{"data":{"id":"PE-18","name":"Location of System Components","family":"PE","family_name":"Physical and Environmental Protection","withdrawn":false,"description":"Position system components within the facility to minimize potential damage from [Assignment: organization-defined physical and environmental hazards] and to minimize the opportunity for unauthorized access.","supplemental_guidance":"Physical and environmental hazards include floods, fires, tornadoes, earthquakes, hurricanes, terrorism, vandalism, an electromagnetic pulse, electrical interference, and other forms of incoming electromagnetic radiation. Organizations consider the location of entry points where unauthorized individuals, while not being granted access, might nonetheless be near systems. Such proximity can increase the risk of unauthorized access to organizational communications using wireless packet sniffers or microphones, or unauthorized disclosure of information.","enhancements":[{"id":"PE-18(01)","name":"Facility Site","withdrawn":true,"incorporated_into":["PE-23"]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":true,"nist_800_53":{"rev5":{"id":"PE-18","name":"Location of System Components","description":"Position system components within the facility to minimize potential damage from [Assignment: organization-defined physical and environmental hazards] and to minimize the opportunity for unauthorized access.","discussion":"Physical and environmental hazards include floods, fires, tornadoes, earthquakes, hurricanes, terrorism, vandalism, an electromagnetic pulse, electrical interference, and other forms of incoming electromagnetic radiation. Organizations consider the location of entry points where unauthorized individuals, while not being granted access, might nonetheless be near systems. Such proximity can increase the risk of unauthorized access to organizational communications using wireless packet sniffers or microphones, or unauthorized disclosure of information.","related_controls":["CP-02","PE-05","PE-19","PE-20","RA-03"],"baseline_low":false,"baseline_moderate":false,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":["A.5.10","A.7.5","A.7.8"],"iso_27002_2022":["7.3","7.8"],"cobit_2019":["DSS01","DSS05"],"pci_dss_v4":[],"nist_csf_2":["PR.AA-06","PR.IR-02"],"cis_controls_v8":[],"soc2_tsc":["A1.2"],"finos_ccc":[],"iso_42001_2023":["A.4.5"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["INF.1","INF.2"],"anssi":["Hygiene.37","Hygiene.38","SecNumCloud.12.1"],"osfi_b13":["B-13.2.6"],"finma_circular":["IV.A(28)","IV.D(81)"],"gdpr":[],"dora":[],"bio2":["7.3","7.8"],"rbi_csf":["Annex1.3","ITGRCA.18"],"fisc":["FISC.F1"],"lgpd_bcb":[],"hkma_tme1":["TME1.5.1"],"mlps_2":["8.1.1.1"],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-10"],"nca_ecc":["1-11"],"qatar_nia":["PS"],"sama_csf":["3.7"],"uae_ia":["T6"],"bog_cisd":["CISD-XIV"],"bom_ctrm":["3.5"],"cbe_csf":["CTO-10"],"sa_js2":["JS2-PE"],"bot_cyber":["Ch2.8"],"eba_ict":["3.4.3"],"ecb_croe":["CROE.2.3.6"],"ffiec_is":["II.C.8"],"hipaa_sr":["§164.310(a)(1)","§164.310(b)"],"iosco_cyber":["PROT-5"],"sebi_cscrf":["PR.PE"],"cmmc_2":["PE"],"nerc_cip":["CIP-006-6"],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":["D"],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":["7"],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["08.a"],"iso_27799":["11.1","11.2"],"lloyds_ms":["PHYS.1"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":["EIOPA-ICT-4.5"],"owasp_masvs_v2":["MASVS-PLATFORM-3"],"csa_ccm_v4":["DCS-15"],"csa_aicm":["DCS-15"],"ccss_v9":["1.03.4"],"mica":[],"basel_sco60":["SCO60.64"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.5.10, A.7.5 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.AA-06, PR.IR-02 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to --H, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}