NIST 800-171 Controls · Physical Protection
PE.1.001 — Limit Physical Access to Systems
Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
What PE.1.001 means in plain English
Lock the doors to any rooms where your computers, servers, or filing cabinets with government contract data are kept. Not everyone in the building should be able to walk into the server closet or the office where CUI is stored. Use locked doors, key cards, or even simple deadbolts with a sign-out key log. If you have a server rack, put it in a locked room or a locked cabinet — not sitting in the open shop floor.
The assessment question
“Are rooms and areas containing systems, servers, or paper files with CUI physically locked or otherwise restricted so that only authorized employees can enter?”
How to implement PE.1.001
- Identify every location where CUI is stored or processed — server closets, offices with CUI workstations, filing cabinets with printed CUI. Mark these on a simple floor plan.
- Install keyed deadbolt locks or keypad locks on doors to server rooms and CUI storage areas. A basic keypad deadbolt like Schlage BE365 costs about $100 and requires no wiring.
- Maintain a key or access code log: record who has a key or knows the code, and review quarterly. When someone leaves, re-key or change the code.
- For server racks in shared spaces, use a locking server cabinet (available for $300-$500) if a dedicated room is not feasible.
- Post "Authorized Personnel Only" signage on doors to restricted areas.
Evidence your assessor will ask for
- Floor plan or diagram showing restricted areas where CUI systems are located
- Photos of locked doors, keypad locks, or badge readers on restricted areas
- Key/access code issuance log showing who has physical access
- Written Physical Access Control Policy or procedure
- Signage photos showing "Authorized Personnel Only" on restricted areas
Does AI prompt monitoring help with this control? Honestly, no.
PE.1.001 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Physical Protection controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.