Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.10.01OFFICIAL TITLEPENDING NIST SME REVIEW

03.10.01Physical Access Authorizations

03.10 Physical Protection · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires developing, approving, and maintaining a list of individuals authorized to access the facility where the system resides, issuing authorization credentials for facility access, reviewing the access list at an organization-defined frequency, and removing individuals when access is no longer required.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Facility access is granted from a list, not by familiarity. Somebody owns the roster of who may enter the spaces where systems and CUI live, credentials are issued against it, and the list is reviewed and pruned on a schedule — badge system or paper, the logic is the same.

Across revisions

Rev. 2's 'limit physical access to authorized individuals' (3.10.1) becomes a structured lifecycle in Rev. 3: list, credentials, defined-frequency review, and removal.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Scope 'facility' honestly — the server room, records storage, and production floor may each need their own authorization list.
  • Connect the list to offboarding (03.09.02) so terminations revoke physical access with the same discipline as logical access.
  • Review at the defined cadence and keep the review itself as a record — the pruning event is the evidence.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The current authorized-access list with approval and review dates
  • Credential issuance records reconciled against the list
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated