Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family PE

PE-2Physical Access Authorizations

Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides; Issue authorization credentials for facility access; Review the access list detailing authorized facility access by individuals {{ insert: param, pe-02_odp }} ; and Remove individuals from the facility access list when access is no longer required.

Last updated: 20 August 2026 13:14 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (1)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-1263Improper Physical Access Control13This control directly develops, approves, maintains, reviews, and revokes physical facility access authorizations and credentials, preventing improper physical access control.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-48973 6.49.30.0022good
CVE-2023-38290 5.77.80.0019good
CVE-2024-28326 5.16.80.0027good
CVE-2025-4386 5.06.80.0016good
CVE-2022-32506 4.96.40.0043good
CVE-2024-39512 4.96.60.0022good
CVE-2025-6785 3.54.70.0022good
CVE-2025-596962.83.20.0021good
CVE-2025-8762 5.06.80.0018good

Other controls in family PE

PE-1 PE-10 PE-11 PE-12 PE-13 PE-14 PE-15 PE-16 PE-17 PE-18 PE-19 PE-20 PE-21 PE-22 PE-23 PE-3 PE-4 PE-5 PE-6 PE-7 PE-8 PE-9