What you need to know
A cardholder export shows what the system grants, not what a person still needs. Have accountable role and area owners affirm required access, challenge exceptions, remove stale grants, and verify the controller received the change.
Potentially affected
Employees, contractors, visitors with recurring access, badges and mobile credentials, access levels, schedules, door groups, sensitive areas, HR and vendor lifecycle events, physical keys used as exceptions, PACS integrations, and audit evidence.
DSE recommendation
Build a complete identity-to-access inventory, route each grant to the accountable role and area owners with business context, expire or remove unsupported access, reconcile changes to field panels and exceptions, and retain evidence of decision and verification.
Source facts: authorization lists are meant to be maintained and reviewed
NIST Special Publication 800-53 Revision 5.1, control PE-2, calls for developing, approving, and maintaining a list of individuals authorized for physical access, issuing authorization credentials, reviewing the list at an organization-defined frequency, and removing people when access is no longer required. Its first enhancement addresses authorization based on position or role.
CISA’s Facility Access Control: An Interagency Security Committee Best Practice discusses the access-control process for federal facilities, including employees, visitors, screening, authentication, and physical access control systems. It stresses that risk and operations shape the selected controls.
Both publications are U.S. federal guidance. They do not automatically impose a particular review interval or access model on a private organization. Applicable law, regulation, contract, collective bargaining, safety needs, building rules, and the organization’s risk decisions govern. The DSE process below is an operational recommendation, not a compliance determination.
DSE recommendation: make need the input and system state the verified output
Do not send managers a raw list of badge numbers and ask whether it “looks right.” Build a review package around people and work. For each identity, show employer or sponsor, status, role, home location, supervisor, contract end date, credential type, access levels, schedules, sensitive doors, last relevant use where lawful, and exceptions. Separate reliable source data from unresolved mismatches.
- Define ownership. The manager or contract sponsor confirms that the person still requires access for assigned work. The area owner confirms that the role may enter the protected space. Security administers the system but should not invent the business need.
- Review roles before people. Validate what each standard role should receive, including schedules and holidays. Removing obsolete doors from a role can correct many cardholders consistently. Keep high-risk and emergency roles narrow and named.
- Challenge direct grants. Identify access outside a standard role, 24-hour schedules, broad master groups, temporary projects, transferred staff, dormant credentials, duplicate identities, indefinite contractors, and people whose manager or sponsor is missing. Require a reason, owner, and expiry.
- Resolve lifecycle conflicts. Reconcile HR, contractor, training, licensing, safety, tenant, and PACS records. A person marked active in one system may have changed role or site in another. Escalate discrepancies rather than silently choosing the most permissive state.
- Apply with control. Use approved change records, second review for sensitive areas, and a defined emergency-access path. Consider safety and continuity before mass removal. Do not use access history alone to revoke a grant that is legitimately needed only during rare events.
- Verify the field result. Confirm removed access is absent from the credential, access level, downstream controller or lock, mobile credential service, visitor platform, and documented physical-key exception. Sample denied transactions or use an approved test credential without inconveniencing occupants.
Track completion by decision quality, not by percentage of emails answered. An approval with no accountable owner, “keep all,” or an unresolved system mismatch is not complete. Age outstanding reviews, suspend or escalate according to policy, and give security leadership a view of unsupported high-risk access.
Retain the reviewed population, data cutoff, decisions, approvers, changes, verification, unresolved exceptions, and next due date. Protect the review package because it maps people to secured areas. The result should answer two different questions with evidence: why the person needs entry, and whether the deployed system now enforces that approved need.
Measure unsupported direct grants, overdue decisions, identities without sponsors, expired contractors still enabled, failed controller updates, and high-risk exceptions by age. Stop a review wave when source data is materially incomplete or the change pipeline cannot verify removals. Fix the data or deployment control first; a fast attestation on an unreliable population creates false assurance.
Official references
- National Institute of Standards and Technology, SP 800-53 Revision 5.1, PE-2 Physical Access Authorizations.
- Cybersecurity and Infrastructure Security Agency, Interagency Security Committee, Facility Access Control: An ISC Best Practice.
Review the official source
NIST SP 800-53 Revision 5.1: Security and Privacy Controls for Information Systems and Organizations · Verified August 17, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE