Personnel Security
NIST SP 800-53 Rev 5 Personnel Security controls.
Policy and Procedures
Develop, document, and disseminate to [parameter]:
Position Risk Designation
Assign a risk designation to all organizational positions;
Personnel Screening
Screen individuals prior to authorizing access to the system; and
Personnel Termination
Upon termination of individual employment:
Personnel Transfer
Review and confirm ongoing operational need for current logical and physical access authorizations to systems and facilities when individuals are reassigned or transferred to other positions within the organization;
Access Agreements
Develop and document access agreements for organizational systems;
External Personnel Security
Establish personnel security requirements, including security roles and responsibilities for external providers;
Personnel Sanctions
Employ a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures; and
Position Descriptions
Incorporate security and privacy roles and responsibilities into organizational position descriptions.