1Overview
PE.L2-3.10.5 governs the keys to the building. It requires that physical access devices be identified, controlled, and managed, so that the badges, keys, and other devices that grant physical entry are themselves accounted for and governed. It is a one-point requirement, but it is one of the named exclusions that cannot be placed on a plan of action, so it has to be met at assessment.
Physical access limits depend on the devices that enforce them, the access cards, keys, fobs, and codes that open doors. If those devices are not tracked and governed, the access limits erode: a lost badge that is never deactivated, a key held by a departed employee, or an unaccounted-for fob each becomes an unmanaged path in. This control requires that physical access devices be identified, so the organization knows what exists; controlled, so their issue and use are governed; and managed, so they are maintained, reclaimed, and deactivated over their life. Though it carries a single point, it is named in the regulation as a requirement that cannot be deferred, and its three assessment objectives are identification, control, and management.
Control and manage physical access devices.
The requirement names control and management of physical access devices, and the assessment objectives add identification as the foundation. Identifying the devices means knowing which badges, keys, and codes exist and grant access; controlling them means governing how they are issued and used; managing them means maintaining them over time, including reclaiming and deactivating devices when access should end. Together these keep the devices that enforce physical access from becoming an unmanaged gap.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.10.5 into three objectives: identify, control, and manage physical access devices.
Physical access devices are identified. The organization knows which devices grant access.
Physical access devices are controlled. Their issue and use are governed.
Physical access devices are managed. They are maintained, reclaimed, and deactivated over their life.
The three objectives are identify, control, and manage. The common gap is at objective [c], management, where devices are issued but never reclaimed or deactivated, so lost badges and departed-employee keys stay live. The assessor looks for all three across the devices that grant physical access.
3Failure Patterns
The failures are about access devices that are unaccounted for or never deactivated.
Devices not tracked
Without knowing which badges, keys, and codes exist, the organization cannot govern them. Identifying the access devices is the basis for controlling and managing them.
Lost devices left active
A lost badge or key that is never deactivated remains a working path in. Managing devices includes deactivating them when they are lost or should no longer grant access.
Departed-employee devices not reclaimed
Access devices held by people who have left continue to open doors if not reclaimed or deactivated. Management ties device status to the person's access needs.
4Ownership
This is a facilities and security-owned control tied to the access device lifecycle.
| Role | Responsibility for this control |
|---|---|
| Facilities and security | Identifies, controls, and manages physical access devices over their life. Owns the device inventory and records. |
| Human resources | Notifies of departures so devices can be reclaimed or deactivated. |
| Security or compliance lead | Confirms devices are identified, controlled, and managed, including deactivation. |
5Tooling
The control is delivered by an access device inventory and a lifecycle process.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Access device inventory | Identification of the devices that grant access. |
| [b] | Issue and use governance | Control over how devices are issued and used. |
| [c] | Reclaim and deactivation process | Management of devices over their life. |
The caveat is that management, especially deactivation, is where the control is proven. An inventory and issue process without a reliable way to reclaim and deactivate devices leaves live devices in the wrong hands. Because this control is a named exclusion, it cannot be deferred, so all three objectives have to hold at assessment.
6Evidence
The satisfied version of 3.10.5 shows access devices identified, controlled, and managed.
| Evidence | What it demonstrates |
|---|---|
| Access device inventory | Objective [a]. Devices are identified. |
| Issue and governance records | Objective [b]. Devices are controlled. |
| Reclaim and deactivation records | Objective [c]. Devices are managed over their life. |
The evidence should show physical access devices identified, their issue and use controlled, and their lifecycle managed including deactivation. The inventory together with the governance and deactivation records is the clearest demonstration, and because this control is a named exclusion that cannot sit on a plan of action, the practice has to be real at the time of assessment.
A badge no one reclaims is a door left open
The devices that enforce physical access have to be tracked and deactivated when access should end, or the limits they enforce persist in the wrong hands, so this control asks that they be identified, controlled, and managed, and as a named exclusion it cannot be deferred. Building an access device lifecycle is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.10.5. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.10.5[a] through 3.10.5[c]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, which names PE.L2-3.10.5 among the requirements that may not be placed on a plan of action. ecfr.gov