GuideAdvisoryAccess Control

Control physical access credentials from issue through revocation

A physical credential remains trustworthy only when identity verification, approval, issuance, access changes, loss response, periodic review, and revocation operate as one controlled lifecycle.

Executive summary

What you need to know

A physical credential remains trustworthy only when identity verification, approval, issuance, access changes, loss response, periodic review, and revocation operate as one controlled lifecycle.

Potentially affected

Organizations that issue employee, contractor, visitor, temporary, card, fob, smart-card, emergency, test, or mobile credentials through a physical access control system.

DSE recommendation

Map the credential lifecycle to named owners and measurable time limits, then reconcile people, credentials, access levels, lifecycle events, and physical inventory with defensible evidence.

Source fact: authorization and credentials require continuing control

NIST SP 800-53 Rev. 5 Update 1 provides a catalog of security and privacy controls that organizations tailor to their risks. Physical and Environmental Protection control PE-2 addresses authorizing physical access, maintaining an authorized-access list, issuing credentials, reviewing access, and removing people from the list when access is no longer required. PE-3 addresses enforcing physical access and maintaining relevant access records. The publication is mandatory in specified federal contexts, but it is not automatically a compliance requirement for every private organization.

The underlying principle applies broadly: a card’s technology cannot compensate for stale authorization. One person may hold several legitimate credentials, including a mobile instance, but each credential must remain traceable to a verified identity, sponsor, status, access approval, issue event, and expiration or review rule.

Separate lifecycle responsibilities

The authoritative personnel or contractor owner confirms relationship status. A manager sponsors business need. The protected-area owner approves sensitive-space access. The credential administrator encodes, issues, suspends, replaces, and revokes credentials. Physical security defines policy, reconciles records, monitors exceptions, and tests performance. Avoid requester self-approval and shared badge-holder records.

Before issue, authenticate the request and recipient, check for duplicate or active credentials, approve the least access needed, and document special doors, schedules, anti-passback exceptions, and expiration. Record the unique credential identifier, technology, issuer, recipient, activation, sponsor, and acknowledgement. Test an intended door and a representative denial without recording reusable credential secrets in the ticket.

DSE recommendation: make changes event-driven

  1. Connect joiner, mover, leave, contract-end, and termination events to the credential process with defined completion targets and acknowledgements.
  2. On a role or location change, remove access tied only to the prior assignment. Require fresh approval for restricted areas instead of copying the old profile wholesale.
  3. On reported loss, authenticate the reporter, disable the affected credential promptly, review relevant activity, issue a different identifier, and document investigation or notification decisions.
  4. At departure, coordinate timing with the authorized personnel process, revoke every card, fob, mobile instance, and associated permission, recover property, and verify completion. Property return does not replace electronic revocation.
  5. Review active credentials against authoritative people, sponsor, access-level, expiration, inventory, and activity records. Include contractors, visitors, emergency badges, guard credentials, test cards, and dormant mobile instances.
  6. Control blank stock, returned cards, printers, keys, mobile licenses, and destruction. Prevent a returned or replaced identifier from silently remaining active.

Measure median and maximum revocation time, credentials without current sponsors, overdue temporary access, dormant active credentials, lost-credential replacements, inventory differences, and unresolved privileged access. Set review frequency by risk: a data center, cash room, laboratory, executive area, or round-the-clock entrance may justify more frequent review than a public lobby. Every exception should have a reason, accountable owner, expiration, and closure evidence.

Primary reference

Review the official source

NIST SP 800-53 Rev. 5 Update 1: Security and Privacy Controls · Published September 23, 2020

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE