# PE-18 Location of System Components

NIST SP 800-53 control. Family: PE Physical and Environmental Protection. Function: preventative. Baselines: high. Mapping licence: CC BY-SA 4.0.

Statement: Position system components within the facility to minimize potential damage from [Assignment: organization-defined physical and environmental hazards] and to minimize the opportunity for unauthorized access.
Guidance: Physical and environmental hazards include floods, fires, tornadoes, earthquakes, hurricanes, terrorism, vandalism, an electromagnetic pulse, electrical interference, and other forms of incoming electromagnetic radiation. Organizations consider the location of entry points where unauthorized individuals, while not being granted access, might nonetheless be near systems. Such proximity can increase the risk of unauthorized access to organizational communications using wireless packet sniffers or microphones, or unauthorized disclosure of information.

## Enhancements (none current)
Withdrawn by NIST: PE-18(01) (now in PE-23).

## Clauses by framework (44 frameworks)
- iso_27001_2022: A.5.10, A.7.5, A.7.8
- iso_27002_2022: 7.3, 7.8
- cobit_2019: DSS01, DSS05
- nist_csf_2: PR.AA-06, PR.IR-02
- soc2_tsc: A1.2
- iso_42001_2023: A.4.5
- bsi_grundschutz: INF.1, INF.2
- anssi: Hygiene.37, Hygiene.38, SecNumCloud.12.1
- osfi_b13: B-13.2.6
- finma_circular: IV.A(28), IV.D(81)
- bio2: 7.3, 7.8
- rbi_csf: Annex1.3, ITGRCA.18
- fisc: FISC.F1
- hkma_tme1: TME1.5.1
- mlps_2: 8.1.1.1
- cbb_tm: TM-10
- nca_ecc: 1-11
- qatar_nia: PS
- sama_csf: 3.7
- uae_ia: T6
- bog_cisd: CISD-XIV
- bom_ctrm: 3.5
- cbe_csf: CTO-10
- sa_js2: JS2-PE
- bot_cyber: Ch2.8
- eba_ict: 3.4.3
- ecb_croe: CROE.2.3.6
- ffiec_is: II.C.8
- hipaa_sr: §164.310(a)(1), §164.310(b)
- iosco_cyber: PROT-5
- sebi_cscrf: PR.PE
- cmmc_2: PE
- nerc_cip: CIP-006-6
- pci_pts: D
- pci_hsm: 7
- hitrust_csf: 08.a
- iso_27799: 11.1, 11.2
- lloyds_ms: PHYS.1
- solvency_ii: EIOPA-ICT-4.5
- owasp_masvs_v2: MASVS-PLATFORM-3
- csa_ccm_v4: DCS-15
- csa_aicm: DCS-15
- ccss_v9: 1.03.4
- basel_sco60: SCO60.64
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PE-18
- Clauses only: /api/v1/controls/PE-18?fields=mappings
- Page for people: /controls/pe-18/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
