3.10.3 — Escort Every Visitor
What It Says
Section titled “What It Says”Escort visitors and monitor visitor activity.
What It Actually Means
Section titled “What It Actually Means”Every visitor — including well-known vendors, friends, and family — is signed in, given a distinguishable visitor badge, and escorted by an authorized employee at all times when in areas where CUI is handled or stored. Escort means continuous accompaniment, not ‘check in periodically.’ Monitor means observe their activities. Visitor logs record: name, purpose, escort, arrival/departure times.
Pass or Fail
Section titled “Pass or Fail”Your assessor needs a “yes” to every row:
| # | Question | What “yes” looks like |
|---|---|---|
| 1 | Are visitors escorted? | Escort policy enforced; visitor log with escort name |
| 2 | Is visitor activity monitored? | Escorts accompany visitors continuously; CCTV supplements |
What to Have Ready on Assessment Day
Section titled “What to Have Ready on Assessment Day”Documents they’ll review: Physical and environmental protection policy; visitor escort procedures; visitor sign-in logs; visitor badge inventory; system security plan
People they’ll talk to: Personnel with physical access responsibilities; information security personnel
Live demos they’ll ask for: “Show me your visitor sign-in process.” “Where are visitor badges? Are they visually distinct?” “Walk me through what happens when a visitor arrives.” “Show me a recent visitor log.”
The Assessor’s Playbook
Section titled “The Assessor’s Playbook”These are the actual questions. Have answers ready.
- “Show me your visitor sign-in process.”
- “Are visitors distinguishable from employees? How?”
- “Show me a recent visitor log entry.”
- “What happens if the escort needs to step away?”
Where Companies Trip Up
Section titled “Where Companies Trip Up”Unescorted visitors. Left alone ‘just for a minute.’ If the escort leaves, the visitor leaves the area.
No sign-in log. Visitors enter without being recorded. Maintain a visitor log at reception.
No visitor badges. Visitors indistinguishable from employees. Use clearly distinct visitor badges.
How to Talk About This
Section titled “How to Talk About This”Connected Requirements
Section titled “Connected Requirements”| Requirement | Why it matters here |
|---|---|
| 3.10.1 — Lock the Doors | Visitors need escort because areas are access-controlled |
| 3.10.4 — Log Physical Access | Visitor logs are part of physical access audit trail |
| 3.7.6 — Escort Uncleared Techs | Maintenance personnel escort procedures |
Implementation
Section titled “Implementation”Step-by-step guides for Microsoft 365, AWS, Azure, and GCP are available to Ancitus clients.
Start a conversation →CMMC Practice ID: PE.L2-3.10.3 | SPRS Weight: 1 point | POA&M Eligible: Yes