1Overview
PE.L2-3.10.4 creates the record of who came and went. It requires that audit logs of physical access be maintained, so that physical entries to the facility are recorded and can be reviewed after the fact. It is a one-point requirement, but it is one of the named exclusions that cannot be placed on a plan of action, so it has to be met at assessment.
Limiting and monitoring physical access controls entry in the moment; logging it creates the record that supports investigation later. This control requires that audit logs of physical access be maintained, so that who entered, and when, is captured. Those logs are what allow the organization to reconstruct physical access during an investigation, confirm that the access limits held, or spot a pattern of concern. Though it carries a single point, it is named in the regulation as a requirement that cannot be deferred, and its single assessment objective is that the physical access logs are maintained.
Maintain audit logs of physical access.
The requirement is to maintain audit logs of physical access. In practice these are the records of entry to the facility and controlled areas, whether captured by an electronic access system, a visitor log, or another record, kept over time so they are available for review. The point is that physical access leaves a durable, reviewable trail rather than passing without record.
2The Assessment Objective
NIST SP 800-171A frames 3.10.4 as a single objective: maintain audit logs of physical access.
Audit logs of physical access are maintained. Physical entries are recorded and kept.
The single objective is maintaining the physical access logs. The common failure is physical access controlled but not recorded, or recorded and then not retained. The assessor looks for physical access logs that are maintained and available.
3Failure Patterns
The failures are about physical access that leaves no durable record.
Access not logged
Where physical entry is controlled but not recorded, there is no trail to review after an incident. Maintaining access logs captures who entered and when.
Logs not retained
Access records that are captured but discarded quickly cannot support later investigation. The logs have to be maintained over time.
Partial coverage
Logging entry to some controlled areas but not others leaves gaps in the record. Physical access logging has to cover the controlled access points.
4Ownership
This is a facilities and security-owned control.
| Role | Responsibility for this control |
|---|---|
| Facilities and security | Maintains the physical access logs, whether electronic or manual. Owns the access log evidence. |
| Security or compliance lead | Confirms logs are maintained across controlled access points and retained. |
| Program lead | Sets retention for physical access logs and includes them in review. |
5Tooling
The control is delivered by physical access logging, electronic or manual, with retention.
| Objective | Tooling | What it provides |
|---|---|---|
| capture | Electronic access system, visitor and entry logs | Records of physical entry. |
| retain | Log retention | Physical access records kept over time for review. |
The caveat is that the logs have to be both captured and retained, across the controlled access points. Because this control is a named exclusion, it cannot be deferred, so the logging has to be a real, maintained practice at assessment. The assessor examines whether physical access logs are maintained, so capture and retention both have to hold.
6Evidence
The satisfied version of 3.10.4 shows maintained physical access logs.
| Evidence | What it demonstrates |
|---|---|
| Physical access logs | The objective. Physical entries are recorded. |
| Log retention practice | The objective. Logs are maintained over time. |
The evidence should show audit logs of physical access maintained and retained across controlled access points. The physical access logs and their retention are the clearest demonstration, and because this control is a named exclusion that cannot sit on a plan of action, the practice has to be real at the time of assessment.
Controlling access is not the same as recording it
Entry controls act in the moment, but only maintained logs let you reconstruct who was physically present, so this control asks for physical access audit logs, and as a named exclusion it cannot be deferred. Building maintained, retained physical access logging is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.10.4. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.10.4. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, which names PE.L2-3.10.4 among the requirements that may not be placed on a plan of action. ecfr.gov