PE-3: Physical Access Control

PE-03 requires your organization to verify every person's authorization before granting physical entry to facilities and systems, then log

Quick-reference card

FieldValue
Control IDPE-03
Control NamePhysical Access Control
FrameworkNIST SP 800-53 Revision 5
Control FamilyPhysical and Environmental Protection
BaselinesLOW MODERATE HIGH
RelevanceFirst Party and Third Party
Risk SeverityHigh

What this control requires

PE-03 requires your organization to verify every person’s authorization before granting physical entry to facilities and systems, then log that access at every entry and exit point. The control spans six operational demands: enforcing access authorizations at defined perimeters, maintaining audit logs, controlling publicly accessible areas, escorting visitors, securing physical access devices like keys and badge readers, and rotating combinations and credentials on a defined schedule.

In practice, this means you need more than a locked door and a sign-in sheet. Your facility must have defined entry and exit points where authorization is checked before anyone crosses the threshold, whether through biometric readers, card access systems, or stationed guards. Visitor activity must be monitored and escorted, not just logged at reception and forgotten. Every key, combination, lock code, and access control device must be inventoried, stored securely, and changed at a frequency you define in policy, and immediately when personnel with access are transferred or terminated.

The control also requires you to account for publicly accessible areas within your facilities. Lobbies, retail floors, shared conference spaces, and any area where unauthorized individuals could reach sensitive infrastructure need defined safeguards. The distinction matters because attackers don’t always break in through back doors. They walk through the front.

Why it matters

Physical access failures don’t generate the same headlines as software exploits, but they produce some of the most operationally damaging breaches in practice. When an attacker gains physical access to hardware, they bypass every logical control you’ve built, from encryption to network segmentation. PE-03 exists because the gap between “someone unauthorized entered a facility” and “data was exfiltrated” is often measured in minutes, not months.

The risk is not limited to server rooms. Anywhere your organization processes, stores, or transmits sensitive data through physical devices, a PE-03 failure can cascade into a full compromise. Retail checkout lanes, warehouse shipping stations, badge-printing rooms, and even janitorial closets housing network switches all fall within scope.

Barnes and Noble PIN Pad Tampering

In September 2012, criminals physically tampered with PIN pad devices at 63 Barnes and Noble store locations across nine states. The attackers opened Verifone terminal housings and installed hardware skimmers capable of capturing payment card numbers and PINs at the moment of transaction, without leaving any externally visible sign of modification. Barnes and Noble discovered the compromise on September 14, 2012, during a routine device sweep and immediately shut down PIN pad processing across all of its approximately 700 U.S. locations while federal authorities investigated.

The company publicly disclosed the incident in October 2012 and acknowledged it did not know when the devices had been tampered with or how long the compromised pads had been in operation before discovery. The perpetrators were never publicly identified. A single tampered device per store, across 63 locations, in a coordinated multi-state campaign illustrates how retail checkout areas require the same physical access scrutiny that PE-03 applies to server rooms and data centers (BusinessWire). Dark Reading also reported on the coordinated skimming campaign across multiple states.

The failure was the absence of tamper-evident measures on payment devices, insufficient monitoring of the physical spaces where those devices operated, and no inspection cadence that would have caught hardware modification before payment data had been captured. A defense in depth approach that extended physical controls to endpoint devices would have reduced the window of exposure.

What attackers exploit:

  • Unmonitored entry and exit points where physical access devices can be reached without detection
  • Absence of tamper-evident seals or inspection cadences on devices processing sensitive data
  • Visitor and contractor access that goes unescorted through areas housing critical infrastructure
  • Physical access devices, such as keys and badge cards, that are not inventoried or rotated on schedule
  • Publicly accessible areas with no defined boundary separating them from restricted zones

How to implement

Implementing PE-03 across both your own facilities and your vendor ecosystem requires you to define what “authorized access” means at every physical boundary, then prove it with evidence that auditors can verify.

For your organization

Start by identifying every physical entry and exit point in your facilities where systems or sensitive data reside. This includes building perimeters, server rooms, wiring closets, storage areas for backup media, and any space where physical access devices like badge readers or biometric scanners are installed.

For each entry and exit point, define and document the authorization mechanism. Card readers, biometric systems, cipher locks, and security guards are all acceptable under PE-03, but your system security plan must specify which mechanism is used where and why. The authorization check must happen before access is granted, not after.

Deploy physical access audit logging at every controlled point. Automated systems, such as badge readers with timestamps, are preferable because they produce consistent, tamper-resistant records. If you rely on manual sign-in logs, define who reviews them, how often, and what constitutes an anomaly worth investigating.

Build a visitor management process that covers escort requirements, activity monitoring, and badge return. Visitors should never have unescorted access to areas containing systems or physical access devices. Your process must define who is authorized to escort, how visitor badges are visually distinguishable from employee badges, and what happens when a visitor deviates from their approved area.

Inventory all physical access devices, including keys, access cards, PIN pads, lock combinations, and biometric enrollment records. Define a rotation schedule for combinations and keys in your policy. Change them immediately when an employee with access is transferred, terminated, or when a compromise is suspected.

Common mistakes include treating PE-03 as a “server room only” control. The scope extends to every area where physical and environmental protection matters, including publicly accessible areas that border restricted zones. Another frequent gap is maintaining access logs without ever reviewing them, which satisfies the letter of the requirement but not the intent.

For your vendors

When assessing a vendor’s PE-03 posture, your security questionnaire should ask specific questions about the physical boundaries they maintain around systems processing your data. Ask how entry and exit points are controlled, what access logging is in place, how visitors are managed, and what the key and combination rotation policy requires. A physical and data center security questionnaire template can help standardize these questions across your vendor portfolio.

Request evidence beyond self-attestation. Useful artifacts include physical access audit logs covering the most recent review period, a copy of the physical access control policy, the device inventory for physical access mechanisms, and documentation of the most recent combination or key change. If the vendor operates a data center, ask for the SOC 2 Type II report and review the PE-03-relevant testing procedures and results.

Red flags to watch for include vendors who cannot produce access logs for specific time ranges, who have no documented visitor escort policy, or who store physical access devices in unsecured locations. If a vendor says “we use a managed colocation facility,” ask for the colocation provider’s name and request evidence that the provider’s physical controls satisfy PE-03, because outsourcing the data center does not outsource the compliance obligation.

Verify claims where possible. If you conduct on-site assessments, check whether badge readers are operational, whether access logs match the vendor’s stated review cadence, and whether visitor badges are visually distinct and tracked. Remote verification options include requesting timestamped photos of controlled entry points or third-party audit reports covering physical security controls.

Evidence examples

Evidence TypeExample Artifact
Policy and proceduresPhysical and environmental protection policy defining access authorization requirements, entry and exit points, visitor management, and key rotation cadence
Access control logsAutomated badge reader logs or manual sign-in records showing date, time, individual, and authorization status for each facility entry and exit
Device inventoryCurrent inventory of physical access devices, such as keys, access cards, cipher locks, biometric readers, and PIN pads, with assigned custodians and last-verified dates
Visitor management recordsVisitor sign-in and escort logs documenting escort assignment, areas accessed, badge issuance, and badge return
Key and combination change recordsDocumentation of combination and key changes showing dates, triggering events (for example, personnel transfer or termination), and responsible personnel
Publicly accessible area safeguardsList of publicly accessible areas with defined security safeguards, boundary markers, and monitoring mechanisms in place
System security planSystem security plan sections addressing PE-03 implementation, including defined entry and exit points, authorization mechanisms, and audit log review frequency

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20227.1 Physical security perimetersPartial
ISO 27001:20227.2 Physical entryPartial
ISO 27001:20227.3 Securing offices, rooms and facilitiesPartial
ISO 27001:20227.4 Physical security monitoringPartial
NIST SP 800-171 Rev 303.10.07 Physical Access ControlPartial
  • AT-03 — Role-based Training: Ensures personnel responsible for physical access enforcement receive training specific to their duties
  • AU-02 — Event Logging: Specifies which physical access events must be captured in organizational audit logs
  • AU-06 — Audit Record Review, Analysis, and Reporting: Governs how physical access audit logs are reviewed for anomalies and policy violations
  • AU-09 — Protection of Audit Information: Protects physical access logs from unauthorized modification or deletion
  • AU-13 — Monitoring for Information Disclosure: Extends monitoring to detect unauthorized physical disclosure of information
  • CP-10 — System Recovery and Reconstitution: Addresses recovery when physical access failures contribute to system disruption
  • IA-03 — Device Identification and Authentication: Authenticates devices at physical access points before granting network connectivity
  • IA-08 — Identification and Authentication (Non-organizational Users): Applies authentication requirements to visitors and external personnel at physical boundaries
  • MA-05 — Maintenance Personnel: Controls physical access for maintenance workers who require temporary entry to restricted areas
  • MP-02 — Media Access: Restricts physical access to digital and non-digital media stored within controlled areas

Frequently asked questions

What is NIST SP 800-53 PE-03

PE-03 is the NIST SP 800-53 physical access control that requires organizations to enforce access authorizations at facility entry and exit points, maintain audit logs, escort visitors, secure keys and combinations, and inventory all physical access devices on a defined schedule. It applies across LOW, MODERATE, and HIGH baselines, making it a baseline requirement for every federal information system and any organization aligning to the framework.

What happens if PE-03 is not implemented

Without PE-03, unauthorized individuals can enter facilities and access systems, storage areas, or endpoint devices without detection. The Barnes and Noble PIN pad tampering incident demonstrated how the absence of tamper-evident controls and device inspection cadences allowed hardware skimmers to operate undetected across 63 store locations. Uncontrolled physical access also undermines logical controls, because an attacker with physical access to a server or network switch can bypass encryption, exfiltrate data, or install persistent backdoors.

How do you audit PE-03

Auditing PE-03 starts with verifying that physical access audit logs exist for every defined entry and exit point and that those logs are reviewed at the cadence specified in the organization’s physical and environmental protection policy. Auditors should confirm that visitor escort records match the organization’s stated procedures, that the physical access device inventory is current and accounts for all keys, badges, and biometric enrollment records, and that combination and key change records show rotation at the defined frequency. Testing should also verify that publicly accessible areas have documented safeguards separating them from restricted zones.

What are examples of physical access controls under NIST 800-53

Physical access controls under PE-03 include badge readers and card access systems at entry and exit points, biometric scanners for high-security areas, cipher locks on server rooms and wiring closets, security guards who verify authorization before granting entry, and tamper-evident seals on devices like PIN pads and network equipment. Supporting controls include visitor escort procedures, key and combination management processes, and automated audit logging systems that record every access attempt with timestamps and individual identification.

Experience superior visibility and a simpler approach to cyber risk management