CMMC v2.11 Practices

PE.L2-3.10.4  

Reference: CMMC v2.11

Family: PE

Level Introduced: 2

Title: Physical Access Logs [CUI Data]

Practice:
Maintain audit logs of physical access.

Further Discussion:
Make sure you have a record of who accesses your facility (e.g., office, plant, factory). You can do this in writing by having employees and visitors sign in and sign out or by electronic means such as badge readers. Whatever means you use, you need to retain the access records for the time period that your company has defined.

Example
You and your coworkers like to have friends and family join you for lunch at the office on Fridays. Your small company has just signed a contract with the DoD, however, and you now need to document who enters and leaves your facility. You work with the reception staff to ensure that all non-employees sign in at the reception area and sign out when they leave [a]. You retain those paper sign-in sheets in a locked filing cabinet for one year. Employees receive badges or key cards that enable tracking and logging access to company facilities.

Potential Assessment Considerations
• Are logs of physical access to sensitive areas (both authorized access and visitor access) maintained per retention requirements [a]?
• Are visitor access records retained for as long as required [a]?

This is for registered users only. Please sign up for a free account, or Login, to see complete cross references to other standards and frameworks.

This is for registered users only. Please sign up for a free account, or Login, to see complete cross references to other standards and frameworks.

Source: CMMC v2.11