BRACKETOLOGY | FEDRAMP

PE-8: VISITOR ACCESS RECORDS

  • FedRAMP Baseline Membership PE-8:
  • LOW
  • MODERATE
  • HIGH
FedRAMP Bracketology

Use the FedRAMP Control Membership information above to determine if a control or control enhancement is required for each Impact Baseline — LOW, MODERATE, or HIGH

Click on the panel below each control or control enhancement to review the FedRAMP Impact Baseline-specific control configuration requirements for each of the [BRACKETS] in each control and/or control enhancement.

Review and use Additional Requirements and Guidance to build FedRAMP-compliant controls for your risk-based cybersecurity program.

To change the baseline view in the panel, click on LOW, MODERATE, or HIGH when the panel is open

Panels only appear where there are [BRACKETS] in the control or enhancement or where there is FedRAMP-specific requirements or guidance available.

The organization:

    • a. Maintains visitor access records to the facility where the information system resides for [Assignment: organization-defined time period]; and
    • b. Reviews visitor access records [Assignment: organization-defined frequency].
Click Low | Moderate | High below to see FedRAMP control configuration information. It's in BOLD.

The organization:

  • a. Maintains visitor access records to the facility where the information system resides for for a minimum of one (1) year; and
  • b. Reviews visitor access records at least monthly.

The organization:

  • a. Maintains visitor access records to the facility where the information system resides for for a minimum of one (1) year; and
  • b. Reviews visitor access records at least monthly.

The organization:

  • a. Maintains visitor access records to the facility where the information system resides for for a minimum of one (1) year; and
  • b. Reviews visitor access records at least monthly.

SUPPLEMENTAL GUIDANCE

Visitor access records include, for example, names and organizations of persons visiting, visitor signatures, forms of identification, dates of access, entry and departure times, purposes of visits, and names and organizations of persons visited. Visitor access records are not required for publicly accessible areas.

RELATED CONTROLS:

CONTROL ENHANCEMENTS

PE-8 (1) VISITOR ACCESS RECORDS | AUTOMATED RECORDS MAINTENANCE / REVIEW
  • FedRAMP Baseline Membership PE-8 (1):
  • HIGH

The organization employs automated mechanisms to facilitate the maintenance and review of visitor access records.

Supplemental Guidance: NONE

PE-8 (2) VISITOR ACCESS RECORDS | PHYSICAL ACCESS RECORDS

[Withdrawn: Incorporated intoPE-2].

REFERENCES:

  • NO REFERENCES