Overview

Security Requirements for 03.10.05 Manage Physical Access

Physical access devices include keys, locks, combinations, and card readers.

Assessment GuidanceExamine 0/11

How an assessor determines this requirement is met. Source: CMMC Assessment Guide – Level 2, Version 2.13 (NIST SP 800-171 Rev. 2).

Discussion

Identifying and controlling physical access devices (e.g., locks, badges, key cards) is just as important as monitoring and limiting who is able to physically access certain equipment. Physical access devices are only strong protection if you know who has them and what access they allow. Physical access devices can be managed using manual or automatic processes

such a list of who is assigned what key, or updating the badge access system as personnel change roles.

Examples

  1. Example 1

    You are a facility manager. A team member retired today and returns their company keys to you. The project on which they were working requires access to areas that contain equipment with CUI. You receive the keys, check your electronic records against the serial numbers on the keys to ensure all have been returned, and mark each key returned [c].

Assessment Methods

Examine
The process of reviewing, inspecting, observing, studying, or analyzing assessment objects (e.g., policies, procedures, plans, system designs, mechanisms) to facilitate understanding, achieve clarification, or obtain evidence.Example: An assessor reads the access control policy and inspects system configuration settings to confirm they match.

Not all of the evidence listed is required to meet this requirement — check the items your organization has collected.

Interview
The process of holding discussions with individuals or groups within an organization to facilitate understanding, achieve clarification, or identify the location of evidence.Example: An assessor asks a system administrator to describe how user accounts are approved, reviewed, and disabled.
  • Personnel with physical access control responsibilities
  • Personnel with information security responsibilities
Test
The process of exercising assessment objects (e.g., activities, mechanisms) under specified conditions to compare actual behavior with expected behavior.Example: An assessor attempts to sign in with a disabled account to confirm that access is denied.
  • Organizational processes for physical access control
  • Mechanisms supporting or implementing physical access control
  • Physical access control devices

Potential Assessment Considerations

  • Are lists or inventories of physical access devices maintained (e.g., keys, facility badges, key cards) [a]?
  • Is access to physical access devices limited (e.g., granted to, and accessible only by, authorized individuals) [b]?
  • Are physical access devices managed (e.g., revoking key card access when necessary, changing locks as needed, maintaining access control devices and systems) [c]?

Key References

NIST SP 800-171 Rev. 2 3.10.5FAR Clause 52.204-21 Partial b.1.ix

Evidence

  1. 03.10.05.a

    Physical access devices are identified

  1. 03.10.05.b

    Physical access devices are controlled

  1. 03.10.05.c

    Physical access devices are managed