NIST CSF DE.CM-02 - Physical Environment Monitoring
Monitor the physical environment of computing infrastructure for potentially adverse conditions including environmental threats and physical access anomalies
Where this comes from
Provision: DE.CM-02 - Physical Environment Monitoring
Instrument: NIST Cybersecurity Framework 2.0 (February 2024)
Citation: NIST Cybersecurity Framework 2.0, February 26, 2024, Section DE.CM-02 (Physical Environment Monitoring), Cross-reference: NIST SP 800-53 Rev. 5 PE-1 through PE-20; PE-6 (Monitoring Physical Access)
Text version: CSF 2.0
Who it applies to
It applies when all of these are true:
- Data categories collected — any answer
- Service collects behavioral data
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Implementation or documented process meets the reviewed acceptance criteria; identify the tested version and deployment status separately
- Configure defaults from the assessed source and purpose; do not enable data collection or processing merely because this task exists
- Validate behavior for the assessed actors and use cases, including applicable guest or administrator paths
- UI clearly communicates what the feature does to users
- API returns appropriate error codes when feature blocks an action
Questions people ask
- Does NIST CSF DE.CM-02 - Physical Environment Monitoring apply to my service?
- It applies when Data categories collected — any answer; Service collects behavioral data.
- From when does this apply?
- NIST CSF DE.CM-02 - Physical Environment Monitoring applies from 26 February 2024. Its current status is: in force.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.