PE-6 H M L

The organization:
a. Monitors physical access to the facility where the information system resides to detect and respond to physical security incidents;
b. Reviews physical access logs [Assignment: organization-defined frequency] and upon occurrence of [Assignment: organization-defined events or potential indications of events]; and
c. Coordinates results of reviews and investigations with the organizational incident response capability.

  • H PE-6 (b) [at least monthly]
  • M PE-6 (b) [at least monthly]
  • L PE-6 (b) [at least monthly]
DISA Cloud Computing SRG

b. every 30 days

b. Not appropriate for DoD to define for all CSP's infrastructure or service offerings


Supplemental Guidance

Organizational incident response capabilities include investigations of and responses to detected physical security incidents. Security incidents include, for example, apparent security violations or suspicious physical access activities. Suspicious physical access activities include, for example: (i) accesses outside of normal work hours; (ii) repeated accesses to areas not normally accessed; (iii) accesses for unusual lengths of time; and (iv) out-of-sequence accesses.

Related Controls