- Lock wiring closets and patch-panel spaces and put them on the facility access lists like any other controlled area.
- Walk the cable paths — exposed runs in public corridors, shared-tenant spaces, and accessible ceiling voids are where the finding lives.
- In shared buildings, establish what the landlord controls and what you do; an unmanaged shared telecom room needs compensating measures or contractual handling.
03.10.08 — Access Control for Transmission
03.10 Physical Protection · NIST SP 800-171 Rev. 3
Requires controlling physical access to system distribution and transmission lines within organizational facilities.
Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.
NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI ↗What this requirement is after
Network cabling, patch panels, and wiring closets are part of the system too. If someone can walk up to an unlocked telecom closet or an exposed cable run, they can tap, disrupt, or attach to the network without touching a single endpoint.
New in Rev. 3 with no Rev. 2 counterpart — Rev. 2 named no explicit requirement for physical access to transmission lines. Most organizations transition by folding wiring closets and cable paths into the existing facility-control regime rather than building anything new.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- Locked distribution and wiring spaces tied to the facility access list
- A dated review of cable routes and telecom spaces
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this came from in Rev. 2
No direct Rev. 2 counterpart — this requirement is new in Rev. 3. Open the transition crosswalk →
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |