What you need to know
NIST PE-20 addresses asset monitoring within controlled areas. Apply a proportionate inventory to programmer laptops, encoders, spare panels, and service interfaces.
Potentially affected
Facilities using portable PACS programming laptops, enrollment kits, USB service media, credential encoders, diagnostic devices, or uninstalled spare controllers.
DSE recommendation
Define which PACS assets require internal location and movement records, give each a custodian and approved storage point, and reconcile them after every job.
Bottom line: an access-control programming device or spare panel can be sensitive even when it never leaves the building. Its location, custodian, configuration, and connection history should be known throughout work inside controlled areas.
Source fact: NIST includes tracking movement within controlled areas
PE-20 in NIST SP 800-53 Release 5.2.0 calls for using organization-defined asset-location technologies to track and monitor the location and movement of organization-defined assets within organization-defined controlled areas. Its discussion says organizations consult their Office of the General Counsel and senior agency official for privacy about deployment and use of asset-location technologies and potential privacy concerns.
This internal focus is useful for service tools. A laptop with controller software, an encoder that can issue credentials, or a configured spare can create risk while moving between a shop, panel closet, loading area, and active doorway.
Source boundary and applicability
NIST SP 800-53 is a control catalog, and PE-20 is selected and tailored through the relevant authorization or organizational process. It does not require real-time electronic tracking of every item or every person. Tracking technology can introduce employee privacy, labor, safety, battery, radio, and data-retention concerns that require separate review.
Applicability questions
- Which portable asset can issue credentials, change a controller, reveal architecture, or store sensitive data?
- Is the required record room-level, cabinet-level, job-level, or continuous location?
- Who checks the item out, transports it, supervises use, and returns it?
- Does it contain production keys, cached credentials, logs, or network configuration?
- What privacy, labor, or safety review applies to the chosen tracking method?
DSE recommendation: use risk-based internal custody
The following steps are DSE recommendations based on the cited source.
Define an asset class list based on capability and stored information. Assign unique identity, owner, approved storage location, authorized users, permitted connection targets, and required checkout detail. Use the least intrusive method that creates adequate accountability: a cabinet log may be sufficient for one item, while a high-consequence programmer may require job-based custody and technical connection logging.
Before and after work, reconcile asset, accessories, removable media, configuration, and physical condition. Disable shared local accounts, protect production secrets in an approved vault, and remove cached data not needed for the task. Investigate missing or unexplained movement as a security event under established criteria.
Verification and evidence
Retain the asset-class decision, inventory, custodian and storage assignment, privacy review where relevant, checkout and return logs, job linkage, technical connection records, periodic reconciliation, missing-item exercise, and incident dispositions. Do not create unnecessarily detailed movement histories about people when asset accountability can be achieved with less data.
Official references
- NIST SP 800-53 Release 5.2.0, PE-20 — Asset Monitoring and Tracking – National Institute of Standards and Technology; released August 27, 2025
Review the official source
NIST SP 800-53 Release 5.2.0, PE-20 — Asset Monitoring and Tracking · Published August 27, 2025
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE