<section title="9.4. Escorting Uncleared Personnel"><subsection title="Objective"><paragraph
    title="9.4.1."


><![CDATA[<p>Uncleared personnel are escorted within secure areas.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="9.4.2."


><![CDATA[<p>This section covers information relating to the escorting of uncleared personnel without security clearances in secure areas.</p>]]></paragraph>
</block>
</subsection>
<subsection title="PSR references"><paragraph
    title="9.4.3."


><![CDATA[<p class="NormS6C1">Relevant PSR requirements can be found at:</p>
<table class="table-grey" style="width: 112.5%;">
<tbody>
<tr>
<td style="width: 16.9963%;"><strong>Reference</strong></td>
<td style="width: 14.8331%;"><strong>Title</strong></td>
<td style="width: 68.1397%;"><strong>Source</strong></td>
</tr>
<tr>
<td style="width: 16.9963%;">
<p><strong>PSR Mandatory Requirements</strong></p>
</td>
<td style="width: 14.8331%;">GOV4, INFOSEC1, PERSEC1, PERSEC2, PHYSEC1 and PHYSEC2</td>
<td style="width: 68.1397%;">
<p><a title="PSR Home" rel="noopener noreferrer" href="https://www.protectivesecurity.govt.nz/" target="_blank">Home | Protective Security Requirements<br></a></p>
<p><a title="Security Governance" rel="noopener noreferrer" href="https://www.protectivesecurity.govt.nz/policy/security-governance" target="_blank">Security governance (GOV) | Protective Security Requirements</a></p>
<p><a title="Information Secuirty" rel="noopener noreferrer" href="https://www.protectivesecurity.govt.nz/policy/information-security" target="_blank">Information security (INFOSEC) | Protective Security Requirements</a></p>
<p><a title="Personnel Security" rel="noopener noreferrer" href="https://www.protectivesecurity.govt.nz/policy/personnel-security" target="_blank">Personnel security (PERSEC) | Protective Security Requirements</a></p>
<a title="Physical Security" rel="noopener noreferrer" href="https://www.protectivesecurity.govt.nz/policy/physical-security" target="_blank">Physical security (PHYSEC) | Protective Security Requirements</a></td>
</tr>
</tbody>
</table>]]></paragraph>
 </subsection>
<subsection title="Rationale &amp; Controls"> <block title="Unescorted access"><paragraph
    title="9.4.4.R.01."

    tags="Governance,Personnel Security,Facilities"


><![CDATA[<p>Ensuring that personnel have correct security clearances to access sensitive areas and that access by escorted personnel is recorded for auditing purposes is widely considered a standard security practice.</p>]]></paragraph>
<paragraph
    title="9.4.4.C.01."

    tags="Governance,Personnel Security,Facilities"


    classification="Top Secret"
    compliance="Must"
    cid="1569"
><![CDATA[<p>Agencies MUST ensure that all personnel with unescorted access to TOP SECRET areas have appropriate security clearances and briefings.</p>]]></paragraph>
</block>
<block title="Maintaining an unescorted access list"><paragraph
    title="9.4.5.R.01."

    tags="Governance,Personnel Security,Facilities"


><![CDATA[<p>Maintaining an unescorted access list reduces the administrative overhead of determining if personnel can enter a TOP SECRET area without an escort. Personnel with approval for unescorted access must be able to verify their identity at all times while within the secure area.</p>]]></paragraph>
<paragraph
    title="9.4.5.C.01."

    tags="Governance,Personnel Security,Facilities"


    classification="Top Secret"
    compliance="Must"
    cid="1572"
><![CDATA[<p>Agencies MUST maintain an up to date list of personnel entitled to enter a TOP SECRET area without an escort.</p>]]></paragraph>
<paragraph
    title="9.4.5.C.02."

    tags="Governance,Personnel Security,Facilities"


    classification="Top Secret"
    compliance="Must"
    cid="1573"
><![CDATA[<p>Personnel MUST display identity cards at all times while within the secure area.</p>]]></paragraph>
</block>
<block title="Displaying the unescorted access list"><paragraph
    title="9.4.6.R.01."

    tags="Governance,Personnel Security,Facilities"


><![CDATA[<p>Displaying an unescorted access list allows staff to quickly verify if personnel are entitled to be in a TOP SECRET area without an escort. Care should be taken not to reveal the contents of the access list to non-cleared personnel.</p>]]></paragraph>
<paragraph
    title="9.4.6.C.01."

    tags="Governance,Personnel Security,Facilities"


    classification="Top Secret"
    compliance="Should"
    cid="1576"
><![CDATA[<p>Agencies SHOULD display within a TOP SECRET area, an up to date list of personnel entitled to enter the area without an escort.</p>]]></paragraph>
<paragraph
    title="9.4.6.C.02."

    tags="Governance,Personnel Security,Facilities"


    classification="Top Secret"
    compliance="Should Not"
    cid="1577"
><![CDATA[<p>The unescorted access list SHOULD NOT be visible from outside of the secure area.</p>]]></paragraph>
</block>
<block title="Visitors"><paragraph
    title="9.4.7.R.01."

    tags="Governance,Personnel Security,Facilities"


><![CDATA[<p>Visitors to secure areas should be carefully supervised to ensure the need-to-know principle is strictly adhered to.</p>]]></paragraph>
<paragraph
    title="9.4.7.C.01."

    tags="Governance,Personnel Security,Facilities"


    classification="Top Secret"
    compliance="Should"
    cid="1580"
><![CDATA[<p>Visitors SHOULD be carefully supervised to ensure they do not gain access to or have oversight of information above the level of their clearance or outside of their need-to-know.</p>]]></paragraph>
</block>
<block title="Recording visits in a visitor log"><paragraph
    title="9.4.8.R.01."

    tags="Governance,Personnel Security,Facilities"


><![CDATA[<p>Recording visitors to a TOP SECRET area ensures that the agency has a record of visitors should an investigation into an incident need to take place in the future.</p>]]></paragraph>
<paragraph
    title="9.4.8.C.01."

    tags="Governance,Personnel Security,Facilities"


    classification="Top Secret"
    compliance="Must Not"
    cid="1583"
><![CDATA[<p>Agencies MUST NOT permit personnel not on the unescorted access list to enter a TOP SECRET area unless their visit is recorded in a visitor log and they are escorted by a person on the unescorted access list.</p>]]></paragraph>
</block>
<block title="Content of the visitor log"><paragraph
    title="9.4.9.R.01."

    tags="Governance,Personnel Security"


><![CDATA[<p>The contents of the visitor log ensure that security personnel have sufficient details to conduct an investigation into an incident if required.</p>]]></paragraph>
<paragraph
    title="9.4.9.C.01."

    tags="Governance,Personnel Security"


    classification="Top Secret"
    compliance="Must"
    cid="1586"
><![CDATA[<p>Agencies MUST, at minimum, record the following information in a visitor log for each entry:</p><ul>
<li>name;</li>
<li>organisation;</li>
<li>person visiting;</li>
<li>contact details for person visiting; and</li>
<li>date and time in and out.</li>
</ul>]]></paragraph>
</block>
<block title="Separate visitor logs"><paragraph
    title="9.4.10.R.01."

    tags="Governance,Personnel Security"


><![CDATA[<p>Maintaining a separate visitor log for TOP SECRET areas assists in enforcing the need-to-know principle. General visitors do not need-to-know of personnel that have visited TOP SECRET areas.</p>]]></paragraph>
<paragraph
    title="9.4.10.C.01."

    tags="Governance,Personnel Security"


    classification="Top Secret"
    compliance="Must"
    cid="1589"
><![CDATA[<p>Agencies with a TOP SECRET area within a larger facility MUST maintain a separate log from any general visitor log.</p>]]></paragraph>
</block>
</subsection>
</section>
