Quick-reference card
| Field | Value |
|---|---|
| Control ID | PE-20 |
| Control name | Asset Monitoring and Tracking |
| Framework | NIST SP 800-53 Revision 5 |
| Control family | Physical and Environmental Protection |
| Baselines | Not assigned to any baseline |
| Implementation level | Organization |
| Relevance | First Party and Third Party |
| Risk severity | Medium |
What this control requires
PE-20 requires organizations to deploy asset location technologies that track and monitor physical assets across all controlled areas. That includes devices, equipment, vehicles, and system components that support critical operations. The goal isn’t just knowing what you own. It’s knowing where it is at any point in time.
In practice, this means maintaining continuous visibility into the physical location and movement of assets within facilities, data centers, warehouses, and other defined perimeters. Organizations must define which assets require tracking, designate the controlled areas where monitoring applies, and select location technologies that match the sensitivity and mobility of those assets.
PE-20 also carries an explicit privacy dimension that most teams overlook. The official NIST guidance calls out the need to consult legal counsel and the senior agency official for privacy before deploying location technologies. Asset tracking systems that monitor movement patterns can intersect with employee privacy protections, making this control one of the few in the physical and environmental protection (PE) family where privacy review is a compliance prerequisite, not just a best practice.
Why it matters
Most organizations treat asset tracking as a logistics problem rather than a security control. That gap creates real compliance exposure during audits. When assessors ask for evidence that you know where your critical assets are, a spreadsheet updated quarterly doesn’t satisfy PE-20’s requirement for continuous, technology-enabled monitoring.
Failure to maintain this control introduces audit risk in several ways. Federal agencies and contractors operating under NIST SP 800-53 face findings when they can’t demonstrate that asset location technologies are actually deployed and producing tracking records. For organizations subject to FedRAMP or similar authorization frameworks, unaddressed PE controls can delay or block authorization decisions entirely.
The risk extends beyond audit findings. Without reliable asset location data, organizations can’t detect unauthorized removal of equipment, can’t verify that decommissioned hardware actually left the facility through approved channels, and can’t confirm that sensitive assets haven’t been moved to unsecured areas. These aren’t theoretical concerns. They’re the conditions that make physical attack surface compromise possible.
Where this breaks down most often is at the boundary between physical security and IT asset management. Teams responsible for physical access controls rarely coordinate with the teams maintaining system component inventories, which means movement of assets between zones goes unrecorded.
The vectors that attackers and insider threats exploit when PE-20 controls are weak:
- Unauthorized equipment removal where laptops, servers, or storage media leave controlled areas without detection or logging
- Rogue device introduction where unauthorized hardware enters a facility and connects to internal networks because no movement monitoring exists to flag the anomaly
- Asset swaps during maintenance where components are replaced with compromised hardware during routine servicing, and the substitution goes undetected
- Decommissioning gaps where assets marked for destruction or secure disposal are diverted before reaching the destruction facility
- Shadow inventory drift where assets move between buildings, floors, or cages without updating any tracking system, creating blind spots in both physical security and configuration management
How to implement
The most common failure mode with PE-20 isn’t choosing the wrong technology. It’s deploying tracking for the wrong scope of assets or failing to define what “controlled area” actually means in your environment. Start with those definitions before selecting tools.
For your organization
Begin by establishing which assets require location tracking. Not every piece of equipment needs an RFID tag. PE-20 targets assets whose unauthorized movement or loss would affect operations or security posture. Servers, network infrastructure, portable storage media, and mission-critical equipment are the priority categories.
Define your controlled areas explicitly. A controlled area is any space where you maintain physical access controls and expect assets to remain unless formally transferred. This includes data centers, server rooms, secure storage, and equipment staging areas. Document the boundaries so that tracking systems can distinguish between authorized movement within a zone and unauthorized movement across zones.
Select asset location technologies that match the mobility and sensitivity profile of each asset class. Radio-frequency identification (RFID) works well for high-volume, stationary or semi-stationary assets within a facility. GPS tracking applies to vehicles and equipment that move between sites. Bluetooth low energy (BLE) beacons offer room-level granularity for indoor environments. Barcode or QR-based systems provide a lower-cost option for periodic inventory verification, though they don’t deliver the continuous monitoring PE-20 envisions.
Integrate tracking data with your asset inventory processes. Location records should feed into or reconcile against your system component inventory required by CM-08. When an asset’s tracked location doesn’t match its recorded assignment, that discrepancy should trigger an investigation workflow.
Address the privacy review requirement early. Before deploying any location technology that could track personnel movement patterns, engage your legal counsel and privacy office. Document the consultation and any resulting constraints on data collection, retention, or access. This step is a PE-20 requirement, not optional due diligence.
Finally, establish monitoring and alerting procedures. Tracking technology that generates data nobody reviews doesn’t satisfy the control. Define thresholds for alerts, such as an asset leaving a controlled area outside of approved transfer windows, and assign responsibility for investigating those alerts.
For your vendors
When assessing a vendor’s PE-20 posture, the goal is to determine whether they have technology-enabled visibility into where critical assets are, not just whether they maintain an asset list.
Request documentation of the vendor’s asset tracking program. This should include a policy that defines which asset categories are subject to location monitoring, which controlled areas are in scope, and what technologies are deployed. A vendor that can only produce a static inventory spreadsheet hasn’t implemented PE-20.
Ask for evidence of the specific location technologies in use. Acceptable evidence includes system configuration documentation for RFID, GPS, or BLE tracking platforms, along with sample tracking records showing asset location data over time. The records should demonstrate continuous or near-continuous monitoring, not just periodic manual scans.
Verify that the vendor’s tracking scope covers the assets relevant to your engagement. If you’ve entrusted hardware, data, or system components to the vendor, those specific assets should fall within their PE-20 monitoring boundary. Ask which of your assets are tracked and within which controlled areas.
Review the vendor’s procedures for handling tracking anomalies. When an asset appears outside its authorized location or goes missing from tracking, the vendor should have a documented investigation and escalation process. Request sample records of past anomaly investigations to confirm the process is active, not just documented.
Evaluate privacy compliance as well. Vendors deploying location technologies should be able to demonstrate that they’ve conducted the required privacy review, particularly if the tracking systems operate in spaces shared with personnel. This is a direct PE-20 compliance requirement and a red flag if absent.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Physical and environmental protection policy | Policy document defining asset categories subject to location monitoring and designated controlled areas |
| Asset tracking procedures | Documented procedures for deploying, maintaining, and responding to alerts from asset location technologies |
| Asset inventory with tracking requirements | List of organizational assets requiring monitoring, including asset classification, assigned controlled area, and tracking technology type |
| System configuration documentation | Configuration records for RFID, GPS, or BLE asset tracking platforms showing monitored zones and alert thresholds |
| Asset monitoring and tracking records | Logs from location tracking systems showing asset position data, movement events, and anomaly alerts over a defined period |
| Privacy review documentation | Records of consultation with legal counsel and the senior agency official for privacy regarding asset location technology deployment |
| System security plan and privacy plan | Sections of the SSP and privacy plan that describe the PE-20 implementation, technology selection rationale, and privacy safeguards |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.10 Acceptable use of information and other associated assets | Partial |
Related controls
Other controls in the PE family and related families that interact with PE-20:
- CM-08 — System Component Inventory: PE-20 tracking data should reconcile against the component inventory CM-08 requires, creating a feedback loop between physical location and logical asset records
- PE-16 — Delivery and Removal: PE-16 governs the authorization and documentation of assets entering or leaving a facility, while PE-20 provides the ongoing monitoring that verifies those delivery and removal records remain accurate
- PM-08 — Critical Infrastructure Plan: PE-20’s asset tracking supports PM-08 by ensuring that critical infrastructure components are accounted for and locatable as part of continuity and protection planning
Frequently asked questions
What is NIST SP 800-53 PE-20
PE-20 is the NIST SP 800-53 control that requires organizations to use asset location technologies to track and monitor the movement of physical assets within controlled areas. It applies to equipment, vehicles, system components, and other assets whose unauthorized movement or loss could affect security or operations. PE-20 also requires organizations to address privacy implications of deploying location tracking technologies by consulting legal counsel before implementation.
What happens if PE-20 is not implemented
Without PE-20, organizations lose visibility into where critical physical assets are located at any given time, creating gaps that auditors will flag during assessments. Unauthorized removal of equipment, rogue device introduction, and decommissioning failures all become harder to detect and investigate. For federal agencies and contractors, a missing PE-20 implementation can contribute to findings that delay system authorizations and weaken the overall authorization package.
How do you audit PE-20
Auditing PE-20 starts with verifying that asset location technologies are deployed and actively monitoring the assets and controlled areas defined in the organization’s scope. Assessors review tracking system configuration, sample monitoring logs, alert investigation records, and the documented list of assets requiring tracking. They also verify that the organization completed the required privacy consultation before deploying location technologies. The key test is whether the tracking system produces continuous location data that the organization actually reviews and acts on, not just whether the technology exists.
What technologies are used for asset monitoring and tracking under NIST 800-53
NIST SP 800-53 doesn’t prescribe specific technologies for PE-20, but common implementations include RFID tags and readers for facility-level tracking, GPS modules for mobile assets and vehicles, and BLE beacons for room-level indoor positioning. Some organizations use barcode or QR-based systems for periodic inventory verification, though these don’t deliver the continuous monitoring PE-20 envisions. The right technology depends on asset mobility, facility layout, and the granularity of location data the organization needs to satisfy its defined controlled-area boundaries.