What you need to know
A mechanical key can bypass identity, schedules, revocation, alarms, and audit trails. Govern high-impact keys with named ownership, least privilege, controlled issue, inventory, return, loss response, and periodic proof of custody.
Potentially affected
Master, grand-master, control, emergency, override, elevator, gate, cabinet, equipment, and restricted keys; key cabinets and lockers; cylinders and cores; locksmith records; contractors; responders; PACS exceptions; and incident procedures.
DSE recommendation
Map each key to the openings and consequences it controls, tier it by impact, minimize copies and master scope, issue to accountable people for defined need and duration, verify custody, integrate loss and offboarding response, and rekey when residual risk is unacceptable.
Source facts: physical access controls require assessable authorization and enforcement
CISA’s Catalog of Recommendations includes physical-access control recommendations to secure keys, combinations, and other physical access devices; inventory those devices periodically; and change keys when they are lost or when holders transfer or terminate. It identifies keys, locks, combinations, and card readers as physical access devices.
NIST SP 800-53 Revision 5.1, control PE-3, independently addresses securing physical access devices, inventorying selected devices at an organization-defined frequency, and changing combinations or keys when they are lost, compromised, or held by people who transfer or terminate.
The General Services Administration’s Physical Access Control Systems in GSA-Controlled Space directive establishes governance for PACS in its scope, including coordinated responsibility and an agency approach. Electronic access policy does not make a building’s mechanical locks, override cylinders, cabinets, or emergency keys disappear.
The CISA control-system catalog is used here as a reference model, not as a universal private-sector requirement, and the GSA directive governs only its stated federal scope. These sources do not set a private company’s legal key-control requirements or prescribe its key hierarchy. Treating a high-impact key as a privileged credential is a DSE governance analogy: both confer authority, require a lifecycle, and can create serious residual access when copied, lost, or not returned. Fire service and emergency keys may be subject to code or authority requirements that take precedence.
DSE recommendation: govern reach, custody, and residual access
Build a controlled key register from locksmith and field verification, not from an inherited spreadsheet alone. For every serialized key or controlled set, identify keyway and mark, openings or key levels reached, cylinder or core population, owner, custodian, approved holders, authorized purpose, issue and return dates, copy restrictions, storage, last verification, and response plan if missing.
- Tier by consequence. Distinguish a single office key from a master that opens perimeter, server, monitoring, medication, evidence, cash, roof, elevator, or life-safety spaces. Apply stronger approval, storage, two-person handling, and verification to broader or more sensitive reach.
- Reduce master scope. Issue the narrowest key that supports the work. Use time-limited checkout for infrequent tasks and avoid permanent contractor masters when supervised or site-specific access works. Do not stamp a key with an address or meaningful room name that helps a finder.
- Control production. Limit ordering, cutting, pinning, duplication, and record access to authorized roles and qualified providers. Reconcile blank stock and issued keys. A “do not duplicate” marking is an instruction, not proof that copying is technically impossible.
- Prove custody. Store reserves and returned keys in an appropriately controlled cabinet or safe. Review high-impact keys more often, require the holder to present the item, and investigate missing signatures, unexplained transfers, damaged seals, or a key that cannot be produced.
- Join the lifecycle. Make key return part of transfer, leave, contract end, and emergency-access review. Human resources or vendor closure should not be considered complete until both electronic and mechanical access are resolved. Preserve lawful responder access.
- Plan for loss. Define immediate reporting, affected-opening analysis, compensating patrol or guard, electronic-event review, stakeholder notice, cylinder or core replacement decision, and documentation. Recovering a key later does not prove it was never copied.
Reconcile mechanical exceptions with PACS designs. If a door is electronically monitored but routinely opened by an untracked key, the operator may receive only a forced-door alarm—or no useful identity at all. Decide whether a monitored key switch, credentialed process, cabinet checkout, or procedural control is appropriate without obstructing required emergency use.
Audit the system by sampling from both directions: select keys and verify every opening they reach; select high-risk openings and identify every key level that reaches them. Protect the resulting map as sensitive security information. Completion means unsupported keys were returned or risk-treated and the organization understands the access that remains—not merely that holders signed a form.
Official references
- Cybersecurity and Infrastructure Security Agency, Catalog of Recommendations, Physical Access Control.
- National Institute of Standards and Technology, SP 800-53 Revision 5.1: Security and Privacy Controls for Information Systems and Organizations, PE-3.
- U.S. General Services Administration, Physical Access Control Systems in GSA-Controlled Space.
Review the official source
CISA Catalog of Recommendations: Physical Access Control · Verified August 17, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE