PE-8: Visitor Access Records
Control Family:
CSF v1.1 References:
PF v1.0 References:
Threats Addressed:
Baselines:
- Low
- PE-8
- Moderate
- PE-8
- High
- PE-8
- (1)
Next Version:
- NIST Special Publication 800-53 Revision 5:
- PE-8: Visitor Access Records
Control Statement
The organization:
- Maintains visitor access records to the facility where the information system resides for [Assignment: organization-defined time period]; and
- Reviews visitor access records [Assignment: organization-defined frequency].
Supplemental Guidance
Visitor access records include, for example, names and organizations of persons visiting, visitor signatures, forms of identification, dates of access, entry and departure times, purposes of visits, and names and organizations of persons visited. Visitor access records are not required for publicly accessible areas.
Control Enhancements
PE-8(1): Automated Records Maintenance / Review
Baseline(s):
- High
The organization employs automated mechanisms to facilitate the maintenance and review of visitor access records.