Entry control devices must be paired with effective access control procedures; two or more technologies may be combined (biometric plus PIN, credential plus lock), though layering can lengthen verification and throughput. Common performance measures are throughput (time for an authorised person or item to pass a point) and false readings and acceptance. Systems should give depth of protection in line with operational requirements, considering: the design, construction and condition of the premises and modes of operation; the operations, their nature, sensitivity, importance or vulnerability and the threats against them and the organization; the area, region and environment; how valuable and critical the assets are; and safety, legal and financial limits. The organization should: set parameters and requirements for each facility, space, property or operation; define access levels for areas, the entry systems and procedures to enforce them and the set levels of control; define how access is granted, denied and how unauthorised or attempted access is handled; define how materials are screened, how assets are handled and controlled, and how adversaries are detected and responded to; make sure competent PAP professionals handle the design, installation, upkeep, monitoring and management of entry components; build in safeguards against attempts to defeat the system; make sure security staff are fit for their tasks, with detailed procedures coordinated with the devices; run frequent, irregular checks and tests of the systems and staff assignments; require recognition by at least two of the three identification factors for entry to a controlled area; enforce a uniform way of wearing and displaying credentials in authorised-only areas; build entry and exit points for single-file passage so attempts to defeat controls are easier to spot; train and educate all staff in good access control aligned with security and safety policies; run a process to issue, audit and cancel credentials; and define the response to unauthorised attempts or bypassing.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.