1Overview
PE.L2-3.10.2 is the family's second five-point requirement and it adds protection and monitoring of the facility itself. It requires that the physical facility and the support infrastructure for organizational systems be both protected and monitored, so that the building and the utilities the systems depend on are safeguarded and watched. It is a five-point requirement that cannot be deferred on a plan of action.
Systems depend not just on their own security but on the facility around them and the infrastructure that supports them, the power, cooling, cabling, and communications lines that keep them running. This control requires two things applied to both the facility and that support infrastructure: protection, so they are safeguarded against harm, and monitoring, so problems or intrusions are detected. Protecting the facility without monitoring it leaves incidents unseen; monitoring without protection leaves the facility vulnerable. Its five-point weight reflects that the facility and its infrastructure underpin everything the systems do.
Protect and monitor the physical facility and support infrastructure for organizational systems.
The requirement pairs protection and monitoring across two subjects: the physical facility where systems reside, and the support infrastructure they depend on. Protection means safeguards such as secured entry and environmental controls; monitoring means the facility and infrastructure are watched, through surveillance, alarms, or oversight, so that intrusions or failures are noticed. The four assessment objectives correspond to protecting and monitoring each of the facility and the support infrastructure.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.10.2 into four objectives: protect and monitor the facility, and protect and monitor the support infrastructure.
The physical facility where organizational systems reside is protected. The building housing systems is safeguarded.
The support infrastructure for organizational systems is protected. Power, cabling, and utilities are safeguarded.
The physical facility where organizational systems reside is monitored. The building is watched for problems and intrusions.
The support infrastructure for organizational systems is monitored. The utilities the systems depend on are watched.
The four objectives pair protection and monitoring across facility and infrastructure. The common gap is at objectives [c] and [d], monitoring, where the facility is protected but not actually watched, so an intrusion or failure is discovered only after the fact. The assessor looks for both protection and monitoring across both subjects.
3Failure Patterns
The failures are about facilities or infrastructure that are protected but not watched, or watched but not protected.
Protection without monitoring
A secured facility with no surveillance or oversight means intrusions and failures go unseen until damage is done. Monitoring the facility completes the protection.
Support infrastructure overlooked
Focusing on the systems while leaving power, cabling, and utilities exposed leaves the infrastructure they depend on vulnerable. Protecting and monitoring the support infrastructure is required alongside the facility.
Monitoring not acted on
Monitoring that produces alerts no one reviews is monitoring in name only. The facility and infrastructure have to be genuinely watched.
4Ownership
This is a facilities-owned control with security oversight.
| Role | Responsibility for this control |
|---|---|
| Facilities and security | Protects and monitors the facility and support infrastructure. Owns the physical protection and monitoring evidence. |
| IT and system administrator | Identifies the support infrastructure the systems depend on. |
| Security or compliance lead | Confirms both protection and monitoring cover the facility and infrastructure. |
5Tooling
The control is delivered by physical safeguards and monitoring of the facility and infrastructure.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [b] | Secured entry, environmental and infrastructure safeguards | Protection of the facility and support infrastructure. |
| [c], [d] | Surveillance, alarms, environmental monitoring | Monitoring of the facility and support infrastructure. |
The caveat is that monitoring has to be real and acted on, and cover the infrastructure as well as the building. Cameras no one watches and alerts no one reviews do not satisfy monitoring, and infrastructure left out leaves a gap. The assessor examines protection and monitoring across both subjects, so all four objectives have to hold.
6Evidence
The satisfied version of 3.10.2 shows the facility and infrastructure both protected and monitored.
| Evidence | What it demonstrates |
|---|---|
| Physical protection measures | Objectives [a], [b]. Facility and infrastructure protected. |
| Monitoring records | Objectives [c], [d]. Facility and infrastructure monitored. |
The evidence should show the physical facility and support infrastructure both protected and monitored. The protection measures together with the monitoring records are the clearest demonstration, and because this control cannot sit on a plan of action, both have to be real at the time of assessment.
A secured facility still has to be a watched one
The facility and the infrastructure the systems depend on underpin everything, and this five-point control asks that both be protected and monitored so intrusions and failures are seen. Pairing physical safeguards with real monitoring is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.10.2. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.10.2[a] through 3.10.2[d]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing PE.L2-3.10.2 among the five-point basic security requirements. ecfr.gov