{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/control-controllers-and-servers-through-receiving-and-removal/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/",
        "slug": "control-controllers-and-servers-through-receiving-and-removal",
        "url": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/control-controllers-and-servers-through-receiving-and-removal/"
        },
        "title": "Control controllers and servers through receiving and removal",
        "summary": "NIST PE-16 addresses authorization and records for system components entering and leaving a facility. Extend PACS custody to delivery, staging, repair, return, and disposal.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:35:41+00:00",
        "modified_at": "2026-08-25T21:36:17+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 2,
        "word_count": 430,
        "potentially_affected": "Organizations receiving, staging, moving, repairing, returning, or disposing of PACS controllers, servers, enrollment devices, storage, and related components.",
        "dse_recommendation": "Require component identity, authorization, custody, inspection, configuration state, data handling, and destination records from receiving through final removal.",
        "primary_source": {
            "name": "NIST SP 800-53 Release 5.2.0, PE-16 — Delivery and Removal",
            "url": "https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-16",
            "published_on": "2025-08-27",
            "authority": "National Institute of Standards and Technology"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> a panel or server can bypass normal change control while it is on a loading dock, installer cart, repair bench, or outbound pallet. Physical custody should connect procurement and receiving to configuration, media protection, and final disposition.</p>\n<h2>Source fact: NIST addresses authorization and records for component movement</h2>\n<p>PE-16 in <a href=\"https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-16\" target=\"_blank\" rel=\"noopener noreferrer\">NIST SP 800-53 Release 5.2.0</a> calls for authorizing and controlling organization-defined types of system components entering and exiting the facility and maintaining records of those components. Its discussion says enforcing those authorizations may require restricting access to delivery areas and isolating those areas from the system and media libraries.</p>\n<p>For PACS, the component may contain configuration, credentials, certificates, logs, personal data, or an address that reveals architecture. A replacement can also introduce an unapproved firmware or supply-chain state before anyone enrolls it as an asset.</p>\n<h2>Source boundary and applicability</h2>\n<p>NIST SP 800-53 is a security and privacy control catalog. PE-16 becomes mandatory only through an applicable authorization, policy, contract, regulation, or tailored control baseline. It does not prescribe one receiving process, inspect a specific product, or replace media-sanitization, procurement, hazardous-material, shipping, or evidence rules.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>Which PACS components contain configuration, keys, logs, identity data, or storage?</li>\n<li>Who may authorize receipt, internal movement, repair shipment, return, and disposal?</li>\n<li>Can deliveries reach operational networks or secure areas before inspection?</li>\n<li>How are serial number, tamper state, firmware, accessories, and purchase source verified?</li>\n<li>What sanitization, evidence hold, license release, or vendor attestation is required before exit?</li>\n</ul>\n<h2>DSE recommendation: create an inbound and outbound custody gate</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<p>At receipt, match purchase order, supplier, model, serial number, packaging or tamper indicators, and destination. Hold components in a controlled staging area until inspection, asset registration, approved firmware and configuration, and network onboarding are complete. Record every person or service that takes custody.</p>\n<p>Before removal, identify the asset and owner, preserve required logs or evidence, revoke credentials and certificates, release licenses, sanitize storage by approved method, and record destination and carrier. For repair returns, define whether the vendor may access stored data or keys. Reconcile receiving, inventory, PACS configuration, and financial disposition so no item remains simultaneously active and recorded as removed.</p>\n<h2>Verification and evidence</h2>\n<p>Retain authorization, purchase and shipping records, serial-number and asset matches, inspection checklist, staging access log, baseline configuration, custody transfers, removal approval, sanitization evidence, certificate or credential revocation, carrier receipt, and inventory reconciliation. Protect detailed architecture and secret information from the general shipping record.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-16\" target=\"_blank\" rel=\"noopener noreferrer\">NIST SP 800-53 Release 5.2.0, PE-16 — Delivery and Removal</a> &#8211; National Institute of Standards and Technology; released August 27, 2025</li>\n</ul>",
        "content_text": "Bottom line: a panel or server can bypass normal change control while it is on a loading dock, installer cart, repair bench, or outbound pallet. Physical custody should connect procurement and receiving to configuration, media protection, and final disposition.\nSource fact: NIST addresses authorization and records for component movement\nPE-16 in NIST SP 800-53 Release 5.2.0 calls for authorizing and controlling organization-defined types of system components entering and exiting the facility and maintaining records of those components. Its discussion says enforcing those authorizations may require restricting access to delivery areas and isolating those areas from the system and media libraries.\nFor PACS, the component may contain configuration, credentials, certificates, logs, personal data, or an address that reveals architecture. A replacement can also introduce an unapproved firmware or supply-chain state before anyone enrolls it as an asset.\nSource boundary and applicability\nNIST SP 800-53 is a security and privacy control catalog. PE-16 becomes mandatory only through an applicable authorization, policy, contract, regulation, or tailored control baseline. It does not prescribe one receiving process, inspect a specific product, or replace media-sanitization, procurement, hazardous-material, shipping, or evidence rules.\nApplicability questions\n\nWhich PACS components contain configuration, keys, logs, identity data, or storage?\nWho may authorize receipt, internal movement, repair shipment, return, and disposal?\nCan deliveries reach operational networks or secure areas before inspection?\nHow are serial number, tamper state, firmware, accessories, and purchase source verified?\nWhat sanitization, evidence hold, license release, or vendor attestation is required before exit?\n\nDSE recommendation: create an inbound and outbound custody gate\nThe following steps are DSE recommendations based on the cited source.\nAt receipt, match purchase order, supplier, model, serial number, packaging or tamper indicators, and destination. Hold components in a controlled staging area until inspection, asset registration, approved firmware and configuration, and network onboarding are complete. Record every person or service that takes custody.\nBefore removal, identify the asset and owner, preserve required logs or evidence, revoke credentials and certificates, release licenses, sanitize storage by approved method, and record destination and carrier. For repair returns, define whether the vendor may access stored data or keys. Reconcile receiving, inventory, PACS configuration, and financial disposition so no item remains simultaneously active and recorded as removed.\nVerification and evidence\nRetain authorization, purchase and shipping records, serial-number and asset matches, inspection checklist, staging access log, baseline configuration, custody transfers, removal approval, sanitization evidence, certificate or credential revocation, carrier receipt, and inventory reconciliation. Protect detailed architecture and secret information from the general shipping record.\nOfficial references\n\nNIST SP 800-53 Release 5.2.0, PE-16 — Delivery and Removal – National Institute of Standards and Technology; released August 27, 2025",
        "content_markdown": "Bottom line: a panel or server can bypass normal change control while it is on a loading dock, installer cart, repair bench, or outbound pallet. Physical custody should connect procurement and receiving to configuration, media protection, and final disposition.\n\n## Source fact: NIST addresses authorization and records for component movement\n\nPE-16 in [NIST SP 800-53 Release 5.2.0](https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-16) calls for authorizing and controlling organization-defined types of system components entering and exiting the facility and maintaining records of those components. Its discussion says enforcing those authorizations may require restricting access to delivery areas and isolating those areas from the system and media libraries.\n\nFor PACS, the component may contain configuration, credentials, certificates, logs, personal data, or an address that reveals architecture. A replacement can also introduce an unapproved firmware or supply-chain state before anyone enrolls it as an asset.\n\n## Source boundary and applicability\n\nNIST SP 800-53 is a security and privacy control catalog. PE-16 becomes mandatory only through an applicable authorization, policy, contract, regulation, or tailored control baseline. It does not prescribe one receiving process, inspect a specific product, or replace media-sanitization, procurement, hazardous-material, shipping, or evidence rules.\n\n## Applicability questions\n\n- Which PACS components contain configuration, keys, logs, identity data, or storage?\n\n- Who may authorize receipt, internal movement, repair shipment, return, and disposal?\n\n- Can deliveries reach operational networks or secure areas before inspection?\n\n- How are serial number, tamper state, firmware, accessories, and purchase source verified?\n\n- What sanitization, evidence hold, license release, or vendor attestation is required before exit?\n\n## DSE recommendation: create an inbound and outbound custody gate\n\nThe following steps are DSE recommendations based on the cited source.\n\nAt receipt, match purchase order, supplier, model, serial number, packaging or tamper indicators, and destination. Hold components in a controlled staging area until inspection, asset registration, approved firmware and configuration, and network onboarding are complete. Record every person or service that takes custody.\n\nBefore removal, identify the asset and owner, preserve required logs or evidence, revoke credentials and certificates, release licenses, sanitize storage by approved method, and record destination and carrier. For repair returns, define whether the vendor may access stored data or keys. Reconcile receiving, inventory, PACS configuration, and financial disposition so no item remains simultaneously active and recorded as removed.\n\n## Verification and evidence\n\nRetain authorization, purchase and shipping records, serial-number and asset matches, inspection checklist, staging access log, baseline configuration, custody transfers, removal approval, sanitization evidence, certificate or credential revocation, carrier receipt, and inventory reconciliation. Protect detailed architecture and secret information from the general shipping record.\n\n## Official references\n\n- [NIST SP 800-53 Release 5.2.0, PE-16 — Delivery and Removal](https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-16) – National Institute of Standards and Technology; released August 27, 2025"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/",
                "url": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Control controllers and servers through receiving and removal",
                        "item": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/#article",
                "identifier": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/",
                "url": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/",
                "headline": "Control controllers and servers through receiving and removal",
                "description": "NIST PE-16 addresses authorization and records for system components entering and leaving a facility. Extend PACS custody to delivery, staging, repair…",
                "abstract": "NIST PE-16 addresses authorization and records for system components entering and leaving a facility. Extend PACS custody to delivery, staging, repair, return, and disposal.",
                "articleBody": "Bottom line: a panel or server can bypass normal change control while it is on a loading dock, installer cart, repair bench, or outbound pallet. Physical custody should connect procurement and receiving to configuration, media protection, and final disposition.\nSource fact: NIST addresses authorization and records for component movement\nPE-16 in NIST SP 800-53 Release 5.2.0 calls for authorizing and controlling organization-defined types of system components entering and exiting the facility and maintaining records of those components. Its discussion says enforcing those authorizations may require restricting access to delivery areas and isolating those areas from the system and media libraries.\nFor PACS, the component may contain configuration, credentials, certificates, logs, personal data, or an address that reveals architecture. A replacement can also introduce an unapproved firmware or supply-chain state before anyone enrolls it as an asset.\nSource boundary and applicability\nNIST SP 800-53 is a security and privacy control catalog. PE-16 becomes mandatory only through an applicable authorization, policy, contract, regulation, or tailored control baseline. It does not prescribe one receiving process, inspect a specific product, or replace media-sanitization, procurement, hazardous-material, shipping, or evidence rules.\nApplicability questions\n\nWhich PACS components contain configuration, keys, logs, identity data, or storage?\nWho may authorize receipt, internal movement, repair shipment, return, and disposal?\nCan deliveries reach operational networks or secure areas before inspection?\nHow are serial number, tamper state, firmware, accessories, and purchase source verified?\nWhat sanitization, evidence hold, license release, or vendor attestation is required before exit?\n\nDSE recommendation: create an inbound and outbound custody gate\nThe following steps are DSE recommendations based on the cited source.\nAt receipt, match purchase order, supplier, model, serial number, packaging or tamper indicators, and destination. Hold components in a controlled staging area until inspection, asset registration, approved firmware and configuration, and network onboarding are complete. Record every person or service that takes custody.\nBefore removal, identify the asset and owner, preserve required logs or evidence, revoke credentials and certificates, release licenses, sanitize storage by approved method, and record destination and carrier. For repair returns, define whether the vendor may access stored data or keys. Reconcile receiving, inventory, PACS configuration, and financial disposition so no item remains simultaneously active and recorded as removed.\nVerification and evidence\nRetain authorization, purchase and shipping records, serial-number and asset matches, inspection checklist, staging access log, baseline configuration, custody transfers, removal approval, sanitization evidence, certificate or credential revocation, carrier receipt, and inventory reconciliation. Protect detailed architecture and secret information from the general shipping record.\nOfficial references\n\nNIST SP 800-53 Release 5.2.0, PE-16 — Delivery and Removal – National Institute of Standards and Technology; released August 27, 2025",
                "datePublished": "2026-08-25T21:35:41+00:00",
                "dateModified": "2026-08-25T21:36:17+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/control-controllers-and-servers-through-receiving-and-removal/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Control controllers and servers through receiving and removal"
                },
                "articleSection": [
                    "Access Control",
                    "Cybersecurity"
                ],
                "keywords": [
                    "Access Control",
                    "Cybersecurity",
                    "Playbook",
                    "Important priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    }
                ],
                "wordCount": 430,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "NIST SP 800-53 Release 5.2.0, PE-16 — Delivery and Removal",
                    "url": "https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-16",
                    "datePublished": "2025-08-27"
                }
            }
        ]
    }
}