Personnel Security (PS)¶
Domain: Personnel Security (PS)
Requirements in this domain: 2
Assessment Objectives in this domain: 4
PS.L2-3.9.1¶
PS.L2-3.9.1[a]¶
Assessment Objective
individuals are screened prior to authorizing access to organizational systems.
Collection Approach: Artifact
Potential Evidence Examples
Screening/background-check records (or confirmation of completion from HR, redacted as needed) showing personnel were screened before being granted access to organizational systems containing CUI.
Assessment Guide – Further Discussion
Are appropriate background checks completed prior granting access to organizational systems containing CUI [a]?
PS.L2-3.9.2¶
PS.L2-3.9.2[a]¶
Assessment Objective
a policy and/or process for terminating system access authorization and any credentials coincident with personnel actions is established.
Collection Approach: Document
Potential Evidence Examples
Personnel Security Policy/Procedure and companion Access Control Policy/Procedure describing how system access and credentials are terminated or adjusted coincident with personnel actions (termination, transfer, role change).
Assessment Guide – Further Discussion
- Is all company information system-related property retrieved from the terminated or transferred employee within a certain timeframe [a,c]?
- Is access to company information and information systems formerly controlled by the terminated or transferred employee retained for a certain timeframe [a,c]?
- Is the information security office and data owner of the change in authorization notified within a certain timeframe [a]?
PS.L2-3.9.2[b]¶
Assessment Objective
system access and credentials are terminated consistent with personnel actions such as termination or transfer.
Collection Approach: Artifact
Potential Evidence Examples
Sampled offboarding/transfer record (e.g., HR termination notice plus IT account-disable ticket, timestamped) showing account access and credentials were actually terminated or modified in conjunction with the personnel action.
Assessment Guide – Further Discussion
Are authenticators/credentials associated with the employee revoked upon termination or transfer within a certain time frame [b,c]?
PS.L2-3.9.2[c]¶
Assessment Objective
the system is protected during and after personnel transfer actions.
Collection Approach: Artifact
Potential Evidence Examples
Completed personnel out-processing/transfer checklist showing steps taken to protect the system during and after the transfer (e.g., access review, equipment return, credential revocation confirmation).
Assessment Guide – Further Discussion
- Is all company information system-related property retrieved from the terminated or transferred employee within a certain timeframe [a,c]?
- Is access to company information and information systems formerly controlled by the terminated or transferred employee retained for a certain timeframe [a,c]?
- Are authenticators/credentials associated with the employee revoked upon termination or transfer within a certain time frame [b,c]?
- Is information system access disabled upon employee termination or transfer [c]?