{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/recertify-physical-access-from-the-role-owner/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/",
        "slug": "recertify-physical-access-from-the-role-owner",
        "url": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/recertify-physical-access-from-the-role-owner/"
        },
        "title": "Re-certify physical access from the role owner—not from the cardholder list",
        "summary": "A cardholder export shows what the system grants, not what a person still needs. Have accountable role and area owners affirm required access, challenge exceptions, remove stale grants, and verify the controller received the change.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-17T13:10:00+00:00",
        "modified_at": "2026-08-17T19:22:09+00:00",
        "reviewed_on": "2026-08-17",
        "reading_minutes": 3,
        "word_count": 636,
        "potentially_affected": "Employees, contractors, visitors with recurring access, badges and mobile credentials, access levels, schedules, door groups, sensitive areas, HR and vendor lifecycle events, physical keys used as exceptions, PACS integrations, and audit evidence.",
        "dse_recommendation": "Build a complete identity-to-access inventory, route each grant to the accountable role and area owners with business context, expire or remove unsupported access, reconcile changes to field panels and exceptions, and retain evidence of decision and verification.",
        "primary_source": {
            "name": "NIST SP 800-53 Revision 5.1: Security and Privacy Controls for Information Systems and Organizations",
            "url": "https://csrc.nist.gov/CSRC/media/Projects/risk-management/800-53%20Downloads/800-53r5/SP_800-53_v5_1-derived-OSCAL.pdf",
            "published_on": null,
            "authority": "National Institute of Standards and Technology"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts: authorization lists are meant to be maintained and reviewed</h2>\n<p><a href=\"https://csrc.nist.gov/CSRC/media/Projects/risk-management/800-53%20Downloads/800-53r5/SP_800-53_v5_1-derived-OSCAL.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">NIST Special Publication 800-53 Revision 5.1</a>, control PE-2, calls for developing, approving, and maintaining a list of individuals authorized for physical access, issuing authorization credentials, reviewing the list at an organization-defined frequency, and removing people when access is no longer required. Its first enhancement addresses authorization based on position or role.</p>\n<p>CISA’s <a href=\"https://www.cisa.gov/sites/default/files/2025-02/Facility%20Access%20Control%20-%20An%20Interagency%20Security%20Committee%20Best%20Practice-02-20.pdf\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Facility Access Control: An Interagency Security Committee Best Practice</em></a> discusses the access-control process for federal facilities, including employees, visitors, screening, authentication, and physical access control systems. It stresses that risk and operations shape the selected controls.</p>\n<p>Both publications are U.S. federal guidance. They do not automatically impose a particular review interval or access model on a private organization. Applicable law, regulation, contract, collective bargaining, safety needs, building rules, and the organization’s risk decisions govern. The DSE process below is an operational recommendation, not a compliance determination.</p>\n\n<h2>DSE recommendation: make need the input and system state the verified output</h2>\n<p>Do not send managers a raw list of badge numbers and ask whether it “looks right.” Build a review package around people and work. For each identity, show employer or sponsor, status, role, home location, supervisor, contract end date, credential type, access levels, schedules, sensitive doors, last relevant use where lawful, and exceptions. Separate reliable source data from unresolved mismatches.</p>\n<ol>\n<li><strong>Define ownership.</strong> The manager or contract sponsor confirms that the person still requires access for assigned work. The area owner confirms that the role may enter the protected space. Security administers the system but should not invent the business need.</li>\n<li><strong>Review roles before people.</strong> Validate what each standard role should receive, including schedules and holidays. Removing obsolete doors from a role can correct many cardholders consistently. Keep high-risk and emergency roles narrow and named.</li>\n<li><strong>Challenge direct grants.</strong> Identify access outside a standard role, 24-hour schedules, broad master groups, temporary projects, transferred staff, dormant credentials, duplicate identities, indefinite contractors, and people whose manager or sponsor is missing. Require a reason, owner, and expiry.</li>\n<li><strong>Resolve lifecycle conflicts.</strong> Reconcile HR, contractor, training, licensing, safety, tenant, and PACS records. A person marked active in one system may have changed role or site in another. Escalate discrepancies rather than silently choosing the most permissive state.</li>\n<li><strong>Apply with control.</strong> Use approved change records, second review for sensitive areas, and a defined emergency-access path. Consider safety and continuity before mass removal. Do not use access history alone to revoke a grant that is legitimately needed only during rare events.</li>\n<li><strong>Verify the field result.</strong> Confirm removed access is absent from the credential, access level, downstream controller or lock, mobile credential service, visitor platform, and documented physical-key exception. Sample denied transactions or use an approved test credential without inconveniencing occupants.</li>\n</ol>\n<p>Track completion by decision quality, not by percentage of emails answered. An approval with no accountable owner, “keep all,” or an unresolved system mismatch is not complete. Age outstanding reviews, suspend or escalate according to policy, and give security leadership a view of unsupported high-risk access.</p>\n<p>Retain the reviewed population, data cutoff, decisions, approvers, changes, verification, unresolved exceptions, and next due date. Protect the review package because it maps people to secured areas. The result should answer two different questions with evidence: why the person needs entry, and whether the deployed system now enforces that approved need.</p>\n<p>Measure unsupported direct grants, overdue decisions, identities without sponsors, expired contractors still enabled, failed controller updates, and high-risk exceptions by age. Stop a review wave when source data is materially incomplete or the change pipeline cannot verify removals. Fix the data or deployment control first; a fast attestation on an unreliable population creates false assurance.</p>\n\n<h2>Official references</h2>\n<ul>\n<li>National Institute of Standards and Technology, <a href=\"https://csrc.nist.gov/CSRC/media/Projects/risk-management/800-53%20Downloads/800-53r5/SP_800-53_v5_1-derived-OSCAL.pdf\" target=\"_blank\" rel=\"noopener noreferrer\"><em>SP 800-53 Revision 5.1</em></a>, PE-2 Physical Access Authorizations.</li>\n<li>Cybersecurity and Infrastructure Security Agency, Interagency Security Committee, <a href=\"https://www.cisa.gov/sites/default/files/2025-02/Facility%20Access%20Control%20-%20An%20Interagency%20Security%20Committee%20Best%20Practice-02-20.pdf\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Facility Access Control: An ISC Best Practice</em></a>.</li>\n</ul>",
        "content_text": "Source facts: authorization lists are meant to be maintained and reviewed\nNIST Special Publication 800-53 Revision 5.1, control PE-2, calls for developing, approving, and maintaining a list of individuals authorized for physical access, issuing authorization credentials, reviewing the list at an organization-defined frequency, and removing people when access is no longer required. Its first enhancement addresses authorization based on position or role.\nCISA’s Facility Access Control: An Interagency Security Committee Best Practice discusses the access-control process for federal facilities, including employees, visitors, screening, authentication, and physical access control systems. It stresses that risk and operations shape the selected controls.\nBoth publications are U.S. federal guidance. They do not automatically impose a particular review interval or access model on a private organization. Applicable law, regulation, contract, collective bargaining, safety needs, building rules, and the organization’s risk decisions govern. The DSE process below is an operational recommendation, not a compliance determination.\n\nDSE recommendation: make need the input and system state the verified output\nDo not send managers a raw list of badge numbers and ask whether it “looks right.” Build a review package around people and work. For each identity, show employer or sponsor, status, role, home location, supervisor, contract end date, credential type, access levels, schedules, sensitive doors, last relevant use where lawful, and exceptions. Separate reliable source data from unresolved mismatches.\n\nDefine ownership. The manager or contract sponsor confirms that the person still requires access for assigned work. The area owner confirms that the role may enter the protected space. Security administers the system but should not invent the business need.\nReview roles before people. Validate what each standard role should receive, including schedules and holidays. Removing obsolete doors from a role can correct many cardholders consistently. Keep high-risk and emergency roles narrow and named.\nChallenge direct grants. Identify access outside a standard role, 24-hour schedules, broad master groups, temporary projects, transferred staff, dormant credentials, duplicate identities, indefinite contractors, and people whose manager or sponsor is missing. Require a reason, owner, and expiry.\nResolve lifecycle conflicts. Reconcile HR, contractor, training, licensing, safety, tenant, and PACS records. A person marked active in one system may have changed role or site in another. Escalate discrepancies rather than silently choosing the most permissive state.\nApply with control. Use approved change records, second review for sensitive areas, and a defined emergency-access path. Consider safety and continuity before mass removal. Do not use access history alone to revoke a grant that is legitimately needed only during rare events.\nVerify the field result. Confirm removed access is absent from the credential, access level, downstream controller or lock, mobile credential service, visitor platform, and documented physical-key exception. Sample denied transactions or use an approved test credential without inconveniencing occupants.\n\nTrack completion by decision quality, not by percentage of emails answered. An approval with no accountable owner, “keep all,” or an unresolved system mismatch is not complete. Age outstanding reviews, suspend or escalate according to policy, and give security leadership a view of unsupported high-risk access.\nRetain the reviewed population, data cutoff, decisions, approvers, changes, verification, unresolved exceptions, and next due date. Protect the review package because it maps people to secured areas. The result should answer two different questions with evidence: why the person needs entry, and whether the deployed system now enforces that approved need.\nMeasure unsupported direct grants, overdue decisions, identities without sponsors, expired contractors still enabled, failed controller updates, and high-risk exceptions by age. Stop a review wave when source data is materially incomplete or the change pipeline cannot verify removals. Fix the data or deployment control first; a fast attestation on an unreliable population creates false assurance.\n\nOfficial references\n\nNational Institute of Standards and Technology, SP 800-53 Revision 5.1, PE-2 Physical Access Authorizations.\nCybersecurity and Infrastructure Security Agency, Interagency Security Committee, Facility Access Control: An ISC Best Practice.",
        "content_markdown": "## Source facts: authorization lists are meant to be maintained and reviewed\n\n[NIST Special Publication 800-53 Revision 5.1](https://csrc.nist.gov/CSRC/media/Projects/risk-management/800-53%20Downloads/800-53r5/SP_800-53_v5_1-derived-OSCAL.pdf), control PE-2, calls for developing, approving, and maintaining a list of individuals authorized for physical access, issuing authorization credentials, reviewing the list at an organization-defined frequency, and removing people when access is no longer required. Its first enhancement addresses authorization based on position or role.\n\nCISA’s [Facility Access Control: An Interagency Security Committee Best Practice](https://www.cisa.gov/sites/default/files/2025-02/Facility%20Access%20Control%20-%20An%20Interagency%20Security%20Committee%20Best%20Practice-02-20.pdf) discusses the access-control process for federal facilities, including employees, visitors, screening, authentication, and physical access control systems. It stresses that risk and operations shape the selected controls.\n\nBoth publications are U.S. federal guidance. They do not automatically impose a particular review interval or access model on a private organization. Applicable law, regulation, contract, collective bargaining, safety needs, building rules, and the organization’s risk decisions govern. The DSE process below is an operational recommendation, not a compliance determination.\n\n## DSE recommendation: make need the input and system state the verified output\n\nDo not send managers a raw list of badge numbers and ask whether it “looks right.” Build a review package around people and work. For each identity, show employer or sponsor, status, role, home location, supervisor, contract end date, credential type, access levels, schedules, sensitive doors, last relevant use where lawful, and exceptions. Separate reliable source data from unresolved mismatches.\n\n- Define ownership. The manager or contract sponsor confirms that the person still requires access for assigned work. The area owner confirms that the role may enter the protected space. Security administers the system but should not invent the business need.\n\n- Review roles before people. Validate what each standard role should receive, including schedules and holidays. Removing obsolete doors from a role can correct many cardholders consistently. Keep high-risk and emergency roles narrow and named.\n\n- Challenge direct grants. Identify access outside a standard role, 24-hour schedules, broad master groups, temporary projects, transferred staff, dormant credentials, duplicate identities, indefinite contractors, and people whose manager or sponsor is missing. Require a reason, owner, and expiry.\n\n- Resolve lifecycle conflicts. Reconcile HR, contractor, training, licensing, safety, tenant, and PACS records. A person marked active in one system may have changed role or site in another. Escalate discrepancies rather than silently choosing the most permissive state.\n\n- Apply with control. Use approved change records, second review for sensitive areas, and a defined emergency-access path. Consider safety and continuity before mass removal. Do not use access history alone to revoke a grant that is legitimately needed only during rare events.\n\n- Verify the field result. Confirm removed access is absent from the credential, access level, downstream controller or lock, mobile credential service, visitor platform, and documented physical-key exception. Sample denied transactions or use an approved test credential without inconveniencing occupants.\n\nTrack completion by decision quality, not by percentage of emails answered. An approval with no accountable owner, “keep all,” or an unresolved system mismatch is not complete. Age outstanding reviews, suspend or escalate according to policy, and give security leadership a view of unsupported high-risk access.\n\nRetain the reviewed population, data cutoff, decisions, approvers, changes, verification, unresolved exceptions, and next due date. Protect the review package because it maps people to secured areas. The result should answer two different questions with evidence: why the person needs entry, and whether the deployed system now enforces that approved need.\n\nMeasure unsupported direct grants, overdue decisions, identities without sponsors, expired contractors still enabled, failed controller updates, and high-risk exceptions by age. Stop a review wave when source data is materially incomplete or the change pipeline cannot verify removals. Fix the data or deployment control first; a fast attestation on an unreliable population creates false assurance.\n\n## Official references\n\n- National Institute of Standards and Technology, [SP 800-53 Revision 5.1](https://csrc.nist.gov/CSRC/media/Projects/risk-management/800-53%20Downloads/800-53r5/SP_800-53_v5_1-derived-OSCAL.pdf), PE-2 Physical Access Authorizations.\n\n- Cybersecurity and Infrastructure Security Agency, Interagency Security Committee, [Facility Access Control: An ISC Best Practice](https://www.cisa.gov/sites/default/files/2025-02/Facility%20Access%20Control%20-%20An%20Interagency%20Security%20Committee%20Best%20Practice-02-20.pdf)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/",
                "url": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-17"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Re-certify physical access from the role owner—not from the cardholder list",
                        "item": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/#article",
                "identifier": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/",
                "url": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/",
                "headline": "Re-certify physical access from the role owner—not from the cardholder list",
                "description": "A cardholder export shows what the system grants, not what a person still needs. Have accountable role and area owners affirm required access…",
                "abstract": "A cardholder export shows what the system grants, not what a person still needs. Have accountable role and area owners affirm required access, challenge exceptions, remove stale grants, and verify the controller received the change.",
                "articleBody": "Source facts: authorization lists are meant to be maintained and reviewed\nNIST Special Publication 800-53 Revision 5.1, control PE-2, calls for developing, approving, and maintaining a list of individuals authorized for physical access, issuing authorization credentials, reviewing the list at an organization-defined frequency, and removing people when access is no longer required. Its first enhancement addresses authorization based on position or role.\nCISA’s Facility Access Control: An Interagency Security Committee Best Practice discusses the access-control process for federal facilities, including employees, visitors, screening, authentication, and physical access control systems. It stresses that risk and operations shape the selected controls.\nBoth publications are U.S. federal guidance. They do not automatically impose a particular review interval or access model on a private organization. Applicable law, regulation, contract, collective bargaining, safety needs, building rules, and the organization’s risk decisions govern. The DSE process below is an operational recommendation, not a compliance determination.\n\nDSE recommendation: make need the input and system state the verified output\nDo not send managers a raw list of badge numbers and ask whether it “looks right.” Build a review package around people and work. For each identity, show employer or sponsor, status, role, home location, supervisor, contract end date, credential type, access levels, schedules, sensitive doors, last relevant use where lawful, and exceptions. Separate reliable source data from unresolved mismatches.\n\nDefine ownership. The manager or contract sponsor confirms that the person still requires access for assigned work. The area owner confirms that the role may enter the protected space. Security administers the system but should not invent the business need.\nReview roles before people. Validate what each standard role should receive, including schedules and holidays. Removing obsolete doors from a role can correct many cardholders consistently. Keep high-risk and emergency roles narrow and named.\nChallenge direct grants. Identify access outside a standard role, 24-hour schedules, broad master groups, temporary projects, transferred staff, dormant credentials, duplicate identities, indefinite contractors, and people whose manager or sponsor is missing. Require a reason, owner, and expiry.\nResolve lifecycle conflicts. Reconcile HR, contractor, training, licensing, safety, tenant, and PACS records. A person marked active in one system may have changed role or site in another. Escalate discrepancies rather than silently choosing the most permissive state.\nApply with control. Use approved change records, second review for sensitive areas, and a defined emergency-access path. Consider safety and continuity before mass removal. Do not use access history alone to revoke a grant that is legitimately needed only during rare events.\nVerify the field result. Confirm removed access is absent from the credential, access level, downstream controller or lock, mobile credential service, visitor platform, and documented physical-key exception. Sample denied transactions or use an approved test credential without inconveniencing occupants.\n\nTrack completion by decision quality, not by percentage of emails answered. An approval with no accountable owner, “keep all,” or an unresolved system mismatch is not complete. Age outstanding reviews, suspend or escalate according to policy, and give security leadership a view of unsupported high-risk access.\nRetain the reviewed population, data cutoff, decisions, approvers, changes, verification, unresolved exceptions, and next due date. Protect the review package because it maps people to secured areas. The result should answer two different questions with evidence: why the person needs entry, and whether the deployed system now enforces that approved need.\nMeasure unsupported direct grants, overdue decisions, identities without sponsors, expired contractors still enabled, failed controller updates, and high-risk exceptions by age. Stop a review wave when source data is materially incomplete or the change pipeline cannot verify removals. Fix the data or deployment control first; a fast attestation on an unreliable population creates false assurance.\n\nOfficial references\n\nNational Institute of Standards and Technology, SP 800-53 Revision 5.1, PE-2 Physical Access Authorizations.\nCybersecurity and Infrastructure Security Agency, Interagency Security Committee, Facility Access Control: An ISC Best Practice.",
                "datePublished": "2026-08-17T13:10:00+00:00",
                "dateModified": "2026-08-17T19:22:09+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/recertify-physical-access-from-the-role-owner/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Re-certify physical access from the role owner—not from the cardholder list"
                },
                "articleSection": [
                    "Access Control",
                    "Cybersecurity"
                ],
                "keywords": [
                    "Access Control",
                    "Cybersecurity",
                    "Playbook",
                    "Advisory priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    }
                ],
                "wordCount": 636,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "NIST SP 800-53 Revision 5.1: Security and Privacy Controls for Information Systems and Organizations",
                    "url": "https://csrc.nist.gov/CSRC/media/Projects/risk-management/800-53%20Downloads/800-53r5/SP_800-53_v5_1-derived-OSCAL.pdf"
                }
            }
        ]
    }
}