PE-6: MONITORING PHYSICAL ACCESS
TAILORED FOR INDUSTRIAL CONTROL SYSTEMS
ICS Control Baselines:
- Low
- Moderate
- High
The organization:
- a. Monitors physical access to the facility where the information system resides to detect and respond to physical security incidents;
- b. Reviews physical access logs [Assignment: organization-defined frequency] and upon occurrence of [Assignment: organization-defined events or potential indications of events]; and
- c. Coordinates results of reviews and investigations with the organizational incident response capability.
SUPPLEMENTAL GUIDANCE
Organizational incident response capabilities include investigations of and responses to detected physical security incidents. Security incidents include, for example, apparent security violations or suspicious physical access activities. Suspicious physical access activities include, for example: (i) accesses outside of normal work hours; (ii) repeated accesses to areas not normally accessed; (iii) accesses for unusual lengths of time; and (iv) out-of-sequence accesses.
ICS SUPPLEMENTAL GUIDANCE
Physical access controls and defense-in-depth measures are used as compensating controls by the organization when necessary and possible to supplement ICS security when electronic mechanisms are unable to monitor, detect and alarm when an ICS has been accessed. These compensating controls are in addition to the PE-6 controls (e.g., employing PE-3 (4) Lockable Casings and/or PE-3 (5) Tamper Protection).
RELATED CONTROLS: PE-6
CONTROL ENHANCEMENTS
PE-6 (1) MONITORING PHYSICAL ACCESS | INTRUSION ALARMS/SURVEILLANCE EQUIPMENT
ICS Control Baselines:
- Moderate
- High
The organization monitors physical intrusion alarms and surveillance equipment.
Supplemental Guidance: NONE
No ICS Supplemental Guidance.
PE-6 (2) MONITORING PHYSICAL ACCESS | AUTOMATED INTRUSION RECOGNITION / RESPONSES
NOT SELECTED FOR THE NIST ISC CONTROL SET
The organization employs automated mechanisms to recognize [Assignment: organization-defined classes/types of intrusions] and initiate [Assignment: organization-defined response actions].
Supplemental Guidance: NONE
RELATED CONTROLS: PE-6 (2)
PE-6 (3) MONITORING PHYSICAL ACCESS | VIDEO SURVEILLANCE
NOT SELECTED FOR THE NIST ISC CONTROL SET
The organization employs video surveillance of [Assignment: organization-defined operational areas] and retains video recordings for [Assignment: organization-defined time period].
Supplemental Guidance:
This control enhancement focuses on recording surveillance video for purposes of subsequent review, if circumstances so warrant (e.g., a break-in detected by other means). It does not require monitoring surveillance video although organizations may choose to do so. Note that there may be legal considerations when performing and retaining video surveillance, especially if such surveillance is in a public location.
PE-6 (4) MONITORING PHYSICAL ACCESS | MONITORING PHYSICAL ACCESS TO INFORMATION SYSTEMS
ICS Control Baselines:
- Moderate (ADDED)
- High
The organization monitors physical access to the information system in addition to the physical access monitoring of the facility as [Assignment: organization-defined physical spaces containing one or more components of the information system].
Supplemental Guidance:
This control enhancement provides additional monitoring for those areas within facilities where there is a concentration of information system components (e.g., server rooms, media storage areas, communications centers).
ICS Supplemental Guidance:
The locations of ICS components (e.g., field devices, remote terminal units) can include various remote locations (e.g., substations, pumping stations).
Rationale (adding PE-6 (4) to MODERATE baseline): Many of the ICS components are in remote geographical and dispersed locations with little capability to monitor all ICS components. Other components may be in ceilings, floors, or distribution closets with minimal physical barriers to detect, delay or deny access to the devices and no electronic surveillance or guard forces response capability.
RELATED CONTROLS: PE-6 (4)
REFERENCES:
- NIST Special Publication 800-82 | GUIDE TO INDUSTRIAL CONTROL SYSTEMS (ICS) SECURITY