{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/place-access-control-components-away-from-hazards-and-public-reach/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/",
        "slug": "place-access-control-components-away-from-hazards-and-public-reach",
        "url": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/place-access-control-components-away-from-hazards-and-public-reach/"
        },
        "title": "Place access-control components away from hazards and public reach",
        "summary": "NIST PE-18 calls for positioning system components to reduce physical and environmental hazards and unauthorized access. Apply that lens to PACS panels, power, and interfaces.",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            },
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:35:43+00:00",
        "modified_at": "2026-08-25T21:36:17+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 2,
        "word_count": 420,
        "potentially_affected": "Access-control panels, power supplies, network switches, interfaces, door controllers, enrollment stations, and service ports installed in exposed or hazardous locations.",
        "dse_recommendation": "Survey component placement for public reach, water, heat, impact, service access, and utility hazards, then relocate or protect equipment using approved design and change control.",
        "primary_source": {
            "name": "NIST SP 800-53 Release 5.2.0, PE-18 — Location of System Components",
            "url": "https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-18",
            "published_on": "2025-08-27",
            "authority": "National Institute of Standards and Technology"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> a locked controller cabinet can still be poorly placed. Water piping, public ceilings, vehicle impact, heat, dust, shared tenant space, or an accessible disconnect can defeat availability or allow tampering before a door alarm is ever generated.</p>\n<h2>Source fact: NIST addresses component location as a protection decision</h2>\n<p>PE-18 in <a href=\"https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-18\" target=\"_blank\" rel=\"noopener noreferrer\">NIST SP 800-53 Release 5.2.0</a> calls for positioning system components within a facility to minimize potential damage from physical and environmental hazards and to minimize opportunities for unauthorized access. The control is broad enough to include computing and supporting components, not merely user workstations.</p>\n<p>Applied to PACS, placement affects both security and continuity. A controller above a publicly accessible ceiling, below a leak source, or beside an unprotected power cutoff can convert a local condition into multiple uncontrolled doors.</p>\n<h2>Source boundary and applicability</h2>\n<p>NIST SP 800-53 is a control catalog. Whether PE-18 is mandatory, selected, tailored, or used as guidance depends on the organization&#8217;s authorization framework, contract, regulation, and system boundary. It does not provide a universal mounting location, enclosure rating, flood elevation, fire requirement, or code approval. Qualified design disciplines and local requirements remain necessary.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>Which doors and functions fail if this panel, power supply, switch, or interface is damaged?</li>\n<li>Can the public, tenants, vendors, or unescorted staff reach the equipment or its cables?</li>\n<li>Are water, condensation, temperature, dust, vibration, impact, or electromagnetic hazards present?</li>\n<li>Is service access safe, observable, and possible without defeating another control?</li>\n<li>Do enclosure, battery, ventilation, fire, and accessibility requirements constrain relocation?</li>\n</ul>\n<h2>DSE recommendation: add placement risk to panel acceptance</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<p>Create an inventory with component location, controlled doors, power and network dependencies, enclosure, access population, environmental conditions, nearby utilities, and failure consequence. Inspect above and below the equipment, trace accessible cable and disconnect paths, and consider credible maintenance and building events. Rank deficiencies by the number and importance of affected openings.</p>\n<p>Use relocation, rated enclosure, barriers, leak protection, protected power, tamper monitoring, or procedural control only after responsible facilities, security, electrical, fire, and accessibility owners approve the design. Do not place batteries or energized equipment in a sealed or unlisted arrangement.</p>\n<h2>Verification and evidence</h2>\n<p>Retain the component inventory, sanitized plans, photographs, environmental and access observations, manufacturer installation requirements, approved risk treatment, change ticket, tamper and power-loss tests, and inspection cadence. Reassess after renovations, tenant changes, utility work, leaks, impacts, or repeated faults.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-18\" target=\"_blank\" rel=\"noopener noreferrer\">NIST SP 800-53 Release 5.2.0, PE-18 — Location of System Components</a> &#8211; National Institute of Standards and Technology; released August 27, 2025</li>\n</ul>",
        "content_text": "Bottom line: a locked controller cabinet can still be poorly placed. Water piping, public ceilings, vehicle impact, heat, dust, shared tenant space, or an accessible disconnect can defeat availability or allow tampering before a door alarm is ever generated.\nSource fact: NIST addresses component location as a protection decision\nPE-18 in NIST SP 800-53 Release 5.2.0 calls for positioning system components within a facility to minimize potential damage from physical and environmental hazards and to minimize opportunities for unauthorized access. The control is broad enough to include computing and supporting components, not merely user workstations.\nApplied to PACS, placement affects both security and continuity. A controller above a publicly accessible ceiling, below a leak source, or beside an unprotected power cutoff can convert a local condition into multiple uncontrolled doors.\nSource boundary and applicability\nNIST SP 800-53 is a control catalog. Whether PE-18 is mandatory, selected, tailored, or used as guidance depends on the organization’s authorization framework, contract, regulation, and system boundary. It does not provide a universal mounting location, enclosure rating, flood elevation, fire requirement, or code approval. Qualified design disciplines and local requirements remain necessary.\nApplicability questions\n\nWhich doors and functions fail if this panel, power supply, switch, or interface is damaged?\nCan the public, tenants, vendors, or unescorted staff reach the equipment or its cables?\nAre water, condensation, temperature, dust, vibration, impact, or electromagnetic hazards present?\nIs service access safe, observable, and possible without defeating another control?\nDo enclosure, battery, ventilation, fire, and accessibility requirements constrain relocation?\n\nDSE recommendation: add placement risk to panel acceptance\nThe following steps are DSE recommendations based on the cited source.\nCreate an inventory with component location, controlled doors, power and network dependencies, enclosure, access population, environmental conditions, nearby utilities, and failure consequence. Inspect above and below the equipment, trace accessible cable and disconnect paths, and consider credible maintenance and building events. Rank deficiencies by the number and importance of affected openings.\nUse relocation, rated enclosure, barriers, leak protection, protected power, tamper monitoring, or procedural control only after responsible facilities, security, electrical, fire, and accessibility owners approve the design. Do not place batteries or energized equipment in a sealed or unlisted arrangement.\nVerification and evidence\nRetain the component inventory, sanitized plans, photographs, environmental and access observations, manufacturer installation requirements, approved risk treatment, change ticket, tamper and power-loss tests, and inspection cadence. Reassess after renovations, tenant changes, utility work, leaks, impacts, or repeated faults.\nOfficial references\n\nNIST SP 800-53 Release 5.2.0, PE-18 — Location of System Components – National Institute of Standards and Technology; released August 27, 2025",
        "content_markdown": "Bottom line: a locked controller cabinet can still be poorly placed. Water piping, public ceilings, vehicle impact, heat, dust, shared tenant space, or an accessible disconnect can defeat availability or allow tampering before a door alarm is ever generated.\n\n## Source fact: NIST addresses component location as a protection decision\n\nPE-18 in [NIST SP 800-53 Release 5.2.0](https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-18) calls for positioning system components within a facility to minimize potential damage from physical and environmental hazards and to minimize opportunities for unauthorized access. The control is broad enough to include computing and supporting components, not merely user workstations.\n\nApplied to PACS, placement affects both security and continuity. A controller above a publicly accessible ceiling, below a leak source, or beside an unprotected power cutoff can convert a local condition into multiple uncontrolled doors.\n\n## Source boundary and applicability\n\nNIST SP 800-53 is a control catalog. Whether PE-18 is mandatory, selected, tailored, or used as guidance depends on the organization’s authorization framework, contract, regulation, and system boundary. It does not provide a universal mounting location, enclosure rating, flood elevation, fire requirement, or code approval. Qualified design disciplines and local requirements remain necessary.\n\n## Applicability questions\n\n- Which doors and functions fail if this panel, power supply, switch, or interface is damaged?\n\n- Can the public, tenants, vendors, or unescorted staff reach the equipment or its cables?\n\n- Are water, condensation, temperature, dust, vibration, impact, or electromagnetic hazards present?\n\n- Is service access safe, observable, and possible without defeating another control?\n\n- Do enclosure, battery, ventilation, fire, and accessibility requirements constrain relocation?\n\n## DSE recommendation: add placement risk to panel acceptance\n\nThe following steps are DSE recommendations based on the cited source.\n\nCreate an inventory with component location, controlled doors, power and network dependencies, enclosure, access population, environmental conditions, nearby utilities, and failure consequence. Inspect above and below the equipment, trace accessible cable and disconnect paths, and consider credible maintenance and building events. Rank deficiencies by the number and importance of affected openings.\n\nUse relocation, rated enclosure, barriers, leak protection, protected power, tamper monitoring, or procedural control only after responsible facilities, security, electrical, fire, and accessibility owners approve the design. Do not place batteries or energized equipment in a sealed or unlisted arrangement.\n\n## Verification and evidence\n\nRetain the component inventory, sanitized plans, photographs, environmental and access observations, manufacturer installation requirements, approved risk treatment, change ticket, tamper and power-loss tests, and inspection cadence. Reassess after renovations, tenant changes, utility work, leaks, impacts, or repeated faults.\n\n## Official references\n\n- [NIST SP 800-53 Release 5.2.0, PE-18 — Location of System Components](https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-18) – National Institute of Standards and Technology; released August 27, 2025"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/",
                "url": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Place access-control components away from hazards and public reach",
                        "item": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/#article",
                "identifier": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/",
                "url": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/",
                "headline": "Place access-control components away from hazards and public reach",
                "description": "NIST PE-18 calls for positioning system components to reduce physical and environmental hazards and unauthorized access. Apply that lens to PACS…",
                "abstract": "NIST PE-18 calls for positioning system components to reduce physical and environmental hazards and unauthorized access. Apply that lens to PACS panels, power, and interfaces.",
                "articleBody": "Bottom line: a locked controller cabinet can still be poorly placed. Water piping, public ceilings, vehicle impact, heat, dust, shared tenant space, or an accessible disconnect can defeat availability or allow tampering before a door alarm is ever generated.\nSource fact: NIST addresses component location as a protection decision\nPE-18 in NIST SP 800-53 Release 5.2.0 calls for positioning system components within a facility to minimize potential damage from physical and environmental hazards and to minimize opportunities for unauthorized access. The control is broad enough to include computing and supporting components, not merely user workstations.\nApplied to PACS, placement affects both security and continuity. A controller above a publicly accessible ceiling, below a leak source, or beside an unprotected power cutoff can convert a local condition into multiple uncontrolled doors.\nSource boundary and applicability\nNIST SP 800-53 is a control catalog. Whether PE-18 is mandatory, selected, tailored, or used as guidance depends on the organization’s authorization framework, contract, regulation, and system boundary. It does not provide a universal mounting location, enclosure rating, flood elevation, fire requirement, or code approval. Qualified design disciplines and local requirements remain necessary.\nApplicability questions\n\nWhich doors and functions fail if this panel, power supply, switch, or interface is damaged?\nCan the public, tenants, vendors, or unescorted staff reach the equipment or its cables?\nAre water, condensation, temperature, dust, vibration, impact, or electromagnetic hazards present?\nIs service access safe, observable, and possible without defeating another control?\nDo enclosure, battery, ventilation, fire, and accessibility requirements constrain relocation?\n\nDSE recommendation: add placement risk to panel acceptance\nThe following steps are DSE recommendations based on the cited source.\nCreate an inventory with component location, controlled doors, power and network dependencies, enclosure, access population, environmental conditions, nearby utilities, and failure consequence. Inspect above and below the equipment, trace accessible cable and disconnect paths, and consider credible maintenance and building events. Rank deficiencies by the number and importance of affected openings.\nUse relocation, rated enclosure, barriers, leak protection, protected power, tamper monitoring, or procedural control only after responsible facilities, security, electrical, fire, and accessibility owners approve the design. Do not place batteries or energized equipment in a sealed or unlisted arrangement.\nVerification and evidence\nRetain the component inventory, sanitized plans, photographs, environmental and access observations, manufacturer installation requirements, approved risk treatment, change ticket, tamper and power-loss tests, and inspection cadence. Reassess after renovations, tenant changes, utility work, leaks, impacts, or repeated faults.\nOfficial references\n\nNIST SP 800-53 Release 5.2.0, PE-18 — Location of System Components – National Institute of Standards and Technology; released August 27, 2025",
                "datePublished": "2026-08-25T21:35:43+00:00",
                "dateModified": "2026-08-25T21:36:17+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/place-access-control-components-away-from-hazards-and-public-reach/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Place access-control components away from hazards and public reach"
                },
                "articleSection": [
                    "Access Control",
                    "Business Continuity",
                    "Cybersecurity"
                ],
                "keywords": [
                    "Access Control",
                    "Business Continuity",
                    "Cybersecurity",
                    "Checklist",
                    "Important priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    }
                ],
                "wordCount": 420,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "NIST SP 800-53 Release 5.2.0, PE-18 — Location of System Components",
                    "url": "https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home?element=PE-18",
                    "datePublished": "2025-08-27"
                }
            }
        ]
    }
}