NIST 800-53 r5 · Controls catalogue · Family PE
PE-3Physical Access Control
Enforce physical access authorizations at {{ insert: param, pe-03_odp.01 }} by: Verifying individual access authorizations before granting access to the facility; and Controlling ingress and egress to the facility using {{ insert: param, pe-03_odp.02 }}; Maintain physical access audit logs for {{ insert: param, pe-03_odp.04 }}; Control access to areas within the facility designated as publicly accessible by implementing the following controls: {{ insert: param, pe-03_odp.05 }}; Escort visitors and control visitor activity {{ insert: param, pe-03_odp.06 }}; Secure keys, combinations, and other physical access devices; Inventory {{ insert: param, pe-03_odp.07 }} every {{ insert: param, pe-03_odp.08 }} ; and Change combinations and keys {{ insert: param, pe-3_prm_9 }} and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Requires verification of individual access authorizations before granting facility entry, addressing missing authentication for critical physical access. |
CWE-732 | Incorrect Permission Assignment for Critical Resource | 1,900+ | Mandates securing keys/combinations, periodic inventory, and rotation on compromise or personnel changes to correct improper physical permission assignments. |
CWE-552 | Files or Directories Accessible to External Parties | 500+ | Controls access to facility areas (including publicly accessible zones) to prevent external parties from reaching internal resources or sensitive locations. |
CWE-778 | Insufficient Logging | 28 | Requires maintenance of physical access audit logs, directly mitigating insufficient logging of access attempts and events. |
CWE-1263 | Improper Physical Access Control | 13 | Directly implements physical access authorizations, ingress/egress controls, visitor escorting, and key/combination management to prevent unauthorized physical entry. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-48973 UPD | 6.4 | 9.3 | 0.0022 | good |
CVE-2023-38290 UPD | 5.7 | 7.8 | 0.0019 | good |
CVE-2024-28326 UPD | 5.1 | 6.8 | 0.0027 | good |
CVE-2025-4386 UPD | 5.0 | 6.8 | 0.0016 | good |
CVE-2022-32506 UPD | 4.9 | 6.4 | 0.0043 | good |
CVE-2024-39512 UPD | 4.9 | 6.6 | 0.0022 | good |
CVE-2025-6785 UPD | 3.5 | 4.7 | 0.0022 | good |
CVE-2025-59696 | 2.8 | 3.2 | 0.0021 | good |
CVE-2025-8762 UPD | 5.0 | 6.8 | 0.0018 | good |
CVE-2024-36438 UPD | 5.4 | 7.3 | 0.0019 | good |