{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/physical-access-credential-lifecycle-badges-cards-mobile/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/",
        "slug": "physical-access-credential-lifecycle-badges-cards-mobile",
        "url": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/physical-access-credential-lifecycle-badges-cards-mobile/"
        },
        "title": "Control physical access credentials from issue through revocation",
        "summary": "A physical credential remains trustworthy only when identity verification, approval, issuance, access changes, loss response, periodic review, and revocation operate as one controlled lifecycle.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-28T14:22:00+00:00",
        "modified_at": "2026-07-28T14:22:00+00:00",
        "reviewed_on": "2026-07-28",
        "reading_minutes": 3,
        "word_count": 450,
        "potentially_affected": "Organizations that issue employee, contractor, visitor, temporary, card, fob, smart-card, emergency, test, or mobile credentials through a physical access control system.",
        "dse_recommendation": "Map the credential lifecycle to named owners and measurable time limits, then reconcile people, credentials, access levels, lifecycle events, and physical inventory with defensible evidence.",
        "primary_source": {
            "name": "NIST SP 800-53 Rev. 5 Update 1: Security and Privacy Controls",
            "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
            "published_on": "2020-09-23",
            "authority": "National Institute of Standards and Technology"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source fact: authorization and credentials require continuing control</h2>\n<p>NIST <a href=\"https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final\" target=\"_blank\" rel=\"noopener noreferrer\">SP 800-53 Rev. 5 Update 1</a> provides a catalog of security and privacy controls that organizations tailor to their risks. Physical and Environmental Protection control PE-2 addresses authorizing physical access, maintaining an authorized-access list, issuing credentials, reviewing access, and removing people from the list when access is no longer required. PE-3 addresses enforcing physical access and maintaining relevant access records. The publication is mandatory in specified federal contexts, but it is not automatically a compliance requirement for every private organization.</p>\n<p>The underlying principle applies broadly: a card&#8217;s technology cannot compensate for stale authorization. One person may hold several legitimate credentials, including a mobile instance, but each credential must remain traceable to a verified identity, sponsor, status, access approval, issue event, and expiration or review rule.</p>\n\n<h2>Separate lifecycle responsibilities</h2>\n<p>The authoritative personnel or contractor owner confirms relationship status. A manager sponsors business need. The protected-area owner approves sensitive-space access. The credential administrator encodes, issues, suspends, replaces, and revokes credentials. Physical security defines policy, reconciles records, monitors exceptions, and tests performance. Avoid requester self-approval and shared badge-holder records.</p>\n<p>Before issue, authenticate the request and recipient, check for duplicate or active credentials, approve the least access needed, and document special doors, schedules, anti-passback exceptions, and expiration. Record the unique credential identifier, technology, issuer, recipient, activation, sponsor, and acknowledgement. Test an intended door and a representative denial without recording reusable credential secrets in the ticket.</p>\n\n<h2>DSE recommendation: make changes event-driven</h2>\n<ol>\n<li>Connect joiner, mover, leave, contract-end, and termination events to the credential process with defined completion targets and acknowledgements.</li>\n<li>On a role or location change, remove access tied only to the prior assignment. Require fresh approval for restricted areas instead of copying the old profile wholesale.</li>\n<li>On reported loss, authenticate the reporter, disable the affected credential promptly, review relevant activity, issue a different identifier, and document investigation or notification decisions.</li>\n<li>At departure, coordinate timing with the authorized personnel process, revoke every card, fob, mobile instance, and associated permission, recover property, and verify completion. Property return does not replace electronic revocation.</li>\n<li>Review active credentials against authoritative people, sponsor, access-level, expiration, inventory, and activity records. Include contractors, visitors, emergency badges, guard credentials, test cards, and dormant mobile instances.</li>\n<li>Control blank stock, returned cards, printers, keys, mobile licenses, and destruction. Prevent a returned or replaced identifier from silently remaining active.</li>\n</ol>\n<p>Measure median and maximum revocation time, credentials without current sponsors, overdue temporary access, dormant active credentials, lost-credential replacements, inventory differences, and unresolved privileged access. Set review frequency by risk: a data center, cash room, laboratory, executive area, or round-the-clock entrance may justify more frequent review than a public lobby. Every exception should have a reason, accountable owner, expiration, and closure evidence.</p>",
        "content_text": "Source fact: authorization and credentials require continuing control\nNIST SP 800-53 Rev. 5 Update 1 provides a catalog of security and privacy controls that organizations tailor to their risks. Physical and Environmental Protection control PE-2 addresses authorizing physical access, maintaining an authorized-access list, issuing credentials, reviewing access, and removing people from the list when access is no longer required. PE-3 addresses enforcing physical access and maintaining relevant access records. The publication is mandatory in specified federal contexts, but it is not automatically a compliance requirement for every private organization.\nThe underlying principle applies broadly: a card’s technology cannot compensate for stale authorization. One person may hold several legitimate credentials, including a mobile instance, but each credential must remain traceable to a verified identity, sponsor, status, access approval, issue event, and expiration or review rule.\n\nSeparate lifecycle responsibilities\nThe authoritative personnel or contractor owner confirms relationship status. A manager sponsors business need. The protected-area owner approves sensitive-space access. The credential administrator encodes, issues, suspends, replaces, and revokes credentials. Physical security defines policy, reconciles records, monitors exceptions, and tests performance. Avoid requester self-approval and shared badge-holder records.\nBefore issue, authenticate the request and recipient, check for duplicate or active credentials, approve the least access needed, and document special doors, schedules, anti-passback exceptions, and expiration. Record the unique credential identifier, technology, issuer, recipient, activation, sponsor, and acknowledgement. Test an intended door and a representative denial without recording reusable credential secrets in the ticket.\n\nDSE recommendation: make changes event-driven\n\nConnect joiner, mover, leave, contract-end, and termination events to the credential process with defined completion targets and acknowledgements.\nOn a role or location change, remove access tied only to the prior assignment. Require fresh approval for restricted areas instead of copying the old profile wholesale.\nOn reported loss, authenticate the reporter, disable the affected credential promptly, review relevant activity, issue a different identifier, and document investigation or notification decisions.\nAt departure, coordinate timing with the authorized personnel process, revoke every card, fob, mobile instance, and associated permission, recover property, and verify completion. Property return does not replace electronic revocation.\nReview active credentials against authoritative people, sponsor, access-level, expiration, inventory, and activity records. Include contractors, visitors, emergency badges, guard credentials, test cards, and dormant mobile instances.\nControl blank stock, returned cards, printers, keys, mobile licenses, and destruction. Prevent a returned or replaced identifier from silently remaining active.\n\nMeasure median and maximum revocation time, credentials without current sponsors, overdue temporary access, dormant active credentials, lost-credential replacements, inventory differences, and unresolved privileged access. Set review frequency by risk: a data center, cash room, laboratory, executive area, or round-the-clock entrance may justify more frequent review than a public lobby. Every exception should have a reason, accountable owner, expiration, and closure evidence.",
        "content_markdown": "## Source fact: authorization and credentials require continuing control\n\nNIST [SP 800-53 Rev. 5 Update 1](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) provides a catalog of security and privacy controls that organizations tailor to their risks. Physical and Environmental Protection control PE-2 addresses authorizing physical access, maintaining an authorized-access list, issuing credentials, reviewing access, and removing people from the list when access is no longer required. PE-3 addresses enforcing physical access and maintaining relevant access records. The publication is mandatory in specified federal contexts, but it is not automatically a compliance requirement for every private organization.\n\nThe underlying principle applies broadly: a card’s technology cannot compensate for stale authorization. One person may hold several legitimate credentials, including a mobile instance, but each credential must remain traceable to a verified identity, sponsor, status, access approval, issue event, and expiration or review rule.\n\n## Separate lifecycle responsibilities\n\nThe authoritative personnel or contractor owner confirms relationship status. A manager sponsors business need. The protected-area owner approves sensitive-space access. The credential administrator encodes, issues, suspends, replaces, and revokes credentials. Physical security defines policy, reconciles records, monitors exceptions, and tests performance. Avoid requester self-approval and shared badge-holder records.\n\nBefore issue, authenticate the request and recipient, check for duplicate or active credentials, approve the least access needed, and document special doors, schedules, anti-passback exceptions, and expiration. Record the unique credential identifier, technology, issuer, recipient, activation, sponsor, and acknowledgement. Test an intended door and a representative denial without recording reusable credential secrets in the ticket.\n\n## DSE recommendation: make changes event-driven\n\n- Connect joiner, mover, leave, contract-end, and termination events to the credential process with defined completion targets and acknowledgements.\n\n- On a role or location change, remove access tied only to the prior assignment. Require fresh approval for restricted areas instead of copying the old profile wholesale.\n\n- On reported loss, authenticate the reporter, disable the affected credential promptly, review relevant activity, issue a different identifier, and document investigation or notification decisions.\n\n- At departure, coordinate timing with the authorized personnel process, revoke every card, fob, mobile instance, and associated permission, recover property, and verify completion. Property return does not replace electronic revocation.\n\n- Review active credentials against authoritative people, sponsor, access-level, expiration, inventory, and activity records. Include contractors, visitors, emergency badges, guard credentials, test cards, and dormant mobile instances.\n\n- Control blank stock, returned cards, printers, keys, mobile licenses, and destruction. Prevent a returned or replaced identifier from silently remaining active.\n\nMeasure median and maximum revocation time, credentials without current sponsors, overdue temporary access, dormant active credentials, lost-credential replacements, inventory differences, and unresolved privileged access. Set review frequency by risk: a data center, cash room, laboratory, executive area, or round-the-clock entrance may justify more frequent review than a public lobby. Every exception should have a reason, accountable owner, expiration, and closure evidence."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/",
                "url": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-28"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Control physical access credentials from issue through revocation",
                        "item": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/#article",
                "identifier": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/",
                "url": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/",
                "headline": "Control physical access credentials from issue through revocation",
                "description": "A physical credential remains trustworthy only when identity verification, approval, issuance, access changes, loss response, periodic review, and…",
                "abstract": "A physical credential remains trustworthy only when identity verification, approval, issuance, access changes, loss response, periodic review, and revocation operate as one controlled lifecycle.",
                "articleBody": "Source fact: authorization and credentials require continuing control\nNIST SP 800-53 Rev. 5 Update 1 provides a catalog of security and privacy controls that organizations tailor to their risks. Physical and Environmental Protection control PE-2 addresses authorizing physical access, maintaining an authorized-access list, issuing credentials, reviewing access, and removing people from the list when access is no longer required. PE-3 addresses enforcing physical access and maintaining relevant access records. The publication is mandatory in specified federal contexts, but it is not automatically a compliance requirement for every private organization.\nThe underlying principle applies broadly: a card’s technology cannot compensate for stale authorization. One person may hold several legitimate credentials, including a mobile instance, but each credential must remain traceable to a verified identity, sponsor, status, access approval, issue event, and expiration or review rule.\n\nSeparate lifecycle responsibilities\nThe authoritative personnel or contractor owner confirms relationship status. A manager sponsors business need. The protected-area owner approves sensitive-space access. The credential administrator encodes, issues, suspends, replaces, and revokes credentials. Physical security defines policy, reconciles records, monitors exceptions, and tests performance. Avoid requester self-approval and shared badge-holder records.\nBefore issue, authenticate the request and recipient, check for duplicate or active credentials, approve the least access needed, and document special doors, schedules, anti-passback exceptions, and expiration. Record the unique credential identifier, technology, issuer, recipient, activation, sponsor, and acknowledgement. Test an intended door and a representative denial without recording reusable credential secrets in the ticket.\n\nDSE recommendation: make changes event-driven\n\nConnect joiner, mover, leave, contract-end, and termination events to the credential process with defined completion targets and acknowledgements.\nOn a role or location change, remove access tied only to the prior assignment. Require fresh approval for restricted areas instead of copying the old profile wholesale.\nOn reported loss, authenticate the reporter, disable the affected credential promptly, review relevant activity, issue a different identifier, and document investigation or notification decisions.\nAt departure, coordinate timing with the authorized personnel process, revoke every card, fob, mobile instance, and associated permission, recover property, and verify completion. Property return does not replace electronic revocation.\nReview active credentials against authoritative people, sponsor, access-level, expiration, inventory, and activity records. Include contractors, visitors, emergency badges, guard credentials, test cards, and dormant mobile instances.\nControl blank stock, returned cards, printers, keys, mobile licenses, and destruction. Prevent a returned or replaced identifier from silently remaining active.\n\nMeasure median and maximum revocation time, credentials without current sponsors, overdue temporary access, dormant active credentials, lost-credential replacements, inventory differences, and unresolved privileged access. Set review frequency by risk: a data center, cash room, laboratory, executive area, or round-the-clock entrance may justify more frequent review than a public lobby. Every exception should have a reason, accountable owner, expiration, and closure evidence.",
                "datePublished": "2026-07-28T14:22:00+00:00",
                "dateModified": "2026-07-28T14:22:00+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/physical-access-credential-lifecycle-badges-cards-mobile/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Access Control"
                ],
                "keywords": [
                    "Access Control",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    }
                ],
                "wordCount": 450,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "NIST SP 800-53 Rev. 5 Update 1: Security and Privacy Controls",
                    "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
                    "datePublished": "2020-09-23"
                }
            }
        ]
    }
}