Skip to content

PE.L2-3.10.4 Physical Security 4 of 6 in family

Log Physical Access.

Maintain audit logs of who accessed secured CUI areas and when.

The one-liner

If the assessor asks who entered your server room last Tuesday, can you answer?

3.10.4 — Log Physical Access

Maintain audit logs of physical access.

This is one of 17 NIST SP 800-171 requirements that also map to a CMMC Level 1 practice (FAR 52.204-21 — FCI protection).

Keep records of who accesses secured areas — badge swipe logs, sign-in sheets, camera footage. Retain for the same period as your digital audit logs (typically 90 days minimum, one year preferred). Review periodically for anomalies — unusual after-hours access, unknown individuals, access by people no longer authorized.


Your assessor needs a “yes” to every row:

#QuestionWhat “yes” looks like
1Are physical access audit logs maintained?Badge logs, sign-in sheets, and camera footage retained per defined retention period

Documents they’ll review: Physical and environmental protection policy; physical access log retention policy; badge reader logs; visitor sign-in sheets; camera footage retention settings; system security plan

People they’ll talk to: Personnel with physical access responsibilities; information security personnel

Live demos they’ll ask for: “Show me the physical access log for the server room.” “Pull up who entered last Tuesday.” “How long are badge logs retained?” “Show me the visitor sign-in sheets from the past month.”


These are the actual questions. Have answers ready.

  • “Show me the physical access log for the server room.”
  • “How long do you retain badge access logs?”
  • “Show me visitor sign-in records from the past month.”
  • “Do you review physical access logs? How often?”

No logs. Door is locked but no record of who enters. Badge readers with logging solve this. Manual sign-in sheets are acceptable for areas without badge readers.

Logs not retained. Badge logs overwritten after 7 days. Configure retention to match your digital log retention policy.

No review. Logs exist but nobody looks at them. Monthly review for anomalies.



RequirementWhy it matters here
3.10.1 — Lock the DoorsAccess controls that generate the logs
3.10.3 — Escort Every VisitorVisitor logs are a subset of physical access logs
3.3.1 — Log EverythingPhysical access logs complement digital audit logs