Procedures, emergency procedures among them, give, restrict and withdraw access to premises, buildings and areas as business need dictates, with each access justified, authorised, logged and monitored, and they cover everyone who enters: staff, temporary staff, clients, vendors, visitors and any other third party: every entry point to IT sites is logged and monitored, and visitors, contractors and vendors included, are registered; all personnel wear approved identification at all times; visitors are accompanied throughout their visit; access to sensitive sites is restricted and monitored through perimeter controls such as walls, fences and security devices on internal and external doors; requests for access to computing facilities are managed; access profiles are kept up to date according to job function; and physical security awareness training is held regularly.
This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.