# PE-20 Asset Monitoring and Tracking

NIST SP 800-53 control. Family: PE Physical and Environmental Protection. Function: preventative. In no baseline. Mapping licence: CC BY-SA 4.0.

Statement: Employ [Assignment: organization-defined asset location technologies] to track and monitor the location and movement of [Assignment: organization-defined assets] within [Assignment: organization-defined controlled areas].
Guidance: Asset location technologies can help ensure that critical assets—including vehicles, equipment, and system components—remain in authorized locations. Organizations consult with the Office of the General Counsel and senior agency official for privacy regarding the deployment and use of asset location technologies to address potential privacy concerns.

## Clauses by framework (17 frameworks)
- iso_27001_2022: A.5.10
- nist_csf_2: DE.CM-02, PR.AA-06
- rbi_csf: Annex1.3, ITGRCA.18
- hkma_tme1: TME1.11.1, TME1.11.3
- mlps_2: 8.4, 8.5
- cbb_tm: TM-10
- qatar_nia: PS
- sama_csf: 3.7
- uae_ia: T6
- ffiec_is: II.C.8
- hipaa_sr: §164.310(d)(2)(iii)
- sebi_cscrf: PR.PE
- pci_pts: A, I
- fips_140: FIPS 140-3 §7.7
- fda_21_cfr_11: §11.10(h)
- hitrust_csf: 08.b
- lloyds_ms: PHYS.1
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PE-20
- Clauses only: /api/v1/controls/PE-20?fields=mappings
- Page for people: /controls/pe-20/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
