Browse 1,193 controls and enhancements across 20 security and privacy families. Use the GovRAMP crosswalk to locate controls referenced by Security Snapshot, Core, and Moderate.
A shared catalog supports common-control planning; designation as a common, hybrid, or system-specific control depends on your organization’s implementation and inheritance decisions.
Sources and crosswalk scope
NIST OSCAL content 5.1.1+u4, retrieved 2026-09-18. GovRAMP Snapshot v1.4 and Core selection from Moderate v1.06 reference the December 2020 Rev. 5 text. Mappings establish exact identifier correspondence, not identical requirements, inherited implementation, or GovRAMP authorization. GovRAMP parameters and additional requirements remain authoritative for each program. Full Moderate, High, and other programs are not mapped here. Withdrawn controls are retained for reference.
Official pinned NIST sourceSHA-256: 81cf2de45ede9aef3de7ce09d65ea9d32f662c483bbf916f6e346292b22f7763
Media Protection · Enhancement
MP-8(1) · Documentation of Process
View parent controlControl statement and discussion
NIST control statement
Document system media downgrading actions.
Discussion
Organizations can document the media downgrading process by providing information, such as the downgrading technique employed, the identification number of the downgraded media, and the identity of the individual that authorized and/or performed the downgrading action.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Media Protection · Enhancement
MP-8(2) · Equipment Testing
View parent controlControl statement and discussion
NIST control statement
Test downgrading equipment and procedures [Assignment: organization-defined frequency] to ensure that downgrading actions are being achieved.
Discussion
None.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Media Protection · Enhancement
MP-8(3) · Controlled Unclassified Information
View parent controlControl statement and discussion
NIST control statement
Downgrade system media containing controlled unclassified information prior to public release.
Discussion
The downgrading of controlled unclassified information uses approved sanitization tools, techniques, and procedures.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Media Protection · Enhancement
MP-8(4) · Classified Information
View parent controlControl statement and discussion
NIST control statement
Downgrade system media containing classified information prior to release to individuals without required access authorizations.
Discussion
Downgrading of classified information uses approved sanitization tools, techniques, and procedures to transfer information confirmed to be unclassified from classified systems to unclassified media.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Base control
PE-1 · Policy and Procedures
Control statement and discussion
NIST control statement
a. Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]:
1. [Selection (one-or-more): organization-level; mission/business process-level; system-level] physical and environmental protection policy that:
(a) Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
(b) Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and
2. Procedures to facilitate the implementation of the physical and environmental protection policy and the associated physical and environmental protection controls;
b. Designate an [Assignment: official] to manage the development, documentation, and dissemination of the physical and environmental protection policy and procedures; and
c. Review and update the current physical and environmental protection:
1. Policy [Assignment: frequency] and following [Assignment: events] ; and
2. Procedures [Assignment: frequency] and following [Assignment: events].
Discussion
Physical and environmental protection policy and procedures address the controls in the PE family that are implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that security and privacy programs collaborate on the development of physical and environmental protection policy and procedures. Security and privacy program policies and procedures at the organization level are preferable, in general, and may obviate the need for mission- or system-specific policies and procedures. The policy can be included as part of the general security and privacy policy or be represented by multiple policies that reflect the complex nature of organizations. Procedures can be established for security and privacy programs, for mission or business processes, and for systems, if needed. Procedures describe how the policies or controls are implemented and can be directed at the individual or role that is the object of the procedure. Procedures can be documented in system security and privacy plans or in one or more separate documents. Events that may precipitate an update to physical and environmental protection policy and procedures include assessment or audit findings, security incidents or breaches, or changes in applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Simply restating controls does not constitute an organizational policy or procedure.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · PE-1 — Direct NIST identifier reference. GovRAMP source matrix
Physical and Environmental Protection · Base control
PE-2 · Physical Access Authorizations
Control statement and discussion
NIST control statement
a. Develop, approve, and maintain a list of individuals with authorized access to the facility where the system resides;
b. Issue authorization credentials for facility access;
c. Review the access list detailing authorized facility access by individuals [Assignment: frequency] ; and
d. Remove individuals from the facility access list when access is no longer required.
Discussion
Physical access authorizations apply to employees and visitors. Individuals with permanent physical access authorization credentials are not considered visitors. Authorization credentials include ID badges, identification cards, and smart cards. Organizations determine the strength of authorization credentials needed consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Physical access authorizations may not be necessary to access certain areas within facilities that are designated as publicly accessible.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · PE-2 — Direct NIST identifier reference. GovRAMP source matrix
Physical and Environmental Protection · Enhancement
PE-2(1) · Access by Position or Role
View parent controlControl statement and discussion
NIST control statement
Authorize physical access to the facility where the system resides based on position or role.
Discussion
Role-based facility access includes access by authorized permanent and regular/routine maintenance personnel, duty officers, and emergency medical staff.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Enhancement
PE-2(2) · Two Forms of Identification
View parent controlControl statement and discussion
NIST control statement
Require two forms of identification from the following forms of identification for visitor access to the facility where the system resides: [Assignment: list of acceptable forms of identification].
Discussion
Acceptable forms of identification include passports, REAL ID-compliant drivers’ licenses, and Personal Identity Verification (PIV) cards. For gaining access to facilities using automated mechanisms, organizations may use PIV cards, key cards, PINs, and biometrics.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Enhancement
PE-2(3) · Restrict Unescorted Access
View parent controlControl statement and discussion
NIST control statement
Restrict unescorted access to the facility where the system resides to personnel with [Selection (one-or-more): security clearances for all information contained within the system; formal access authorizations for all information contained within the system; need for access to all information contained within the system; [Assignment: physical access authorizations] ].
Discussion
Individuals without required security clearances, access approvals, or need to know are escorted by individuals with appropriate physical access authorizations to ensure that information is not exposed or otherwise compromised.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Base control
PE-3 · Physical Access Control
Control statement and discussion
NIST control statement
a. Enforce physical access authorizations at [Assignment: entry and exit points] by:
1. Verifying individual access authorizations before granting access to the facility; and
2. Controlling ingress and egress to the facility using [Selection (one-or-more): [Assignment: systems or devices] ; guards];
b. Maintain physical access audit logs for [Assignment: entry or exit points];
c. Control access to areas within the facility designated as publicly accessible by implementing the following controls: [Assignment: physical access controls];
d. Escort visitors and control visitor activity [Assignment: circumstances];
e. Secure keys, combinations, and other physical access devices;
f. Inventory [Assignment: physical access devices] every [Assignment: frequency] ; and
g. Change combinations and keys [Assignment: organization-defined frequency] and/or when keys are lost, combinations are compromised, or when individuals possessing the keys or combinations are transferred or terminated.
Discussion
Physical access control applies to employees and visitors. Individuals with permanent physical access authorizations are not considered visitors. Physical access controls for publicly accessible areas may include physical access control logs/records, guards, or physical access devices and barriers to prevent movement from publicly accessible areas to non-public areas. Organizations determine the types of guards needed, including professional security staff, system users, or administrative staff. Physical access devices include keys, locks, combinations, biometric readers, and card readers. Physical access control systems comply with applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. Organizations have flexibility in the types of audit logs employed. Audit logs can be procedural, automated, or some combination thereof. Physical access points can include facility access points, interior access points to systems that require supplemental access controls, or both. Components of systems may be in areas designated as publicly accessible with organizations controlling access to the components.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · PE-3 — Direct NIST identifier reference. GovRAMP source matrix
Physical and Environmental Protection · Enhancement
PE-3(1) · System Access
View parent controlControl statement and discussion
NIST control statement
Enforce physical access authorizations to the system in addition to the physical access controls for the facility at [Assignment: physical spaces].
Discussion
Control of physical access to the system provides additional physical security for those areas within facilities where there is a concentration of system components.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Enhancement
PE-3(2) · Facility and Systems
View parent controlControl statement and discussion
NIST control statement
Perform security checks [Assignment: frequency] at the physical perimeter of the facility or system for exfiltration of information or removal of system components.
Discussion
Organizations determine the extent, frequency, and/or randomness of security checks to adequately mitigate risk associated with exfiltration.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Enhancement
PE-3(3) · Continuous Guards
View parent controlControl statement and discussion
NIST control statement
Employ guards to control [Assignment: physical access points] to the facility where the system resides 24 hours per day, 7 days per week.
Discussion
Employing guards at selected physical access points to the facility provides a more rapid response capability for organizations. Guards also provide the opportunity for human surveillance in areas of the facility not covered by video surveillance.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Enhancement
PE-3(4) · Lockable Casings
View parent controlControl statement and discussion
NIST control statement
Use lockable physical casings to protect [Assignment: system components] from unauthorized physical access.
Discussion
The greatest risk from the use of portable devices—such as smart phones, tablets, and notebook computers—is theft. Organizations can employ lockable, physical casings to reduce or eliminate the risk of equipment theft. Such casings come in a variety of sizes, from units that protect a single notebook computer to full cabinets that can protect multiple servers, computers, and peripherals. Lockable physical casings can be used in conjunction with cable locks or lockdown plates to prevent the theft of the locked casing containing the computer equipment.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Enhancement
PE-3(5) · Tamper Protection
View parent controlControl statement and discussion
NIST control statement
Employ [Assignment: anti-tamper technologies] to [Selection (one-or-more): detect; prevent] physical tampering or alteration of [Assignment: hardware components] within the system.
Discussion
Organizations can implement tamper detection and prevention at selected hardware components or implement tamper detection at some components and tamper prevention at other components. Detection and prevention activities can employ many types of anti-tamper technologies, including tamper-detection seals and anti-tamper coatings. Anti-tamper programs help to detect hardware alterations through counterfeiting and other supply chain-related risks.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Enhancement
PE-3(7) · Physical Barriers
View parent controlControl statement and discussion
NIST control statement
Limit access using physical barriers.
Discussion
Physical barriers include bollards, concrete slabs, jersey walls, and hydraulic active vehicle barriers.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Enhancement
PE-3(8) · Access Control Vestibules
View parent controlControl statement and discussion
NIST control statement
Employ access control vestibules at [Assignment: locations].
Discussion
An access control vestibule is part of a physical access control system that typically provides a space between two sets of interlocking doors. Vestibules are designed to prevent unauthorized individuals from following authorized individuals into facilities with controlled access. This activity, also known as piggybacking or tailgating, results in unauthorized access to the facility. Interlocking door controllers can be used to limit the number of individuals who enter controlled access points and to provide containment areas while authorization for physical access is verified. Interlocking door controllers can be fully automated (i.e., controlling the opening and closing of the doors) or partially automated (i.e., using security guards to control the number of individuals entering the containment area).
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Base control
PE-4 · Access Control for Transmission
Control statement and discussion
NIST control statement
Control physical access to [Assignment: system distribution and transmission lines] within organizational facilities using [Assignment: security controls].
Discussion
Security controls applied to system distribution and transmission lines prevent accidental damage, disruption, and physical tampering. Such controls may also be necessary to prevent eavesdropping or modification of unencrypted transmissions. Security controls used to control physical access to system distribution and transmission lines include disconnected or locked spare jacks, locked wiring closets, protection of cabling by conduit or cable trays, and wiretapping sensors.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · PE-4 — Direct NIST identifier reference. GovRAMP source matrix
Physical and Environmental Protection · Base control
PE-5 · Access Control for Output Devices
Control statement and discussion
NIST control statement
Control physical access to output from [Assignment: output devices] to prevent unauthorized individuals from obtaining the output.
Discussion
Controlling physical access to output devices includes placing output devices in locked rooms or other secured areas with keypad or card reader access controls and allowing access to authorized individuals only, placing output devices in locations that can be monitored by personnel, installing monitor or screen filters, and using headphones. Examples of output devices include monitors, printers, scanners, audio devices, facsimile machines, and copiers.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · PE-5 — Direct NIST identifier reference. GovRAMP source matrix
Physical and Environmental Protection · Enhancement
PE-5(2) · Link to Individual Identity
View parent controlControl statement and discussion
NIST control statement
Link individual identity to receipt of output from output devices.
Discussion
Methods for linking individual identity to the receipt of output from output devices include installing security functionality on facsimile machines, copiers, and printers. Such functionality allows organizations to implement authentication on output devices prior to the release of output to individuals.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Base control
PE-6 · Monitoring Physical Access
Control statement and discussion
NIST control statement
a. Monitor physical access to the facility where the system resides to detect and respond to physical security incidents;
b. Review physical access logs [Assignment: frequency] and upon occurrence of [Assignment: events] ; and
c. Coordinate results of reviews and investigations with the organizational incident response capability.
Discussion
Physical access monitoring includes publicly accessible areas within organizational facilities. Examples of physical access monitoring include the employment of guards, video surveillance equipment (i.e., cameras), and sensor devices. Reviewing physical access logs can help identify suspicious activity, anomalous events, or potential threats. The reviews can be supported by audit logging controls, such as [AU-2](#au-2) , if the access logs are part of an automated system. Organizational incident response capabilities include investigations of physical security incidents and responses to the incidents. Incidents include security violations or suspicious physical access activities. Suspicious physical access activities include accesses outside of normal work hours, repeated accesses to areas not normally accessed, accesses for unusual lengths of time, and out-of-sequence accesses.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · PE-6 — Direct NIST identifier reference. GovRAMP source matrix
Physical and Environmental Protection · Enhancement
PE-6(1) · Intrusion Alarms and Surveillance Equipment
View parent controlControl statement and discussion
NIST control statement
Monitor physical access to the facility where the system resides using physical intrusion alarms and surveillance equipment.
Discussion
Physical intrusion alarms can be employed to alert security personnel when unauthorized access to the facility is attempted. Alarm systems work in conjunction with physical barriers, physical access control systems, and security guards by triggering a response when these other forms of security have been compromised or breached. Physical intrusion alarms can include different types of sensor devices, such as motion sensors, contact sensors, and broken glass sensors. Surveillance equipment includes video cameras installed at strategic locations throughout the facility.
GovRAMP crosswalk
- GovRAMP Moderate Readiness · PE-6 (1) — Direct NIST identifier reference. GovRAMP source matrix
Physical and Environmental Protection · Enhancement
PE-6(2) · Automated Intrusion Recognition and Responses
View parent controlControl statement and discussion
NIST control statement
Recognize [Assignment: classes or types of intrusions] and initiate [Assignment: response actions] using [Assignment: automated mechanisms].
Discussion
Response actions can include notifying selected organizational personnel or law enforcement personnel. Automated mechanisms implemented to initiate response actions include system alert notifications, email and text messages, and activating door locking mechanisms. Physical access monitoring can be coordinated with intrusion detection systems and system monitoring capabilities to provide integrated threat coverage for the organization.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Enhancement
PE-6(3) · Video Surveillance
View parent controlControl statement and discussion
NIST control statement
(a) Employ video surveillance of [Assignment: operational areas];
(b) Review video recordings [Assignment: frequency] ; and
(c) Retain video recordings for [Assignment: time period].
Discussion
Video surveillance focuses on recording activity in specified areas for the purposes of subsequent review, if circumstances so warrant. Video recordings are typically reviewed to detect anomalous events or incidents. Monitoring the surveillance video is not required, although organizations may choose to do so. There may be legal considerations when performing and retaining video surveillance, especially if such surveillance is in a public location.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.
Physical and Environmental Protection · Enhancement
PE-6(4) · Monitoring Physical Access to Systems
View parent controlControl statement and discussion
NIST control statement
Monitor physical access to the system in addition to the physical access monitoring of the facility at [Assignment: physical spaces].
Discussion
Monitoring physical access to systems provides additional monitoring for those areas within facilities where there is a concentration of system components, including server rooms, media storage areas, and communications centers. Physical access monitoring can be coordinated with intrusion detection systems and system monitoring capabilities to provide comprehensive and integrated threat coverage for the organization.
GovRAMP crosswalk
Not selected in the imported Snapshot or Core sets. This does not establish exclusion from other GovRAMP baselines.