Automated Records Maintenance and Review
LOW MODERATE ✓ HIGHRequirements NIST SOURCE
Maintain and review visitor access records using [organization-defined automated mechanisms].
Discussion (NIST Supplemental Guidance)
Visitor access records may be stored and maintained in a database management system that is accessible by organizational personnel. Automated access to such records facilitates record reviews on a regular basis to determine if access authorizations are current and still required to support organizational mission and business functions.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for PE-8(1) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- automated mechanisms used to maintain visitor access records are defined;
- automated mechanisms used to review visitor access records are defined;
- visitor access records are maintained using <PE-08(01)_ODP[01] automated mechanisms>;
- visitor access records are reviewed using <PE-08(01)_ODP[02] automated mechanisms>.
Examine
[SELECT FROM: Physical and environmental protection policy; procedures addressing visitor access records; automated mechanisms supporting management of visitor access records; visitor access control logs or records; system security plan; privacy plan; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with visitor access record responsibilities; organizational personnel with information security and privacy responsibilities].
Test
[SELECT FROM: Organizational processes for maintaining and reviewing visitor access records; automated mechanisms supporting and/or implementing the maintenance and review of visitor access records].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for PE-8(1). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Physical and environmental protection policy
- system security plan
- privacy plan
Testing
- Organizational processes for maintaining and reviewing visitor access records
- automated mechanisms supporting and/or implementing the maintenance and review of visitor access records
Other Records
- procedures addressing visitor access records
- automated mechanisms supporting management of visitor access records
- visitor access control logs or records
- other relevant documents or records