PE-6: Monitoring Physical Access

PE-06 requires organizations to monitor physical access to facilities housing information systems, review access logs, and coordinate

Quick-reference card

FieldValue
Control IDPE-06
Control NameMonitoring Physical Access
FrameworkNIST SP 800-53, Revision 5
Control FamilyPhysical and Environmental Protection
BaselinesLOW MODERATE HIGH
RelevanceFirst Party and Third Party
Risk SeverityMedium

What this control requires

PE-06 requires organizations to monitor physical access to facilities housing information systems, review access logs, and coordinate findings with incident response. This control sits within the Physical and Environmental Protection family of the broader NIST SP 800-53 framework and applies at all three baselines, making it a baseline expectation rather than an advanced overlay.

In practice, this means you need more than badge readers on doors. You need a monitoring program that combines surveillance technology, log review procedures, and a documented handoff to incident response when something looks wrong. The emphasis isn’t on prevention alone but on detection and response, acknowledging that physical controls can fail and organizations need a feedback loop.

Where this requirement breaks down is in coordination. Many organizations have physical security teams that operate independently from their cybersecurity incident response function. PE-06 explicitly requires these groups to share results, which forces a cross-functional workflow that doesn’t exist by default in most enterprises.

Why it matters

Physical access monitoring failures rarely make headlines the way ransomware does, but they create exactly the kind of audit finding that derails a certification effort or triggers a plan of action and milestones (POA&M) entry. Assessors treat PE-06 deficiencies seriously because an unmonitored facility is an uncontrolled variable in every other security domain. If you can’t demonstrate that you know who entered a server room and when, the integrity of every logical control layered on top becomes questionable.

The compliance risk is compounded by PE-06’s presence in all three baselines. You can’t scope it out for low-impact systems. Auditors reviewing a System Security Plan (SSP) will look for documented monitoring procedures, evidence of regular log reviews, and proof that findings flow into your broader incident handling process. Missing any of those three legs turns a single control gap into a systemic finding.

Contrast that with the operational risk. Physical access monitoring isn’t just an audit checkbox. It’s a detection layer for insider threats, unauthorized maintenance, and social engineering attacks that bypass logical access controls entirely. Without it, you’re relying on prevention-only physical controls and hoping nothing slips through.

What attackers exploit

  • Tailgating and piggybacking into secured areas behind authorized personnel, bypassing badge authentication entirely
  • Credential cloning of proximity cards or key fobs to gain persistent unauthorized physical access
  • After-hours access during periods when monitoring is reduced or surveillance isn’t actively reviewed
  • Social engineering of facilities staff to obtain temporary access badges or escort-free entry
  • Targeting unmanned entry points such as loading docks, utility entrances, or emergency exits that lack equivalent monitoring coverage

How to implement

For your organization

The most common failure mode isn’t missing cameras or badge readers. It’s the gap between collecting physical access control data and actually reviewing it. Organizations invest in monitoring infrastructure, then treat log review as a task nobody owns.

Start by defining your monitoring architecture. Identify every physical access point to facilities where information systems reside, including server rooms, network closets, and data halls. Map each entry point to one or more monitoring mechanisms: video surveillance, electronic access control logs, visitor management systems, or staffed guard posts. Not every entry point needs every mechanism, but every entry point needs at least one that generates a reviewable record.

Establish a log review cadence that matches your risk posture. Daily reviews for high-security areas, weekly for general facilities, and event-triggered reviews when access anomalies surface. Define what constitutes an anomalous event explicitly: access outside business hours, repeated failed badge attempts, access to areas outside someone’s normal pattern, or prolonged access durations. Document these triggers in your physical security procedures.

Build the coordination bridge to incident response. When a log review surfaces suspicious activity, the physical security team needs a documented escalation path into your incident response capability. That means shared ticketing systems, defined escalation criteria, and periodic joint exercises. Your incident response plan should reference physical security incidents explicitly, not treat them as out of scope.

Common mistakes to avoid:

  • Collecting access logs but never reviewing them, creating a false sense of monitoring
  • Relying exclusively on guards without electronic logging that creates reviewable records
  • Defining review frequency too vaguely (“periodically”) to survive an audit
  • Treating physical security and cybersecurity incident response as separate programs with no shared workflow
  • Failing to retain logs long enough to support after-the-fact investigations

For your vendors

When assessing a vendor’s PE-06 posture, the goal is to verify that they don’t just have physical security infrastructure but that they actively monitor it and act on findings. A vendor with cameras everywhere but no log review process is performing security theater, and your compliance monitoring program should catch that distinction.

Request specific evidence rather than general attestations. Ask for their physical access monitoring policy, a sample physical access log review report (with sensitive details redacted), and documentation showing how physical security findings feed into their incident response process. If they process or store your data in a dedicated facility, ask for monitoring specifics for that location.

Use a structured physical and data center security questionnaire to standardize your assessment. Key questions include: What monitoring mechanisms are deployed at each physical access point? How frequently are access logs reviewed? Who performs the reviews and what training do they receive? How are anomalous access events escalated? What is the retention period for physical access logs and surveillance footage?

Watch for red flags during your evaluation. Vendors that can produce an access control policy but can’t show evidence of log reviews are likely not operationalizing the control. Similarly, vendors whose physical security program has no touchpoint with their incident response function haven’t met PE-06’s coordination requirement, regardless of how sophisticated their surveillance technology is.

Common mistakes to avoid:

  • Accepting a SOC 2 report as sufficient evidence without verifying physical access monitoring is included in scope
  • Failing to ask about monitoring at all facility locations where your data resides, not just the primary data center
  • Not verifying that the vendor’s review frequency aligns with their stated policy
  • Overlooking the incident response coordination requirement when evaluating physical security

Evidence examples

Evidence TypeExample Artifact
Policy documentationPhysical access monitoring policy defining monitoring mechanisms, review frequency, escalation criteria, and retention requirements
Access log samplesElectronic badge reader logs showing timestamps, user identity, access point, and entry/exit records for a defined review period
Log review recordsCompleted physical access log review reports with reviewer name, date, findings, and disposition of anomalies
Surveillance documentationVideo surveillance system inventory mapping cameras to facility access points, with retention schedules
Incident coordination evidenceIncident tickets or reports showing physical access anomalies escalated to the incident response team
ProceduresPhysical access monitoring procedures describing review workflows, anomaly detection criteria, and response actions
System security planSSP sections defining PE-06 implementation details, responsible roles, and monitoring architecture

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20227.4 Physical security monitoringPartial
ISO 27001:20228.16 Monitoring activitiesPartial
NIST SP 800-171 Rev 303.10.02 Monitoring Physical AccessPartial
  • AU-02 — Event Logging: defines the events that physical access systems should capture in their audit logs, providing the raw data PE-06 monitoring depends on
  • AU-06 — Audit Record Review, Analysis, and Reporting: establishes the analysis process that PE-06 log reviews feed into for broader organizational awareness
  • AU-09 — Protection of Audit Information: protects the integrity of physical access logs so that PE-06 review findings remain trustworthy and tamper-evident
  • AU-12 — Audit Record Generation: ensures physical access systems generate the audit records PE-06 requires for monitoring and review
  • CA-07 — Continuous Monitoring: provides the organizational framework within which PE-06 physical access monitoring operates as one continuous monitoring input
  • CP-10 — System Recovery and Reconstitution: relies on physical access controls being intact during recovery operations to prevent unauthorized access to systems being restored
  • IR-04 — Incident Handling: receives the escalated findings from PE-06 reviews and investigations, closing the loop between detection and response
  • IR-08 — Incident Response Plan: documents the procedures and coordination pathways that PE-06 requires for routing physical security incidents to response teams

Frequently asked questions

What is NIST SP 800-53 PE-06

PE-06 is the NIST SP 800-53 control that requires organizations to monitor physical access to facilities housing information systems, review physical access logs at a defined frequency and upon specific events, and coordinate review findings with incident response capabilities. It applies at all three baselines and focuses on the detection-and-response side of physical security rather than prevention alone.

The control addresses a gap that physical access prevention controls can’t fully close on their own. Badge readers and locks stop unauthorized entry at the perimeter, but PE-06 ensures you’re actively watching for anomalies, reviewing evidence of who entered and when, and routing suspicious findings to the people who can investigate.

What happens if PE-06 is not implemented

Without PE-06, your organization loses the ability to detect physical security incidents through access log reviews, creating a blind spot that auditors will flag as a systemic finding across your authorization boundary. Because PE-06 sits in all three baselines, its absence generates a POA&M item regardless of system impact level.

The operational consequence goes beyond compliance. Unmonitored physical access means insider threats, tailgating incidents, and unauthorized facility entry go undetected until their downstream effects surface in logical systems. By that point, the investigative trail in access logs may have been overwritten or never existed.

How do you audit PE-06

Auditing PE-06 starts with verifying that physical access monitoring mechanisms exist at every facility access point, then confirming that access log reviews happen at the frequency defined in your procedures and in response to the triggering events you’ve documented. Assessors will request completed log review records, surveillance system inventories, and evidence that findings were coordinated with the incident response team.

The strongest evidence combines technical artifacts with process documentation. Physical access logs demonstrate the monitoring capability exists, but completed review reports with reviewer signatures, anomaly dispositions, and incident tickets prove the organization is actually operationalizing the control rather than just collecting data.

What types of physical access monitoring does NIST require

NIST doesn’t mandate specific monitoring technologies but requires organizations to monitor physical access using mechanisms appropriate to their facility and risk level, including options like video surveillance, electronic access control systems, guard forces, and sensor devices. The critical requirement is that whichever mechanisms you choose must generate reviewable records that support the log review and incident coordination requirements of PE-06.

Specifically, the monitoring program must cover publicly accessible areas within your facilities, not just restricted zones like server rooms. Organizations commonly underestimate this scope requirement and monitor only high-security areas while leaving lobbies, shared spaces, and secondary entrances unmonitored.

Experience superior visibility and a simpler approach to cyber risk management