NIST SP 800-53 Rev 5 LOW PE-8: Visitor Access Records
Maintain visitor access records for FedRAMP-defined period (1 year); review records monthly (FedRAMP).
What else in your programme already covers this
This control maps to 17 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
SOC2-CC6.4 Restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives
SOC2-CC7.1 Detection and monitoring procedures for security events are in place
SOC2-P6.2 Records of personal information disclosures are maintained
9.3.2 Procedures are implemented for authorizing and managing visitor access to the CDE, including: • Visitors are authorized before entering. • Visitors are escorted at all times. • Visitors are clearly identified and given a