Skip to content
ControlVerdict
PE.L2-3.10.4CMMC Level 2Level 2

Physical Access Logs [CUI Data]

Practice statement

Maintain audit logs of physical access.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.10.4.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(1)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    audit logs of physical access are maintained.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    PE.L2-3.10.4Physical Access Logs [CUI Data]
    Maintain audit logs of physical access.
    • [a]

      audit logs of physical access are maintained.

    Badge reads and the paper lobby log kept a year — and actually read

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses the Physical Access Logs objective: audit logs of physical access are maintained.

    What is logged. Every badge read on every controlled door — grants and denials — with the credential, the door, and the timestamp. Denials matter as much as grants; a series of denials at the server room door is the signal this log exists to produce. Door-forced and door-held-open events are logged as well. Visitor entries and exits come from the kiosk record, and the landlord's paper lobby book is collected weekly and retained as a supplementary record.

    Retention. Badge and kiosk records are retained for one year, which exceeds our incident lookback needs and matches the contract's records expectation. Retention is a configuration setting on the badge server plus a nightly export to the log platform, so a failure or tampering of the badge appliance does not take the only copy with it.

    Integrity. Only two administrators can modify badge system configuration, and their administrative actions are themselves logged and reviewed by someone else. The nightly export lands in storage the badge administrators cannot delete. Time is synchronized from the same source as the rest of the environment so physical and logical timelines line up during an investigation.

    Review, which is the part that was missing. A monthly checklist covers: after-hours access to zones 2 and 3, all server room reads compared to change tickets, repeated denials by credential and by door, and any badge used during a period the holder was known to be away. Findings are noted with a disposition even when the disposition is 'confirmed with the employee, legitimate.'

    Use in incidents. The incident runbook cites the physical log as a standard evidence source; on any case involving a device or media, the responder pulls the door history for the relevant window as a matter of course.

    Maintenance. Quarterly verification that every controlled door still reports events and that the nightly export ran; annual test of the retention setting by retrieving a record from eleven months back.

    Accepted gap. The landlord's lobby and building entrance logging is theirs, and the paper book is easily falsified. We treat it as supplementary rather than authoritative and rely on our own suite-door reads as the first trustworthy record.

    What the evidence looks like

    • Badge system audit report sample showing grants, denials, and door-forced events
    • Retention configuration and the nightly export job to the log platform
    • Completed monthly review checklists with dispositions
    • Administrative action log for the badge system with independent review
    • Retrieval test result for a record older than ten months

    Environment

    Electronic badge system on interior doors; the lobby book is still paper because the landlord owns reception. Audit logs existed for years but nobody had ever opened them before an assessment asked.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.