{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/make-visitor-access-sponsored-time-bounded-closed-loop/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/",
        "slug": "make-visitor-access-sponsored-time-bounded-closed-loop",
        "url": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/make-visitor-access-sponsored-time-bounded-closed-loop/"
        },
        "title": "Make visitor access a sponsored, time-bounded, fully closed loop",
        "summary": "A visitor badge is only one moment in a longer control. Tie every non-public visit to an approved sponsor, defined destination and time window, appropriate escort, visible credential, confirmed departure, and reviewable record.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-11T10:17:00+00:00",
        "modified_at": "2026-08-11T14:48:23+00:00",
        "reviewed_on": "2026-08-11",
        "reading_minutes": 4,
        "word_count": 661,
        "potentially_affected": "Reception and security desks, visitor-management procedures, temporary badges, employee sponsors, contractors and vendors, delivery entrances, controlled interior areas, physical visitor logs, and access-control operators.",
        "dse_recommendation": "Define a single visitor lifecycle covering preregistration, identity verification, authorization, zone and time limits, escort rules, badge return, overdue escalation, record review, and privacy-conscious retention.",
        "primary_source": {
            "name": "CISA Interagency Security Committee: Facility Access Control—An ISC Best Practice",
            "url": "https://www.cisa.gov/sites/default/files/2022-11/Facility%20Access%20Control%20-%20An%20Interagency%20Security%20Committee%20Best%20Practice.pdf",
            "published_on": "2020-12-17",
            "authority": "Cybersecurity and Infrastructure Security Agency"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts: visitor access extends beyond identity at the entrance</h2>\n<p>The Interagency Security Committee’s December 2020 <a href=\"https://www.cisa.gov/sites/default/files/2022-11/Facility%20Access%20Control%20-%20An%20Interagency%20Security%20Committee%20Best%20Practice.pdf\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Facility Access Control</em></a> guide addresses the full access process for people entering federally occupied space: arrival, identity and authorization decisions, screening, movement, escort, and the first authentication point into non-public space. It treats visitor processing as part of the facility’s risk-based operating model, not a standalone badge-printing task.</p>\n<p>The guide describes alternate access procedures for a person who cannot present the ordinary accepted identification, including a prearranged visit in which the security post contacts the agency point of contact for access and escort. It states that the visit sponsor, designee, or dedicated escort is responsible for the individual in federally occupied space. Escort procedures and ratios should reflect the type of visitor, associated risk, and operational requirements.</p>\n<p>The ISC presents multiple escort levels, ranging from minimal practices for authorized personnel without local access through continuous, high-positive control for higher-risk circumstances. The chosen level drives proximity, visual or other control, briefing, and monitoring expectations. This is federal best-practice guidance; it does not prescribe a private facility’s identity documents, badge color, escort ratio, retention period, or authority. Applicable law, labor rules, accessibility needs, contracts, privacy obligations, and local facility risk govern the commercial workflow.</p>\n\n<h2>DSE recommendation: close every visit from request through departure</h2>\n<p>Build one workflow for guests, interview candidates, delivery personnel, technicians, auditors, temporary workers, and after-hours vendors. Different visitor classes can have different controls, but none should rely on the receptionist guessing what “normal” means.</p>\n<ol>\n<li><strong>Require a responsible sponsor.</strong> Capture the sponsor, visitor identity information actually needed, organization, purpose, date and expected times, entrance, destination, approved zones, escort requirement, equipment or material being brought in, and any advance screening or accommodation. The sponsor should affirm the request, not merely appear in a directory.</li>\n<li><strong>Verify the visit at arrival.</strong> Match the person to the approved request using the organization’s accepted method. Resolve misspellings, substitutions, early arrivals, groups, and unknown sponsors through a documented exception path. Front-desk pressure should not silently turn an unapproved visit into an approved one.</li>\n<li><strong>Issue the least-capable credential.</strong> Make the badge visibly temporary and configure only the locations and hours needed. Do not copy an employee’s access profile for convenience. Where no electronic credential is needed, use a clearly recognizable visitor badge and control the movement procedurally.</li>\n<li><strong>Make escort ownership explicit.</strong> State who receives the visitor, when custody transfers, where unescorted movement is allowed, and what happens if the host cannot be reached. Include restrooms, cafeterias, smoking areas, loading docks, evacuation, and emergency separation rather than assuming the visitor will remain beside the sponsor.</li>\n<li><strong>Close out the visit.</strong> Record departure, recover or disable the credential, reconcile loaned keys or equipment, and alert on badges still active after the approved window. A checkout kiosk is useful only if someone investigates the exceptions.</li>\n<li><strong>Review the record.</strong> Look for recurring overdue visits, missing badges, repeated sponsor exceptions, entries without departures, unusual after-hours activity, and attempts to reach unapproved areas. Route anomalies to a named owner and document disposition.</li>\n</ol>\n<p>Minimize personal data. Define which fields serve an operational or legal need, who may see them, how long they are retained, how paper logs are protected from casual viewing, and how records are disposed of. Avoid collecting identification numbers or copies merely because the software offers a field.</p>\n<p>Test the process with ordinary and difficult scenarios: a walk-in executive guest, a substitute technician, a large group, an after-hours contractor, a visitor whose sponsor is absent, a lost badge, an evacuation, and a person who declines the stated verification step. Measure time to resolve exceptions, overdue badge closure, unreturned credentials, sponsor response, and record completeness. The result should be welcoming without being vague: every non-public visitor has an owner, a purpose, a boundary, and a verified end.</p>\n\n<h2>Official references</h2>\n<ul>\n<li>Cybersecurity and Infrastructure Security Agency, Interagency Security Committee, <a href=\"https://www.cisa.gov/sites/default/files/2022-11/Facility%20Access%20Control%20-%20An%20Interagency%20Security%20Committee%20Best%20Practice.pdf\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Facility Access Control: An ISC Best Practice</em></a>, December 17, 2020.</li>\n<li>CISA, <a href=\"https://www.cisa.gov/about-interagency-security-committee\" target=\"_blank\" rel=\"noopener noreferrer\">Interagency Security Committee policies, standards, and best practices</a>.</li>\n</ul>",
        "content_text": "Source facts: visitor access extends beyond identity at the entrance\nThe Interagency Security Committee’s December 2020 Facility Access Control guide addresses the full access process for people entering federally occupied space: arrival, identity and authorization decisions, screening, movement, escort, and the first authentication point into non-public space. It treats visitor processing as part of the facility’s risk-based operating model, not a standalone badge-printing task.\nThe guide describes alternate access procedures for a person who cannot present the ordinary accepted identification, including a prearranged visit in which the security post contacts the agency point of contact for access and escort. It states that the visit sponsor, designee, or dedicated escort is responsible for the individual in federally occupied space. Escort procedures and ratios should reflect the type of visitor, associated risk, and operational requirements.\nThe ISC presents multiple escort levels, ranging from minimal practices for authorized personnel without local access through continuous, high-positive control for higher-risk circumstances. The chosen level drives proximity, visual or other control, briefing, and monitoring expectations. This is federal best-practice guidance; it does not prescribe a private facility’s identity documents, badge color, escort ratio, retention period, or authority. Applicable law, labor rules, accessibility needs, contracts, privacy obligations, and local facility risk govern the commercial workflow.\n\nDSE recommendation: close every visit from request through departure\nBuild one workflow for guests, interview candidates, delivery personnel, technicians, auditors, temporary workers, and after-hours vendors. Different visitor classes can have different controls, but none should rely on the receptionist guessing what “normal” means.\n\nRequire a responsible sponsor. Capture the sponsor, visitor identity information actually needed, organization, purpose, date and expected times, entrance, destination, approved zones, escort requirement, equipment or material being brought in, and any advance screening or accommodation. The sponsor should affirm the request, not merely appear in a directory.\nVerify the visit at arrival. Match the person to the approved request using the organization’s accepted method. Resolve misspellings, substitutions, early arrivals, groups, and unknown sponsors through a documented exception path. Front-desk pressure should not silently turn an unapproved visit into an approved one.\nIssue the least-capable credential. Make the badge visibly temporary and configure only the locations and hours needed. Do not copy an employee’s access profile for convenience. Where no electronic credential is needed, use a clearly recognizable visitor badge and control the movement procedurally.\nMake escort ownership explicit. State who receives the visitor, when custody transfers, where unescorted movement is allowed, and what happens if the host cannot be reached. Include restrooms, cafeterias, smoking areas, loading docks, evacuation, and emergency separation rather than assuming the visitor will remain beside the sponsor.\nClose out the visit. Record departure, recover or disable the credential, reconcile loaned keys or equipment, and alert on badges still active after the approved window. A checkout kiosk is useful only if someone investigates the exceptions.\nReview the record. Look for recurring overdue visits, missing badges, repeated sponsor exceptions, entries without departures, unusual after-hours activity, and attempts to reach unapproved areas. Route anomalies to a named owner and document disposition.\n\nMinimize personal data. Define which fields serve an operational or legal need, who may see them, how long they are retained, how paper logs are protected from casual viewing, and how records are disposed of. Avoid collecting identification numbers or copies merely because the software offers a field.\nTest the process with ordinary and difficult scenarios: a walk-in executive guest, a substitute technician, a large group, an after-hours contractor, a visitor whose sponsor is absent, a lost badge, an evacuation, and a person who declines the stated verification step. Measure time to resolve exceptions, overdue badge closure, unreturned credentials, sponsor response, and record completeness. The result should be welcoming without being vague: every non-public visitor has an owner, a purpose, a boundary, and a verified end.\n\nOfficial references\n\nCybersecurity and Infrastructure Security Agency, Interagency Security Committee, Facility Access Control: An ISC Best Practice, December 17, 2020.\nCISA, Interagency Security Committee policies, standards, and best practices.",
        "content_markdown": "## Source facts: visitor access extends beyond identity at the entrance\n\nThe Interagency Security Committee’s December 2020 [Facility Access Control](https://www.cisa.gov/sites/default/files/2022-11/Facility%20Access%20Control%20-%20An%20Interagency%20Security%20Committee%20Best%20Practice.pdf) guide addresses the full access process for people entering federally occupied space: arrival, identity and authorization decisions, screening, movement, escort, and the first authentication point into non-public space. It treats visitor processing as part of the facility’s risk-based operating model, not a standalone badge-printing task.\n\nThe guide describes alternate access procedures for a person who cannot present the ordinary accepted identification, including a prearranged visit in which the security post contacts the agency point of contact for access and escort. It states that the visit sponsor, designee, or dedicated escort is responsible for the individual in federally occupied space. Escort procedures and ratios should reflect the type of visitor, associated risk, and operational requirements.\n\nThe ISC presents multiple escort levels, ranging from minimal practices for authorized personnel without local access through continuous, high-positive control for higher-risk circumstances. The chosen level drives proximity, visual or other control, briefing, and monitoring expectations. This is federal best-practice guidance; it does not prescribe a private facility’s identity documents, badge color, escort ratio, retention period, or authority. Applicable law, labor rules, accessibility needs, contracts, privacy obligations, and local facility risk govern the commercial workflow.\n\n## DSE recommendation: close every visit from request through departure\n\nBuild one workflow for guests, interview candidates, delivery personnel, technicians, auditors, temporary workers, and after-hours vendors. Different visitor classes can have different controls, but none should rely on the receptionist guessing what “normal” means.\n\n- Require a responsible sponsor. Capture the sponsor, visitor identity information actually needed, organization, purpose, date and expected times, entrance, destination, approved zones, escort requirement, equipment or material being brought in, and any advance screening or accommodation. The sponsor should affirm the request, not merely appear in a directory.\n\n- Verify the visit at arrival. Match the person to the approved request using the organization’s accepted method. Resolve misspellings, substitutions, early arrivals, groups, and unknown sponsors through a documented exception path. Front-desk pressure should not silently turn an unapproved visit into an approved one.\n\n- Issue the least-capable credential. Make the badge visibly temporary and configure only the locations and hours needed. Do not copy an employee’s access profile for convenience. Where no electronic credential is needed, use a clearly recognizable visitor badge and control the movement procedurally.\n\n- Make escort ownership explicit. State who receives the visitor, when custody transfers, where unescorted movement is allowed, and what happens if the host cannot be reached. Include restrooms, cafeterias, smoking areas, loading docks, evacuation, and emergency separation rather than assuming the visitor will remain beside the sponsor.\n\n- Close out the visit. Record departure, recover or disable the credential, reconcile loaned keys or equipment, and alert on badges still active after the approved window. A checkout kiosk is useful only if someone investigates the exceptions.\n\n- Review the record. Look for recurring overdue visits, missing badges, repeated sponsor exceptions, entries without departures, unusual after-hours activity, and attempts to reach unapproved areas. Route anomalies to a named owner and document disposition.\n\nMinimize personal data. Define which fields serve an operational or legal need, who may see them, how long they are retained, how paper logs are protected from casual viewing, and how records are disposed of. Avoid collecting identification numbers or copies merely because the software offers a field.\n\nTest the process with ordinary and difficult scenarios: a walk-in executive guest, a substitute technician, a large group, an after-hours contractor, a visitor whose sponsor is absent, a lost badge, an evacuation, and a person who declines the stated verification step. Measure time to resolve exceptions, overdue badge closure, unreturned credentials, sponsor response, and record completeness. The result should be welcoming without being vague: every non-public visitor has an owner, a purpose, a boundary, and a verified end.\n\n## Official references\n\n- Cybersecurity and Infrastructure Security Agency, Interagency Security Committee, [Facility Access Control: An ISC Best Practice](https://www.cisa.gov/sites/default/files/2022-11/Facility%20Access%20Control%20-%20An%20Interagency%20Security%20Committee%20Best%20Practice.pdf), December 17, 2020.\n\n- CISA, [Interagency Security Committee policies, standards, and best practices](https://www.cisa.gov/about-interagency-security-committee)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/",
                "url": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-11"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Make visitor access a sponsored, time-bounded, fully closed loop",
                        "item": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/#article",
                "identifier": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/",
                "url": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/",
                "headline": "Make visitor access a sponsored, time-bounded, fully closed loop",
                "description": "A visitor badge is only one moment in a longer control. Tie every non-public visit to an approved sponsor, defined destination and time window…",
                "abstract": "A visitor badge is only one moment in a longer control. Tie every non-public visit to an approved sponsor, defined destination and time window, appropriate escort, visible credential, confirmed departure, and reviewable record.",
                "articleBody": "Source facts: visitor access extends beyond identity at the entrance\nThe Interagency Security Committee’s December 2020 Facility Access Control guide addresses the full access process for people entering federally occupied space: arrival, identity and authorization decisions, screening, movement, escort, and the first authentication point into non-public space. It treats visitor processing as part of the facility’s risk-based operating model, not a standalone badge-printing task.\nThe guide describes alternate access procedures for a person who cannot present the ordinary accepted identification, including a prearranged visit in which the security post contacts the agency point of contact for access and escort. It states that the visit sponsor, designee, or dedicated escort is responsible for the individual in federally occupied space. Escort procedures and ratios should reflect the type of visitor, associated risk, and operational requirements.\nThe ISC presents multiple escort levels, ranging from minimal practices for authorized personnel without local access through continuous, high-positive control for higher-risk circumstances. The chosen level drives proximity, visual or other control, briefing, and monitoring expectations. This is federal best-practice guidance; it does not prescribe a private facility’s identity documents, badge color, escort ratio, retention period, or authority. Applicable law, labor rules, accessibility needs, contracts, privacy obligations, and local facility risk govern the commercial workflow.\n\nDSE recommendation: close every visit from request through departure\nBuild one workflow for guests, interview candidates, delivery personnel, technicians, auditors, temporary workers, and after-hours vendors. Different visitor classes can have different controls, but none should rely on the receptionist guessing what “normal” means.\n\nRequire a responsible sponsor. Capture the sponsor, visitor identity information actually needed, organization, purpose, date and expected times, entrance, destination, approved zones, escort requirement, equipment or material being brought in, and any advance screening or accommodation. The sponsor should affirm the request, not merely appear in a directory.\nVerify the visit at arrival. Match the person to the approved request using the organization’s accepted method. Resolve misspellings, substitutions, early arrivals, groups, and unknown sponsors through a documented exception path. Front-desk pressure should not silently turn an unapproved visit into an approved one.\nIssue the least-capable credential. Make the badge visibly temporary and configure only the locations and hours needed. Do not copy an employee’s access profile for convenience. Where no electronic credential is needed, use a clearly recognizable visitor badge and control the movement procedurally.\nMake escort ownership explicit. State who receives the visitor, when custody transfers, where unescorted movement is allowed, and what happens if the host cannot be reached. Include restrooms, cafeterias, smoking areas, loading docks, evacuation, and emergency separation rather than assuming the visitor will remain beside the sponsor.\nClose out the visit. Record departure, recover or disable the credential, reconcile loaned keys or equipment, and alert on badges still active after the approved window. A checkout kiosk is useful only if someone investigates the exceptions.\nReview the record. Look for recurring overdue visits, missing badges, repeated sponsor exceptions, entries without departures, unusual after-hours activity, and attempts to reach unapproved areas. Route anomalies to a named owner and document disposition.\n\nMinimize personal data. Define which fields serve an operational or legal need, who may see them, how long they are retained, how paper logs are protected from casual viewing, and how records are disposed of. Avoid collecting identification numbers or copies merely because the software offers a field.\nTest the process with ordinary and difficult scenarios: a walk-in executive guest, a substitute technician, a large group, an after-hours contractor, a visitor whose sponsor is absent, a lost badge, an evacuation, and a person who declines the stated verification step. Measure time to resolve exceptions, overdue badge closure, unreturned credentials, sponsor response, and record completeness. The result should be welcoming without being vague: every non-public visitor has an owner, a purpose, a boundary, and a verified end.\n\nOfficial references\n\nCybersecurity and Infrastructure Security Agency, Interagency Security Committee, Facility Access Control: An ISC Best Practice, December 17, 2020.\nCISA, Interagency Security Committee policies, standards, and best practices.",
                "datePublished": "2026-08-11T10:17:00+00:00",
                "dateModified": "2026-08-11T14:48:23+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/make-visitor-access-sponsored-time-bounded-closed-loop/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Make visitor access a sponsored, time-bounded, fully closed loop"
                },
                "articleSection": [
                    "Access Control"
                ],
                "keywords": [
                    "Access Control",
                    "Playbook",
                    "Advisory priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    }
                ],
                "wordCount": 661,
                "timeRequired": "PT4M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "CISA Interagency Security Committee: Facility Access Control—An ISC Best Practice",
                    "url": "https://www.cisa.gov/sites/default/files/2022-11/Facility%20Access%20Control%20-%20An%20Interagency%20Security%20Committee%20Best%20Practice.pdf",
                    "datePublished": "2020-12-17"
                }
            }
        ]
    }
}