NIST 800-53 r5 · Controls catalogue · Family PE
PE-2Physical Access Authorizations
Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides; Issue authorization credentials for facility access; Review the access list detailing authorized facility access by individuals {{ insert: param, pe-02_odp }} ; and Remove individuals from the facility access list when access is no longer required.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (1)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-1263 | Improper Physical Access Control | 13 | This control directly develops, approves, maintains, reviews, and revokes physical facility access authorizations and credentials, preventing improper physical access control. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-48973 UPD | 6.4 | 9.3 | 0.0022 | good |
CVE-2023-38290 UPD | 5.7 | 7.8 | 0.0019 | good |
CVE-2024-28326 UPD | 5.1 | 6.8 | 0.0027 | good |
CVE-2025-4386 UPD | 5.0 | 6.8 | 0.0016 | good |
CVE-2022-32506 UPD | 4.9 | 6.4 | 0.0043 | good |
CVE-2024-39512 UPD | 4.9 | 6.6 | 0.0022 | good |
CVE-2025-6785 UPD | 3.5 | 4.7 | 0.0022 | good |
CVE-2025-59696 | 2.8 | 3.2 | 0.0021 | good |
CVE-2025-8762 UPD | 5.0 | 6.8 | 0.0018 | good |