Skip to content

Personnel Security (PS)

Domain: Personnel Security (PS)
Requirements in this domain: 2
Assessment Objectives in this domain: 4


PS.L2-3.9.1

PS.L2-3.9.1[a]

Assessment Objective

individuals are screened prior to authorizing access to organizational systems.

Collection Approach: Artifact

Potential Evidence Examples

Screening/background-check records (or confirmation of completion from HR, redacted as needed) showing personnel were screened before being granted access to organizational systems containing CUI.

Assessment Guide – Further Discussion

Are appropriate background checks completed prior granting access to organizational systems containing CUI [a]?


PS.L2-3.9.2

PS.L2-3.9.2[a]

Assessment Objective

a policy and/or process for terminating system access authorization and any credentials coincident with personnel actions is established.

Collection Approach: Document

Potential Evidence Examples

Personnel Security Policy/Procedure and companion Access Control Policy/Procedure describing how system access and credentials are terminated or adjusted coincident with personnel actions (termination, transfer, role change).

Assessment Guide – Further Discussion

  • Is all company information system-related property retrieved from the terminated or transferred employee within a certain timeframe [a,c]?
  • Is access to company information and information systems formerly controlled by the terminated or transferred employee retained for a certain timeframe [a,c]?
  • Is the information security office and data owner of the change in authorization notified within a certain timeframe [a]?

PS.L2-3.9.2[b]

Assessment Objective

system access and credentials are terminated consistent with personnel actions such as termination or transfer.

Collection Approach: Artifact

Potential Evidence Examples

Sampled offboarding/transfer record (e.g., HR termination notice plus IT account-disable ticket, timestamped) showing account access and credentials were actually terminated or modified in conjunction with the personnel action.

Assessment Guide – Further Discussion

Are authenticators/credentials associated with the employee revoked upon termination or transfer within a certain time frame [b,c]?


PS.L2-3.9.2[c]

Assessment Objective

the system is protected during and after personnel transfer actions.

Collection Approach: Artifact

Potential Evidence Examples

Completed personnel out-processing/transfer checklist showing steps taken to protect the system during and after the transfer (e.g., access review, equipment return, credential revocation confirmation).

Assessment Guide – Further Discussion

  • Is all company information system-related property retrieved from the terminated or transferred employee within a certain timeframe [a,c]?
  • Is access to company information and information systems formerly controlled by the terminated or transferred employee retained for a certain timeframe [a,c]?
  • Are authenticators/credentials associated with the employee revoked upon termination or transfer within a certain time frame [b,c]?
  • Is information system access disabled upon employee termination or transfer [c]?