Quick-reference card
| Field | Value |
|---|---|
| Control ID | PE-16 |
| Control Name | Delivery and Removal |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Physical and Environmental Protection |
| Baselines | LOW MODERATE HIGH |
| Relevance | Organization (First Party and Third Party) |
| Risk Severity | Medium |
What this control requires
PE-16 requires organizations to authorize and track every system component that enters or leaves a facility. If a server, laptop, hard drive, or networking device crosses the physical perimeter without documented approval and logging, your organization has a gap that auditors will flag and attackers can exploit.
In practice, this means maintaining a formal authorization process for both inbound deliveries and outbound removals of hardware and media. You need to verify that incoming components match approved purchase orders or transfer requests, and you need to confirm that outgoing items have been sanitized or decommissioned according to your physical and environmental protection policy. Without these checks, your component inventory drifts out of sync with reality, creating blind spots in your configuration management posture.
Beyond authorization, PE-16 demands that you maintain records of every component movement. These records must be detailed enough to reconstruct a chain of custody for any device at any point in time. That level of traceability ties directly into asset lifecycle management and supports related controls governing maintenance, media transport, and supply chain integrity.
Why it matters
Organizations that lack delivery and removal controls face direct audit risk across all three NIST SP 800-53 baselines. Because PE-16 is required at the LOW baseline, there is no exclusion argument available. Failure to maintain this control introduces audit findings and may result in certification withdrawal, loss of authorization to operate (ATO), or regulatory penalties.
The risk extends beyond compliance paperwork. Without a record of what enters and exits your facilities, your system component inventory cannot be trusted. An unreliable inventory undermines every downstream control that depends on knowing what hardware exists in your environment, from vulnerability scanning to incident response.
Where this breaks down most often is at scale. Organizations with multiple facilities, shared loading docks, or high-volume hardware refresh cycles frequently discover that informal delivery processes have replaced the formal authorization workflows documented in their security plans. Auditors test for exactly this gap by sampling recent shipment records against the component inventory.
Specifically, when delivery areas are not physically isolated from production environments, the risk escalates from a documentation gap to a live threat vector. Unvetted hardware can be connected to internal networks before security teams even know it arrived.
What attackers exploit:
- Unauthorized hardware insertion, where rogue devices such as network implants or keyloggers are introduced through unmonitored delivery channels
- Stolen or diverted components during removal, enabling data exfiltration through physical media that was never logged as leaving the facility
- Supply chain tampering, where legitimate shipments are intercepted and modified with compromised firmware or hardware implants before delivery
- Social engineering of delivery staff, using fake work orders or impersonation to bypass facility access controls at loading docks
- Untracked media removal, where drives or backup tapes containing sensitive data leave the facility without sanitization records
How to implement
Most PE-16 failures stem from the same root cause: organizations write a delivery and removal policy but never operationalize it with repeatable workflows, designated personnel, and auditable records. The gap between policy and practice is where both auditors and threat actors find opportunity.
For your organization
Start by defining which system components fall under PE-16 scope. This includes servers, workstations, laptops, mobile devices, networking equipment, removable media, and any hardware that processes, stores, or transmits organizational data. Document these categories in your system security plan and reference the applicable NIST SP 800-53 control family requirements.
Designate specific delivery and removal areas within each facility. These areas should be physically separated from server rooms, data centers, and media libraries. Access to delivery areas should be restricted to authorized personnel, and security cameras or access logs should cover these zones continuously.
Implement a formal authorization workflow for inbound shipments. Every delivery should be matched against a pre-approved purchase order or transfer request before components are accepted. Receiving staff should verify item serial numbers, model numbers, and quantities against the shipping manifest. Discrepancies trigger a hold-and-escalate process rather than ad hoc acceptance.
For outbound removals, require a signed removal authorization form that specifies the component, the reason for removal, the destination, and confirmation that data sanitization procedures have been completed where applicable. Maintain a removal log that captures timestamps, the authorizing official, and the individual physically transporting the component.
Common mistakes include relying on email approvals that are never centralized into an auditable log, allowing IT staff to self-authorize removals without a separation of duties check, and failing to update the asset inventory after components are moved. Avoid these by integrating delivery and removal records with your asset management and configuration management workflows.
For your vendors
When assessing a vendor’s PE-16 compliance, your goal is to verify that they have operationalized delivery and removal controls rather than simply documented a policy. Request specific evidence rather than accepting general attestations.
Ask these questions in your vendor risk assessment or SIG questionnaire:
- Do you maintain a formal authorization process for system components entering and exiting facilities that house customer data?
- How are delivery and staging areas physically separated from production environments?
- What records do you maintain for component deliveries and removals, and how long are those records retained?
- Who is authorized to approve the removal of system components from your facilities, and how is separation of duties enforced?
- How do you verify that components removed from service have been sanitized before leaving the facility?
Request these evidence artifacts: the vendor’s physical and environmental protection policy, a sample of recent delivery and removal logs with authorizations, facility layout documentation showing delivery area isolation, and their system component inventory reconciliation records.
Red flags to watch for include vendors that cannot produce delivery logs for the past 12 months, facilities where delivery areas open directly into server rooms or network closets, removal processes that rely on a single individual’s approval without oversight, and any inability to reconcile their component inventory against recent movement records. These gaps suggest that PE-16 controls exist on paper but are not functioning in practice.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Authorization policy | Physical and environmental protection policy defining which system components require authorization for delivery and removal, including roles and approval thresholds |
| Delivery and removal procedures | Documented workflow specifying steps for receiving, verifying, logging, and releasing system components at each facility |
| Delivery authorization records | Logs linking each inbound shipment to an approved purchase order or transfer request, with receiving staff signatures and timestamps |
| Removal authorization records | Signed removal forms capturing component identifiers, sanitization confirmation, destination, and authorizing official for each outbound transfer |
| Component movement log | Consolidated register of all system components entering and exiting the facility, with serial numbers, dates, and responsible personnel |
| System component inventory | Current inventory cross-referenced against movement logs to confirm that all delivered components are accounted for and all removals are reflected |
| Facility access records | Access logs or camera footage for delivery and staging areas, demonstrating that only authorized personnel handle incoming and outgoing components |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.10 Acceptable use of information and other associated assets | Partial |
| ISO 27001:2022 | 7.10 Storage media | Partial |
| ISO 27001:2022 | 7.2 Physical entry | Partial |
Related controls
- CM-03 – Configuration Change Control: ensures that changes to system components, including those introduced through delivery, follow a formal change management process
- CM-08 – System Component Inventory: maintains the authoritative inventory that delivery and removal records must reconcile against
- MA-02 – Controlled Maintenance: governs maintenance activities that may require components to be delivered to or removed from the facility
- MA-03 – Maintenance Tools: controls which tools are authorized to enter the facility for maintenance purposes, complementing PE-16 delivery authorization
- MP-05 – Media Transport: addresses protections for media in transit, extending PE-16 removal controls beyond the facility perimeter
- PE-20 – Asset Monitoring and Tracking: provides continuous tracking of system components within the facility, supporting the chain of custody PE-16 establishes at entry and exit points
- SR-02 – Supply Chain Risk Management Plan: defines the organizational strategy for managing supply chain risks that PE-16 delivery controls help mitigate at the facility level
- SR-03 – Supply Chain Controls and Processes: operationalizes supply chain protections that intersect with PE-16 when components arrive from external suppliers
- SR-04 – Provenance: tracks the origin and custody history of components, which depends on accurate PE-16 delivery records as the facility-level source of truth
- SR-06 – Supplier Assessments and Reviews: evaluates supplier security practices, including how suppliers handle component delivery and packaging integrity
Frequently asked questions
What is NIST SP 800-53 PE-16?
PE-16 is the NIST SP 800-53 control that requires organizations to authorize and log every system component entering or exiting a facility. It applies at all three baselines (LOW, MODERATE, and HIGH) and covers hardware deliveries, equipment removals, and media transfers. The control ensures that your facility maintains a verifiable chain of custody for physical assets, tying into your system component inventory and configuration management processes.
What happens if PE-16 is not implemented?
Without PE-16 controls, your organization cannot demonstrate that system components entering the facility are authorized or that removed equipment has been properly sanitized. Auditors testing PE-16 will request delivery authorization records and removal logs, and gaps in those records result in findings that can jeopardize your authorization to operate. The downstream impact extends to your component inventory accuracy, because untracked deliveries and removals create discrepancies that undermine vulnerability management and incident response.
How do you audit PE-16?
Auditors assess PE-16 by sampling delivery and removal records against the system component inventory to verify that movements are authorized and logged. They inspect facility layouts to confirm that delivery areas are isolated from production environments and media libraries. The assessment also covers whether the organization retains records of system components with enough detail to reconstruct chain of custody, including serial numbers, authorization signatures, and timestamps for each entry and exit event.
What system components need to be tracked under PE-16?
PE-16 applies to any system component that processes, stores, or transmits organizational information, including servers, workstations, laptops, networking devices, removable storage media, and backup tapes. The scope is defined by the organization in its system security plan and should align with the categories documented in the facility’s physical and environmental protection policy. Components that contain no data but connect to internal networks, such as unmanaged switches or wireless access points, should also be included because they represent potential entry points for unauthorized access.