Physical access requirements incorporate the principle of separation of duties
The principle of separation of duties should be incorporated whenever possible when determining physical access requirements to avoid or reduce the potential impact of errors or malicious activity. For example, an employee may have physical access privileges to enter a facility but may not have access to a server closet.
Related Practices · Input From: Implementing ARCHITECTURE-3a provides input that may be useful for implementing this practice. · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ACCESS-3a, ACCESS-3d, ACCESS-3e, ACCESS-3f, ACCESS-3g.