- Maintain an authorization list per protected area and treat it like any access list: owned, reviewed on a cadence, pruned at every departure.
- Do not forget the unglamorous spaces — network closets, print and mail areas where CUI lands on paper, equipment cabinets in shared offices.
- Small facilities can meet the intent with keyed locks and a documented key register; the discipline matters more than the badge system.
3.10.1 — Physical access limitation
3.10 Physical Protection · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.
Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.
NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A — Assessing Security Requirements for CUI ↗What this requirement is after
Only authorized people get near the systems: server rooms, network closets, and the operating environments where equipment lives. That takes a current list of who is authorized per area and a physical mechanism — badge, lock, key — that enforces it.
Rev. 3 splits the substance: authorization lists and credentials carry to 03.10.01 Physical Access Authorizations, while the enforcement mechanics live in the consolidated 03.10.07 Physical Access Control.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- Per-area authorization lists with owners and review dates
- The enforcing mechanism — badge-system configuration or a maintained key register
- Access removals traceable to terminations and transfers
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this lands in Rev. 3
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |