NIST SP 800-171 & CMMC 2.0 3.10.1 Requirement:

Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

NIST SP 800-171 & CMMC 2.0 3.10.1 Requirement Explanation:

Physical security controls protect information and systems from being accessed by unauthorized persons.

Example NIST SP 800-171 & CMMC 2.0 3.10.1 Implementation:

Prevent unauthorized persons from accessing your company's facilities. Prevent unauthorized persons from physically accessing devices used to support DoD projects. This includes workstations, servers, network devices, printers, and fax machines. Determine which areas of your facility are non-sensitive (e.g., the lobby). Determine which areas of your facility are sensitive. Sensitive areas include your server room and places where your work on DoD contracts. Install locks on doors leading to sensitive areas in your facility. Only provide keys to authorized persons. Provide your employees with ID cards to distinguish them from visitors. . Keep your servers and network devices in a locked room or closet (e.g., server room). Keep hard drives containing “Controlled Unclassified Information” (CUI) in locked containers. Keep paperwork containing “Controlled Unclassified Information” (CUI) in locked cabinets. Place printers and fax machines that print “Controlled Unclassified Information” (CUI) in areas that can only be accessed by authorized persons.

NIST SP 800-171 & CMMC 2.0 3.10.1 Scenario(s):

- Scenario 1:

Jim installs a smart card reader at the entrance of his company's office and at the door to the server room. He provides each employee with a smart card to access the office. He provides authorized members of the IT team access to the server room.
 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 NIST SP 800-171 & CMMC Compliance App

NIST SP 800-171 & CMMC Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.