Core Principles
Access should be based on authorization, business need, and least privilege. Controls should confirm identity, limit entry to approved locations and times, record significant access activity, and support rapid changes when personnel roles change.
Credentials and Authentication
Facilities may use keys, badges, PINs, mobile credentials, biometrics, or combinations of these methods. The appropriate method depends on risk, privacy, operational needs, environmental conditions, and the consequences of unauthorized entry.
Visitor and Contractor Management
Visitor procedures should define sponsorship, identity verification, sign-in, temporary credentials, escort requirements, restricted areas, badge return, and record retention. Contractors and temporary workers should receive only the access needed for their assigned work.
Access Lifecycle
A complete process covers authorization, issuance, activation, modification, suspension, recovery, and revocation. Access should be reviewed periodically and removed promptly after separation, transfer, contract completion, lost credentials, or changed duties.
Emergency Access and Continuity
Plans should address emergency responders, evacuation, lockdown, power loss, system outages, manual overrides, and after-hours access. Emergency functions must be tested without weakening everyday accountability.