, and badges when compromised or when personnel change. Revoke or adjust physical access promptly upon termination or role change.","title":"Restrict physical access to facilities and secure areas","unified_id":"UC-PHYS-01"},"id":"uc:UC-PHYS-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-PHYS-01","sourceIds":["hipaa","iso-27001","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-PHYS-01 — Restrict physical access to facilities and secure areas","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0c6ef72ce50fea52ce2bb9889053328161ea0284d14ed9a7df0c1a16329cdfcf","properties":{"control_id":"CC6.4","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-4-4132a487.json","targetId":"ctrl:soc2:CC6.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:169d6622df6fde59aa992aa7416fb7c99cae450e0c56b5f5b5e87dc64e061da5","properties":{"control_id":"A.7.6","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-6-3e5f12bc.json","targetId":"ctrl:iso-27001:A.7.6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1947576f7898c588cd74ad7b09c7ddef68c76529f12d25c8ccb61bb1489c4e11","properties":{"rationale":"Perimeters, entry controls, credential issuance/review, and visitor escort are the direct defense against unauthorized physical access, including tailgating.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/risk-phys-inadequate-facility-access-a83f3330.json","targetId":"risk:phys-inadequate-facility-access","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1f351b41c6da0c2df1781cfe55b9bd525fa4f987dd6f2432800908487b9d0e8e","properties":{"control_id":"A.7.1","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-1-a327b00e.json","targetId":"ctrl:iso-27001:A.7.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:27c8f3cb070c242662d115aac643c19e0d4f2446ffecec620cbb6d7ede1a2df6","properties":{"rationale":"Restricting entry to facilities and secure areas keeps intruders from reaching interior systems/infrastructure to commit arson or sabotage.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/risk-phys-cyber-physical-facility-attack-e372d06e.json","targetId":"risk:phys-cyber-physical-facility-attack","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2cd6f1b3485b3327ece932dba25882d0c9b671862b3aa9ad17c09af785855ab7","properties":{"control_id":"PE-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pe-3-ac338517.json","targetId":"ctrl:nist-800-53:PE-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3d98b4abe6c39fa772795e80b6a106f0aa6e8acd9592c40b0695fa3ebd335dbb","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","targetId":"uc:UC-PHYS-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:44cc4186b5c1bb4eff60a99d8daf742e4590cc9298b27c249ab8845d231946b4","properties":{"control_id":"A.7.3","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-3-1b2f4ae0.json","targetId":"ctrl:iso-27001:A.7.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4a37ef9deda61ab82c74635517e8f39a95709c839376cbad0a7ebc8d666ef8c9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c7-acbef2ee.json","sourceId":"wf:C7","targetDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","targetId":"uc:UC-PHYS-01","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:51eb1aaf372e56e178e80a1502ebfcf0f2725d63b17c3f28280480fc3cce7f20","properties":{"control_id":"A.7.2","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-2-7f774ee6.json","targetId":"ctrl:iso-27001:A.7.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7600e8066bd80f681f6cdd1adaff667045e6a5a0ff9a75dcdce290af53c5d65d","properties":{"control_id":"HIPAA-164.310","coverage":"partial","delta":"also covers workstation use/security and device and media controls","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-310-9cf84fad.json","targetId":"ctrl:hipaa:HIPAA-164.310","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:90db391e8ba43a89198a45557a7d274fa701140d84bca7394d62d39372d00d43","properties":{},"sourceDetailPath":"/data/v1/records/wf-c35-f84d44e2.json","sourceId":"wf:C35","targetDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","targetId":"uc:UC-PHYS-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a61c7d44753c01400efc9a449a0fff16ab6cb8f5767b3f2355ed9aa905178fe0","properties":{"control_id":"PE-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pe-2-63072cc2.json","targetId":"ctrl:nist-800-53:PE-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b450fb313c85d2f7ed9314516ca62e751231f672d97265d76d897ec912ab5b3c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","targetId":"uc:UC-PHYS-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ef0c725c40dd91eb262848db649a395c5d8f3ffee63175dff3dccc15e08380b1","properties":{"rationale":"Controlling and promptly revoking physical access prevents unauthorized persons from reaching and removing equipment or media.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/risk-phys-theft-of-equipment-media-c64433e7.json","targetId":"risk:phys-theft-of-equipment-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f6f27d8142db5e0f438a3546d99d65c57adb036cf28d13ff93ea629b333fc8f2","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","targetId":"uc:UC-PHYS-01","type":"tests"}],"schemaVersion":1}
