PE-2: Physical Access Authorizations

PE-02 requires your organization to maintain a current, approved list of every person authorized to physically enter the facility where

Quick-reference card

FieldValue
Control IDPE-02
Control namePhysical Access Authorizations
FrameworkNIST SP 800-53, Revision 5
Control familyPhysical and Environmental Protection
BaselinesLOW MODERATE HIGH
RelevanceOrganization (First Party and Third Party)
Risk severityHIGH

What this control requires

PE-02 requires your organization to maintain a current, approved list of every person authorized to physically enter the facility where your information systems reside. That list isn’t a formality. It’s the single artifact auditors check first when evaluating whether your physical security program has teeth.

In practice, this control demands four linked actions. You must develop and approve the authorized access list, issue credentials that prove authorization (badges, smart cards, or identification cards), review the list on a defined schedule, and remove individuals the moment they no longer need access. Each action feeds the next. A list that isn’t reviewed drifts out of date. Credentials issued without a current list create unauthorized access. Removals that lag behind terminations leave the facility open to insiders who should have been locked out.

The scope covers employees, contractors, and any other individual granted ongoing physical access. Visitors are handled separately under visitor management controls. Publicly accessible areas within a facility don’t require individual authorizations, but you still need to define which areas qualify and document that decision.

Why it matters

Unauthorized physical access is one of the fastest paths to a system compromise, yet it’s routinely deprioritized in favor of network-layer controls. When an auditor finds a stale access list or credentials that haven’t been reviewed in over a year, the resulting finding can jeopardize your entire authorization to operate.

Failure to maintain PE-02 introduces direct audit risk. Assessors treat an outdated access list as evidence that the organization lacks the governance maturity to manage physical security. For organizations pursuing or maintaining a Federal Risk and Authorization Management Program (FedRAMP) authorization, a PE-02 finding can delay or block the process entirely. In regulated industries, gaps in physical entry controls surface during ISO 27001 surveillance audits as well.

The risk isn’t theoretical. Physical access failures cascade into other control areas. A person who shouldn’t be in the building can tamper with hardware, install rogue devices, access unencrypted media, or exfiltrate backup tapes. Every one of those outcomes maps to a separate control failure, compounding the original PE-02 gap into a systemic finding.

What attackers exploit

Threat actors target physical access weaknesses through predictable vectors:

  • Tailgating and piggybacking: following an authorized person through a controlled entry without presenting credentials.
  • Credential cloning: duplicating badge data from proximity cards using commercially available readers.
  • Social engineering at reception: posing as a vendor, delivery driver, or maintenance worker to gain temporary access that converts to persistent presence.
  • Exploiting termination delays: accessing facilities using credentials that should have been revoked after role changes, transfers, or terminations.
  • Targeting unmanned entry points: using secondary doors, loading docks, or emergency exits that lack the same access controls as primary entrances.

How to implement

Most PE-02 failures don’t stem from a missing access list. They come from a list that exists on paper but isn’t connected to the credentialing and review processes that keep it accurate.

For your organization

Start by identifying every physical entry point to the facility or data center where systems reside. Map each entry point to the credential type it accepts (badge reader, biometric scanner, key lock) and the population it serves.

Build the authorized access list as a living document. Include the individual’s name, role, sponsoring manager, access level (which zones or rooms they may enter), credential type issued, and the date access was granted. Store the list in a system that supports version history so you can demonstrate changes over time.

Establish an approval workflow. Every addition to the list should require sign-off from a facility manager or security officer. Don’t let self-service provisioning bypass this step. Physical access management (PAM) platforms or integrated identity governance tools can enforce this workflow electronically.

Define your review cadence and stick to it. Quarterly reviews are common for moderate-impact systems. During each review, validate that every person on the list still needs access, that their role justifies the zones they can reach, and that no terminated or transferred individuals remain. Document the review with a dated signature or electronic approval record.

Removal is where most organizations fail. Tie physical access revocation to your human resources offboarding process. When someone leaves the organization or changes roles, their credentials should be deactivated the same day. Collect physical badges and update the access list within 24 hours. Audit the gap between termination dates and credential deactivation dates at least annually.

Common mistakes to avoid:

  • Maintaining the access list in a spreadsheet disconnected from the credentialing system
  • Reviewing the list on schedule but not actually removing flagged individuals
  • Issuing temporary credentials without expiration dates
  • Failing to include contractor and maintenance personnel on the list

For your vendors

When assessing a vendor’s PE-02 compliance, your goal is to confirm that they maintain an active, reviewed physical access list for facilities that process or store your data.

Request a copy of the vendor’s physical access policy and their most recent access list review record. You don’t need the full list of names. You need evidence that the list exists, that it was reviewed within the defined frequency, and that removals are documented.

Ask these questions in your assessment or questionnaire:

  • Do you maintain a documented list of individuals authorized to access the facility where our data is processed or stored?
  • How frequently is the list reviewed, and who approves additions and removals?
  • What is the process for revoking physical access when an employee or contractor is terminated?
  • Are authorization credentials (badges, smart cards) deactivated on the same day as termination?
  • Can you provide evidence of the most recent access list review, including the date and approver?

Red flags during vendor assessment include access lists that haven’t been reviewed in more than six months, no documented approval workflow for granting access, and a gap of more than 48 hours between personnel departure and credential deactivation. If the vendor can’t produce a dated review record, treat it as a material gap in their physical security perimeter controls.

Verify that the vendor’s approach to visitor access is separate from permanent authorization. Visitor logs and escort requirements fall under PE-08, but vendors sometimes conflate the two, which signals a process maturity issue.

Evidence examples

Evidence typeExample artifact
Physical access policyPhysical and environmental protection policy defining authorization requirements, credential types, and review cadence
Authorized personnel access listCurrent roster of individuals approved for facility access, including name, role, access zones, credential type, and approval date
Authorization credentials inventoryLog of issued badges, smart cards, or identification cards mapped to individuals on the access list
Access list review recordsDated review documentation showing who conducted the review, individuals validated, and any removals or changes made
Access termination recordsRecords of credential deactivation and list removal tied to personnel departures, including deactivation date and badge collection confirmation
System security plan excerptRelevant sections of the system security plan (SSP) describing PE-02 implementation, review frequency, and responsible roles

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20227.2 Physical entryPartial
NIST SP 800-171 Rev 303.10.01 Physical Access AuthorizationsPartial
  • AT-03 — Role-based Training: ensures personnel with physical access responsibilities receive training on authorization procedures and credential management.
  • AU-09 — Protection of Audit Information: protects the integrity of physical access logs and review records from unauthorized modification.
  • IA-04 — Identifier Management: governs the lifecycle of identifiers, including physical credential identifiers tied to badge and smart card systems.
  • MA-05 — Maintenance Personnel: requires authorization and escort procedures for maintenance workers who need facility access but aren’t on the permanent access list.
  • MP-02 — Media Access: restricts physical access to digital and non-digital media, reinforcing the access boundaries PE-02 establishes for facility zones.
  • PE-03 — Physical Access Control: enforces the access decisions PE-02 authorizes, covering the mechanisms (locks, guards, badge readers) that gate entry.
  • PE-04 — Access Control for Transmission: protects physical access to transmission lines and cabling within the facility.
  • PE-05 — Access Control for Output Devices: limits physical access to output devices such as printers and displays in controlled areas.
  • PE-08 — Visitor Access Records: manages the visitor access process that PE-02 explicitly excludes from the permanent authorized access list.
  • PM-12 — Insider Threat Program: connects physical access authorization data to broader insider threat detection and response activities.

Frequently asked questions

What is NIST SP 800-53 PE-02

PE-02 is the NIST SP 800-53 control that requires organizations to develop, approve, and maintain an authorized personnel access list for every facility housing information systems. It applies across LOW, MODERATE, and HIGH baselines and covers credential issuance, periodic list review, and timely removal of individuals who no longer need access. The control targets the governance layer of physical security, not the enforcement mechanisms themselves.

What happens if PE-02 is not implemented

Without PE-02, your organization can’t demonstrate who is authorized to enter the facility, which means every other physical security control lacks a foundation. Auditors treat a missing or stale authorized personnel access list as a high-severity finding because it signals a systemic gap in physical security governance. For federal systems, a PE-02 deficiency can delay authorization decisions and trigger plan-of-action-and-milestones (POA&M) entries that require remediation before the system receives its authority to operate.

How do you audit PE-02

Auditors verify PE-02 by requesting the current authorized personnel access list and checking that it was approved by an appropriate authority. They compare the list against issued authorization credentials (badges, smart cards, identification cards) to confirm one-to-one correspondence. The assessor then reviews dated access list review records to validate that reviews occurred at the defined frequency and that removal actions were completed when individuals no longer required access. Sampling termination records against credential deactivation logs reveals whether revocation happens promptly.

What credentials are used for physical access authorizations

Organizations typically issue identification badges, proximity cards, smart cards, or biometric tokens as authorization credentials under PE-02. The credential type should match the security impact level of the system housed in the facility. Higher-impact environments often combine two credential types, such as a badge reader plus a biometric scanner, to strengthen assurance that the person presenting the credential is the individual on the authorized access list.

Experience superior visibility and a simpler approach to cyber risk management