- Match the mechanism to the facility — badge readers in one building, a locked door with a signed key log in another; the requirement is enforcement, not any particular technology.
- Run visitor handling as a procedure: sign-in, badge, named escort, defined areas — including vendor technicians on the production floor.
- Inventory keys, combinations, and badges, and re-key or re-code when one goes missing or its holder departs.
03.10.07 — Physical Access Control
03.10 Physical Protection · NIST SP 800-171 Rev. 3
Requires enforcing physical access authorizations at organization-defined entry and exit points by verifying individual authorizations and controlling ingress and egress; maintaining physical access audit logs; escorting visitors and controlling visitor activity in organization-defined circumstances; and securing keys, combinations, and other physical access devices.
Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.
NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI ↗What this requirement is after
This is the operating half of physical protection: doors actually check the list from 03.10.01, entries get logged, visitors are escorted rather than wandering, and the keys and codes that open everything are themselves accounted for.
Consolidates three Rev. 2 requirements — visitor escort and monitoring (3.10.3), physical access logs (3.10.4), and physical access device management (3.10.5) — into a single Physical Access Control requirement, with entry/exit points and visitor-escort circumstances as organization-defined parameters.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- Physical access logs for the defined entry and exit points
- Visitor logs with escort assignments
- The key and access-device register with loss-handling records
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this came from in Rev. 2
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |