What you need to know
NIST PE-16 addresses authorization and records for system components entering and leaving a facility. Extend PACS custody to delivery, staging, repair, return, and disposal.
Potentially affected
Organizations receiving, staging, moving, repairing, returning, or disposing of PACS controllers, servers, enrollment devices, storage, and related components.
DSE recommendation
Require component identity, authorization, custody, inspection, configuration state, data handling, and destination records from receiving through final removal.
Bottom line: a panel or server can bypass normal change control while it is on a loading dock, installer cart, repair bench, or outbound pallet. Physical custody should connect procurement and receiving to configuration, media protection, and final disposition.
Source fact: NIST addresses authorization and records for component movement
PE-16 in NIST SP 800-53 Release 5.2.0 calls for authorizing and controlling organization-defined types of system components entering and exiting the facility and maintaining records of those components. Its discussion says enforcing those authorizations may require restricting access to delivery areas and isolating those areas from the system and media libraries.
For PACS, the component may contain configuration, credentials, certificates, logs, personal data, or an address that reveals architecture. A replacement can also introduce an unapproved firmware or supply-chain state before anyone enrolls it as an asset.
Source boundary and applicability
NIST SP 800-53 is a security and privacy control catalog. PE-16 becomes mandatory only through an applicable authorization, policy, contract, regulation, or tailored control baseline. It does not prescribe one receiving process, inspect a specific product, or replace media-sanitization, procurement, hazardous-material, shipping, or evidence rules.
Applicability questions
- Which PACS components contain configuration, keys, logs, identity data, or storage?
- Who may authorize receipt, internal movement, repair shipment, return, and disposal?
- Can deliveries reach operational networks or secure areas before inspection?
- How are serial number, tamper state, firmware, accessories, and purchase source verified?
- What sanitization, evidence hold, license release, or vendor attestation is required before exit?
DSE recommendation: create an inbound and outbound custody gate
The following steps are DSE recommendations based on the cited source.
At receipt, match purchase order, supplier, model, serial number, packaging or tamper indicators, and destination. Hold components in a controlled staging area until inspection, asset registration, approved firmware and configuration, and network onboarding are complete. Record every person or service that takes custody.
Before removal, identify the asset and owner, preserve required logs or evidence, revoke credentials and certificates, release licenses, sanitize storage by approved method, and record destination and carrier. For repair returns, define whether the vendor may access stored data or keys. Reconcile receiving, inventory, PACS configuration, and financial disposition so no item remains simultaneously active and recorded as removed.
Verification and evidence
Retain authorization, purchase and shipping records, serial-number and asset matches, inspection checklist, staging access log, baseline configuration, custody transfers, removal approval, sanitization evidence, certificate or credential revocation, carrier receipt, and inventory reconciliation. Protect detailed architecture and secret information from the general shipping record.
Official references
- NIST SP 800-53 Release 5.2.0, PE-16 — Delivery and Removal – National Institute of Standards and Technology; released August 27, 2025
Review the official source
NIST SP 800-53 Release 5.2.0, PE-16 — Delivery and Removal · Published August 27, 2025
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE