PR.AA-06.211
Does your organization implement physical security controls to monitor facilities and restrict unauthorized access?
Explanation
Physical security controls are essential for protecting sensitive assets, data, and personnel from unauthorized physical access. These controls typically include security guards, surveillance cameras, access control systems (key cards, biometric scanners), alarm systems, and locked entrances/exits to create layers of protection around your facilities. Evidence of compliance could include a physical security policy document, photographs of implemented controls (without revealing security vulnerabilities), access control logs, security guard schedules, maintenance records for physical security systems, or a floor plan showing the placement of security cameras and other physical controls.
Implementation Example
Use security guards, security cameras, locked entrances, alarm systems, and other physical controls to monitor facilities and restrict access
ID: PR.AA-06.211
Context
- Function
- PR: PROTECT
- Category
- PR.AA: Identity Management, Authentication, and Access Control
- Sub-Category
- Physical access to assets is managed, monitored, and enforced commensurate with risk

