Does your organization have a formal escort policy requiring all guests, vendors, and third parties to be accompanied by authorized personnel when accessing areas containing business-critical assets?
Explanation
This control prevents unauthorized access to sensitive areas and reduces the risk of data breaches, theft, or sabotage by requiring continuous supervision of non-employees. Without proper escort procedures, visitors might inadvertently or deliberately access, damage, or compromise critical systems, infrastructure, or sensitive information.
Evidence of compliance could include: a documented visitor escort policy, visitor logs showing escort assignments, physical access control procedures that specify escort requirements, or security awareness training materials that cover visitor escort protocols.
Implementation Example
Escort guests, vendors, and other third parties within areas that contain business-critical assets
ID: PR.AA-06.213
Context
- Function
- PR: PROTECT
- Category
- PR.AA: Identity Management, Authentication, and Access Control
- Sub-Category
- Physical access to assets is managed, monitored, and enforced commensurate with risk
Related questions
- Does your organization have a formal process to request, track, review, and fulfill access requests that includes appropriate approval from system or data owners?
- Does your organization have a formal process for managing the lifecycle of cryptographic certificates, keys, identity tokens, and other credentials?
- Does your organization use unique device identifiers based on immutable hardware characteristics or secure provisioning methods?
- Does your organization physically label all authorized hardware assets with unique identifiers for inventory tracking and servicing purposes?
- Does your organization verify individuals' identities during enrollment using government-issued credentials?
- Does your organization issue unique credentials to each individual user and prohibit credential sharing?

