← Controls / PE

PE-18 Location of System Components

Physical and Environmental Protection

High

Description

Position system components within the facility to minimize potential damage from [Assignment: organization-defined physical and environmental hazards] and to minimize the opportunity for unauthorized access.

Supplemental Guidance

Physical and environmental hazards include floods, fires, tornadoes, earthquakes, hurricanes, terrorism, vandalism, an electromagnetic pulse, electrical interference, and other forms of incoming electromagnetic radiation. Organizations consider the location of entry points where unauthorized individuals, while not being granted access, might nonetheless be near systems. Such proximity can increase the risk of unauthorized access to organizational communications using wireless packet sniffers or microphones, or unauthorized disclosure of information.

Enhancements (0)

NIST has withdrawn every enhancement this control had.

  • PE-18(01) Facility Site, now in PE-23

Compliance Mappings

ISO 27001:2022

A.5.10A.7.5A.7.8

ISO 27002:2022

7.37.8

COBIT 2019

DSS01DSS05

NIST CSF 2.0

PR.AA-06PR.IR-02

SOC 2 TSC

A1.2

CSA CCM v4

DCS-15

CSA AICM v1

DCS-15

ISO 42001:2023

A.4.5

BSI IT-Grundschutz

INF.1INF.2

ANSSI

Hygiene.37Hygiene.38SecNumCloud.12.1

FINMA Circular 2023/1

IV.A(28)IV.D(81)

OSFI B-13

B-13.2.6

BIO2

7.37.8

RBI CSF

Annex1.3ITGRCA.18

FISC Security Guidelines

FISC.F1

HKMA TM-E-1

TME1.5.1

MLPS 2.0

8.1.1.1

SAMA CSF

3.7

NCA ECC

1-11

UAE IA

T6

CBB TM

TM-10

Qatar NIA

PS

CBE CSF

CTO-10

SA JS2

JS2-PE

BoG CISD

CISD-XIV

BoM CTRM

3.5

IOSCO Cyber Resilience

PROT-5

FFIEC IS

II.C.8

HIPAA Security Rule

§164.310(a)(1)§164.310(b)

ECB CROE

CROE.2.3.6

EBA ICT Guidelines

3.4.3

SEBI CSCRF

PR.PE

BOT Cyber Resilience

Ch2.8

CMMC 2.0

PE

NERC CIP

CIP-006-6

PCI PTS v6

D

PCI HSM

7

Solvency II

EIOPA-ICT-4.5

Lloyd's Minimum Standards

PHYS.1

HITRUST CSF v11

08.a

ISO 27799

11.111.2

OWASP MASVS v2.1

MASVS-PLATFORM-3

CCSS v9.0

1.03.4

Basel SCO60

SCO60.64

ISO 17799 (legacy)

9.2.1

COBIT 4.1 (legacy)

DS12.1