PE-1 Physical and Environmental Protection Policy and Procedures
Description
This Control addresses the establishment of policy and procedures for the effective implementation of selected security controls and control enhancements in the PE family. Policy and procedures reflect applicable federal laws, executive orders, directives, regulations, policies, standards, and guidance. Security program policies and procedures at the organization level may make the need for system specific policies and procedures unnecessary.
The policy can be included as part of the general information security policy for organizations or conversely, can be represented by multiple policies reflecting the complex nature of certain organizations.
The procedures can be established for the security program in general and for particular information systems, if needed.
The organizational risk management strategy is a key factor in establishing policy and procedures.
Applicability
This Control applies to facilities that house information systems (i.e., data centers) considered mission critical and which require a higher level of security due to the nature of one of the following:
- type of equipment
- type of data the equipment stores
Responsibility for ensuring physical security to information resources may be part of the job function for departmental staff who may include, but not be limited to, information technology staff, information resource custodians, supervisors, managers, and others.
Implementation
Director of Infrastructure or his or her designated representative(s) shall document and manage physical access to mission critical information resources facilities to ensure the protection of information resources from unlawful or unauthorized access, use, modification, or destruction:
- Develop, document, and disseminate to Owners and Custodians:
- A physical and environmental protection policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
- Procedures to facilitate the implementation of the physical and environmental protection policy and associated physical and environmental protection controls; and
- Reviews and updates the current:
- Physical and environmental protection policy annually; and
- Physical and environmental protection procedures annually or when required by information systems, TAMU System, state, federal, and/or regulatory requirements change.
Revision History
Last Updated: February 21, 2025
Previous Versions:
- June 29, 2023
- May 31, 2022
- March 25, 2021
- September 16, 2019