CCI-000927
CCI-000927 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if: - combinations are changed [PE-03_ODP[09]; frequency at which to change combinations is defined], when combinations are compromised, or when individuals possessing the combinations are transferred or terminated. - keys are changed [PE-03_ODP[10]; frequency at which to change keys is defined], when keys are lost, or when individuals possessing the keys are transferred or terminated.
Validation Procedures
Examine: [SELECT FROM: Physical and environmental protection policy; procedures addressing physical access control; physical access control logs or records; inventory records of physical access control devices; system entry and exit points; records of key and lock combination changes; storage locations for physical access control devices; physical access control devices; list of security safeguards controlling access to designated publicly accessible areas within facility; system security plan; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with physical access control responsibilities; organizational personnel with information security responsibilities]. Test: [SELECT FROM: Organizational processes for physical access control; mechanisms supporting and/or implementing physical access control; physical access control devices].