PE-8(3)

  • Requirement

    Limit personally identifiable information contained in visitor access records to the following elements identified in the privacy risk assessment: [Assignment: organization-defined elements].

  • Discussion

    Organizations may have requirements that specify the contents of visitor access records. Limiting personally identifiable information in visitor access records when such information is not needed for operational purposes helps reduce the level of privacy risk created by a system.

More Info

  • Title

    Visitor Access Records | Limit Personally Identifiable Information Elements
  • Family

    Physical and Environmental Protection
  • NIST 800-53B Baseline(s)

    • Privacy
  • Related NIST 800-53 ID

    RA-3;SA-8

NIST 800-53A Assessment Guidance

CMMC Training

Our CMMC Overview Course simplifies CMMC. Enroll so you can make informed decisions!