CCI-000912
CCI-000912 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed will develop and maintain a list of personnel with authorized access to the facilities where information systems reside. The organization will also take action to identify and officially designate its publicly accessible areas where access authorization is not required.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the list of personnel with authorized access to facilities where information systems reside to ensure it is current within every 90 days. The review process should also determine if the organization has identified and officially designated its publicly accessible areas where access authorization is not required. DoD has defined the frequency as every 90 days.
Compelling Evidence
1.) List of personnel with authorized facility access 2.) Description of publicly accessible areas (no access authorization required)