PE-5: Access Control for Output Devices

PE-05 requires you to restrict physical access to system output devices so that only authorized personnel can view, retrieve, or handle the

Quick-reference card

FieldValue
Control IDPE-05
Control nameAccess Control for Output Devices
FrameworkNIST SP 800-53 Revision 5
Control familyPhysical and Environmental Protection (PE)
BaselinesMODERATE HIGH
RelevanceOrganization (First Party and Third Party)
Risk severityMedium

What this control requires

PE-05 requires you to restrict physical access to system output devices so that only authorized personnel can view, retrieve, or handle the information they produce. This means printers, monitors, scanners, copiers, fax machines, and audio devices must be placed in locations where unauthorized individuals can’t walk up and grab sensitive output.

In practice, this goes beyond locking a printer room. You need a layered approach that accounts for where output devices sit, who can reach them, and how displayed information is protected during active use. Screen filters on monitors in shared workspaces, badge-controlled access to printer rooms, and headphone policies for audio playback in open offices all fall under PE-05’s scope.

The control applies at the organizational level within the Physical and Environmental Protection family, meaning your physical security program must define and enforce these protections consistently across every facility where systems operate. Without a deliberate placement strategy and access enforcement mechanism, sensitive data ends up on printer trays, visible on unattended screens, or overheard through speakers in common areas.

Why it matters

Uncontrolled output devices are one of the most overlooked exposure points in physical security programs. Auditors routinely flag PE-05 gaps under NIST SP 800-53 assessments because organizations treat printers and monitors as furniture rather than data egress points. Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings during a MODERATE or HIGH baseline assessment.

Where this breaks down most often is in shared office environments and multi-tenant buildings. A printer in an open hallway, a monitor facing a window, or a scanner in an unlocked conference room creates a passive data leak that doesn’t require any technical sophistication to exploit.

Specifically, when PE-05 protections are absent, the following attack vectors become available to anyone with physical proximity:

  • Uncollected print jobs sitting in output trays for minutes or hours, exposing financial reports, employee records, or security configurations
  • Shoulder surfing on monitors in open floor plans, reception areas, or shared workspaces where screen content is visible to visitors and unauthorized staff
  • Unattended copiers and scanners retaining images of sensitive documents on internal storage or in scan-to-email queues
  • Audio output from speakers in open environments broadcasting conference calls, voicemails, or system alerts containing sensitive information
  • Dumpster diving adjacent to printers where failed prints or test pages containing sensitive data are discarded without shredding

The result is that organizations without PE-05 controls face compounding risk across compliance audits, insider threat exposure, and regulatory scrutiny, particularly in industries handling protected health information, financial records, or personally identifiable information.

How to implement

Most PE-05 failures stem from a disconnect between IT asset management and physical security planning. Output devices get deployed based on convenience, not risk, and physical access controls are retrofitted only after an audit finding.

For your organization

Start by building a complete inventory of every output device connected to your systems. This includes printers, copiers, scanners, fax machines, monitors in shared or public-facing areas, and any audio output devices used for system communications.

Once you have your inventory, classify each device by the sensitivity of the data it handles. A printer that only produces non-sensitive marketing materials presents a different risk profile than one connected to your HR or finance systems. This classification drives the level of physical protection required.

For printers, copiers, and scanners, the most effective approach is placement in dedicated rooms with badge-reader or keypad access. Implement pull-printing (also called secure print release), which holds jobs in a queue until the authorized user authenticates at the device. This eliminates the uncollected-output problem entirely.

For monitors, install privacy screen filters on any display in a shared workspace, open floor plan, or area accessible to visitors. Position monitors so screens face away from windows, walkways, and reception areas. In high-security environments, restrict audio output to headphones only.

Produce the following evidence as part of your implementation:

  • A documented policy covering physical access requirements for each category of output device
  • Facility floor plans annotating device placement and associated access controls
  • Access logs for secured rooms containing output devices
  • Configuration records showing pull-printing or secure release is enabled

Common mistakes include treating PE-05 as a one-time facility setup rather than an ongoing program. Device locations change, new printers get added, and office layouts shift. Build a periodic review cycle into your physical security program to revalidate device placement and access controls at least annually.

For your vendors

When assessing vendors against PE-05, your goal is to verify that their physical security program addresses output devices specifically, not just general facility access. Many vendors claim PE-03 physical access controls cover output devices by default, but PE-05 requires targeted protections beyond perimeter badge access.

Request the following evidence during your assessment:

  • The vendor’s physical and environmental protection policy, specifically the sections addressing output device placement and access
  • A facility layout or floor plan showing where output devices that handle your data are located
  • Access control logs for rooms containing printers, copiers, or scanners that process sensitive information
  • Documentation of secure print release or pull-printing configurations

Ask these direct questions in your vendor security questionnaire:

  1. Where are printers, copiers, and scanners that process customer data physically located?
  2. What access controls restrict who can retrieve output from these devices?
  3. Do you use pull-printing or secure print release for sensitive print jobs?
  4. How do you prevent unauthorized viewing of monitor displays in shared or visitor-accessible areas?

Red flags to watch for include vendors who can’t distinguish between general facility access controls and device-specific output controls. If a vendor’s answer to every PE-05 question is “we have badge access to the building,” they haven’t implemented this control at a device level. Similarly, be wary of vendors who claim all work is digital and no output devices exist. Scanners, monitors, and audio devices still qualify even in paperless environments.

Verify claims beyond self-attestation by requesting photos of device placement, sample access logs, or third-party audit reports (such as a SOC 2 Type II) that specifically reference physical access controls for output devices.

Evidence examples

Evidence TypeExample Artifact
Policy documentationPhysical and environmental protection policy defining access requirements for printers, copiers, scanners, monitors, and audio devices, including placement criteria and authorized access roles
Facility layoutAnnotated floor plans showing the location of each output device relative to access-controlled zones, visitor areas, and building entry points
Device inventoryList of all output devices processing sensitive information, mapped to the systems they serve, data classification level, and assigned access control method
Access control recordsBadge reader or keypad access logs for secured rooms containing printers, copiers, or scanners, showing entry timestamps and personnel identifiers
Display protection documentationRecords of privacy screen filter deployment on monitors in shared workspaces, including the device locations and filter specifications
System security planRelevant sections of the system security plan describing how PE-05 is implemented, the scope of devices covered, and the review cadence

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20227.2 Physical entry controlsPartial
ISO 27001:20227.3 Securing offices, rooms and facilitiesPartial
ISO 27001:20227.7 Clear desk and clear screenPartial
NIST SP 800-171 Rev 303.10.07 Physical Access ControlPartial
  • PE-02 — Physical Access Authorizations: defines who is authorized to access the physical spaces where output devices are located, providing the authorization basis PE-05 enforces at the device level
  • PE-03 — Physical Access Control: establishes the facility-level access controls that PE-05 extends to specific output device locations within the facility
  • PE-04 — Access Control for Transmission: protects data in transit over physical transmission lines, complementing PE-05’s protection of data at the point of output
  • PE-18 — Location of System Components: governs the physical placement of system components for security purposes, directly informing where output devices should be positioned under PE-05

Frequently asked questions

What is NIST SP 800-53 PE-05

PE-05 is the NIST SP 800-53 control that requires organizations to restrict physical access to output devices, including printers, monitors, copiers, scanners, and audio devices, so only authorized individuals can view or retrieve sensitive information. It applies to MODERATE and HIGH baselines and addresses the risk of unauthorized data exposure through unprotected output channels.

What happens if PE-05 is not implemented

Without PE-05 controls, sensitive information displayed on monitors or produced by printers and copiers is accessible to anyone with physical proximity, including visitors, cleaning staff, and unauthorized employees. Auditors evaluating your environment against MODERATE or HIGH baselines will flag missing output device protections as a control deficiency. Repeated findings can delay or block authorization to operate and trigger corrective action plans that consume significant resources.

How do you audit PE-05

Auditing PE-05 starts with verifying that the organization maintains an inventory of output devices and has documented access control requirements for each device category. Assessors then inspect facility floor plans against actual device placement, review access logs for secured printer and copier rooms, and confirm that privacy screen filters are deployed on monitors in shared areas. Pull-printing configurations should be validated by testing whether a print job can be released without user authentication at the device.

What are examples of output devices that need physical access controls

Output devices under PE-05 include any hardware that renders, displays, or reproduces system information in a human-readable or audible form. Printers, copiers, scanners, and fax machines are the most common targets, but monitors in open workspaces, digital signage displaying system data, and speakers or audio devices used for conference calls or system alerts also require protection. Even devices in nominally paperless environments, such as large-format displays in operations centers, fall within scope if they present sensitive information.

Experience superior visibility and a simpler approach to cyber risk management