Personnel Security¶
This template is the starting point for how your organization designates the trust required by each position, screens people before they are granted access, rescreens them on a defined trigger, binds them to an access agreement, and adjusts or removes their access when they transfer or leave. It also covers the personnel security requirements you impose on external providers and the sanctions process that backs your policies.
Personnel security is the one control family the platform cannot execute for you. Background checks happen at your organization, under your legal counsel, before an account is ever requested. What the platform does is gate access on the outcome, hold the record, and evidence that the practice ran. Fill in the sample sections with what your organization actually does, then keep the User Access Request records current so the evidence matches the practice.
This document is also your Personnel Security policy and procedures. It is the document PS-1 asks for.
Quick Summary
A client-fillable template covering the personnel security practice the provider of the offering owns. Personnel security is the one control family the platform cannot execute for you: background checks happen at your organization, under your legal counsel, before an account is ever requested. What the platform does is gate access on the outcome, hold the record, and evidence that the practice ran. The template carries sample text you replace with your real practice, the full Rev5 PS family, the five 20x Key Security Indicators that carry PS lineage, the two CMMC Level 2 PS practices, and a values table that marks every FedRAMP-mandated floor.
Customer-owned template
This is a starting-point template delivered with GRC-ITSM. The practices it describes are owned and executed by your organization, not by the platform. Fill the Organization-Defined Values, remove framework rows you are not pursuing, and adopt it as your own document before relying on it.
Screening is regulated, and the results do not belong in the platform
What you may check, and what you may act on, varies by jurisdiction, so the screening section belongs to your legal counsel as much as to your security function. Record in the platform that screening completed and when. Keep the underlying check results with the role that holds them.
Related documentation
- Client Template Library
- Policies & Procedures
- Access Management -- the User Access Request lifecycle these records live in
- Continuous Monitoring & Reporting -- the recurring account reviews that surface stale access
- Governance, Training & Secure Development -- the training half of KSI-CED-RAT
Download the KB article (Markdown)
Official FedRAMP references
Requirements this document answers¶
Personnel security is answered differently by each of the three frameworks, and the differences matter when you decide how much of this template to fill.
FedRAMP Rev5 (NIST 800-53). The full PS family, every control in the Low baseline and therefore in Moderate and High as well.
| Control | Name | What it asks for |
|---|---|---|
| PS-1 | Policy and Procedures | This document: a personnel security policy and the procedures implementing it, disseminated, owned by a designated official, and reviewed on two separate cadences |
| PS-2 | Position Risk Designation | A risk designation on every position, screening criteria for each, and a standing review of the designations |
| PS-3 | Personnel Screening | Screening before access is authorized, and rescreening on defined conditions |
| PS-3(3) | Information Requiring Special Protective Measures | Additional screening criteria where the information demands it (Moderate and above) |
| PS-4 | Personnel Termination | Access disabled on a clock, credentials revoked, exit interview, property retrieved, information retained |
| PS-5 | Personnel Transfer | Access reconfirmed on reassignment, transfer actions initiated on a clock, notifications sent |
| PS-6 | Access Agreements | Agreements developed, reviewed, signed before access and re-signed on update |
| PS-7 | External Personnel Security | Personnel security requirements imposed on external providers, with notification of their transfers and terminations |
| PS-8 | Personnel Sanctions | A formal sanctions process, with notification when one is initiated |
| PS-9 | Position Descriptions | Security and privacy roles written into position descriptions |
At High (Class D) the baseline adds PS-4(2), automated notification of termination actions. It is out of scope for Class C and this template does not carry it.
FedRAMP 20x. There is no Personnel Security Key Security Indicator family. PS controls appear as underlying lineage beneath five indicators in other families, which means 20x asks you to demonstrate the outcome rather than to produce a personnel security document.
| KSI | Name | PS lineage |
|---|---|---|
| KSI-IAM-ELP | Ensuring Least Privilege | PS-2, PS-3, PS-4, PS-5, PS-6 |
| KSI-IAM-JIT | Authorizing Just-in-Time | PS-2, PS-3, PS-4, PS-5, PS-6, PS-9 |
| KSI-IAM-SUS | Responding to Suspicious Activity | PS-4, PS-8 |
| KSI-CED-RAT | Reviewing All Training | PS-6 |
| KSI-SCR-MON | Monitoring Supply Chain Risk | PS-7 |
Note what is absent: no KSI carries PS-1. Under 20x alone there is no indicator that asks whether this document exists. If you are pursuing 20x only, this template is still worth adopting, because the screening and personnel-action practices it describes are what the five indicators above are evidenced on, but the policy obligation itself comes from Rev5 and CMMC.
CMMC Level 2. Two practices, both in the PS domain, both derived from NIST SP 800-171 Rev. 2.
| Practice | Name | Assessment objectives |
|---|---|---|
| PS.L2-3.9.1 | Screen Individuals | [a] individuals are screened prior to authorizing access to organizational systems containing CUI |
| PS.L2-3.9.2 | Personnel Actions | [a] a policy and/or process for terminating system access and any credentials coincident with personnel actions is established; [b] system access and credentials are terminated consistent with personnel actions such as termination or transfer; and [c] the system is protected during and after personnel transfer actions |
CMMC assessors examine the personnel security policy, the screening procedures, and the records of screened personnel, and they interview personnel with personnel security responsibilities. Objective [a] on PS.L2-3.9.2 is a documentation objective: the policy or process must exist as a document, not only as a habit.
Sample practice: position risk designation and screening criteria¶
Sample text. [Organization] assigns a risk designation to every position with access to the system, using [designation scheme]. The designation is set when the position is created and reviewed on the cadence in the values table. Each designation carries its own screening criteria: what checks are performed, what results disqualify, and what adjudication path applies to an adverse result. Security and privacy responsibilities appropriate to the designation are written into the position description before the position is posted.
Replace with your practice. Name the designation scheme and the role that assigns it. PS-9 is satisfied by the position description work in the last sentence, so make sure that step is real and not a statement of intent. PS-2 requires the designations be reviewed, and FedRAMP sets the floor at every three years.
Sample practice: screening before access¶
Sample text. No individual is granted access to the system before screening completes and is adjudicated favorably for the risk designation of their position. Screening for [designation] positions comprises [checks: identity verification, criminal history, employment verification, education verification, credit check where the position warrants it, and any sector-specific check]. Screening is performed by [provider or internal function] under [legal framework], and the checks performed reflect applicable laws, executive orders, directives, regulations, policies, and the criteria established for the level of access required.
Sample text. The screening outcome is recorded as [record], held by [role] under [retention period]. The record states that screening completed and was adjudicated, and the date; it does not travel into the platform, and the underlying check results stay with [role]. A User Access Request for an individual whose screening has not completed is rejected at approval.
Replace with your practice. Name the checks per designation, who performs them, and where the outcome is held. Two cautions. First, background screening is regulated: what you may check, and what you may act on, varies by jurisdiction, so this section belongs to your legal counsel as much as to your security function. Second, keep the check results out of the platform. The platform needs to know that screening passed and when; it does not need the report.
Sample practice: rescreening¶
Sample text. Individuals are rescreened when [conditions], and on the frequency set for their position's risk designation. Rescreening also occurs out of cycle on [triggers: a change in position risk designation, a documented security concern, a sanctions action, or a break in employment exceeding [period]]. An individual whose rescreening is overdue [treatment: access suspended, or access retained pending completion with a documented risk acceptance by [role]].
Replace with your practice. Rescreening is where most personnel security programs actually fail an assessment, because the initial screen is easy to evidence and the recurring one is not. Put a real trigger and a real treatment for the overdue case in the values table, and make sure something generates the reminder.
Sample practice: access agreements¶
Sample text. Every individual requiring access signs [agreements: rules of behavior, acceptable use, non-disclosure] before access is granted. The agreements are reviewed and updated on the cadence in the values table, and individuals re-sign when an agreement is updated, when their level of access changes, and otherwise on the standing cadence. [Role] holds the signed agreements and reconciles the signed set against the active account set [cadence]; an account with no current signed agreement is raised as a finding.
Replace with your practice. The reconciliation sentence is the part that gets evidenced. A stack of signed agreements proves people signed something; a reconciliation against active accounts proves nobody slipped through.
Sample practice: transfer and termination¶
Sample text. On a transfer or reassignment, [role] reviews the individual's existing logical and physical access against the operational need of the new position and confirms, modifies, or removes each authorization. The transfer actions are initiated within the period in the values table, and [notification recipients, including the access control personnel responsible for the system] are notified within the notification period. Access that the new position does not need is removed rather than left in place pending review.
Sample text. On termination, system access is disabled within the period in the values table, authenticators and credentials associated with the individual are terminated or revoked, an exit interview covering [topics] is conducted, security-related organizational property is retrieved, and the organization retains access to the information and systems the individual controlled. Where a termination follows a security concern, access is disabled first and the remaining steps follow.
Replace with your practice. This is the pair CMMC PS.L2-3.9.2 examines and the pair KSI-IAM-SUS is evidenced on. FedRAMP sets hard clocks here: four hours to disable on termination, twenty-four hours on transfer actions and notifications. Those are floors, not targets.
Sample practice: external personnel¶
Sample text. External providers whose personnel hold organizational credentials, badges, or system privileges are bound by [contract mechanism] to personnel security requirements equivalent to those above, including screening to the risk designation of the access granted. The contract names the security roles and responsibilities of the provider's personnel, requires the provider to notify [recipients] of any transfer or termination of covered personnel within the notification period, and permits [monitoring mechanism] to verify compliance. Provider compliance is reviewed [cadence], and a provider that cannot meet the notification requirement is recorded as a gap with a compensating measure.
Replace with your practice. PS-7 is the control auditors reach for when a subcontractor's departed engineer still has a valid credential. The notification clause is the substance; name where it lives in the agreement.
Sample practice: sanctions¶
Sample text. [Organization] operates a formal sanctions process for individuals who fail to comply with information security and privacy policies and procedures, run by [role] under [policy reference]. When a formal sanctions process is initiated, [recipients, to include the ISSO or equivalent] are notified within the notification period, identifying the individual and the reason. Sanctions outcomes that change an individual's access are executed as User Access Requests so the access change carries the same record as any other.
Replace with your practice. Sanctions usually already exist inside an HR disciplinary policy. PS-8 does not require a separate process, only that the security-relevant one is formal and that the ISSO learns of it on a clock. Point at the HR policy rather than duplicating it.
Organization-defined values¶
FedRAMP defines values for many of the slots below. Where the Notes column says MUST, the value is a framework floor: you may be stricter, never looser, and an interview that "confirms" a looser value produces a finding. Each MUST value is quoted verbatim from its baseline parameter, so the wording varies where FedRAMP's own wording varies. Rows marked Moderate and above have no FedRAMP-defined value in the Low baseline.
| Value | Setting | Notes |
|---|---|---|
| Policy dissemination audience | [personnel or roles] | PS-1 (a) |
| Policy level | [Organization-level, Mission/business process-level, or System-level] | PS-1 (a)(1) |
| Designated official for the policy | [role] | PS-1 (b), manages development, documentation, and dissemination |
| Policy review cadence | [cadence] | PS-1 ©(1) MUST: at least every 3 years |
| Policy review events | [events] | PS-1 ©(1), no FedRAMP-defined value |
| Procedure review cadence | [cadence] | PS-1 ©(2) MUST: at least annually |
| Procedure review events | [events] | PS-1 ©(2) MUST: significant changes |
| Position risk designation scheme | [scheme] | PS-2 (a) |
| Position risk designation review cadence | [cadence] | PS-2 © MUST: at least every three years |
| Screening checks per designation | [checks] | PS-2 (b), PS-3 (a), PS.L2-3.9.1 [a] |
| Screening provider and legal framework | [provider; framework] | PS-3 (a), PS.L2-3.9.1 [a] |
| Screening outcome record and holder | [record; role] | PS-3 (a), evidence for PS.L2-3.9.1 [a] |
| Screening record retention | [period] | PS-3 (a) |
| Rescreening conditions and frequency | [conditions; frequency] | PS-3 (b) MUST: for national security clearances, reinvestigation in the 5th year for top secret, 10th for secret, 15th for confidential; for moderate risk law enforcement and high impact public trust, the 5th year; no reinvestigation for other moderate risk or any low risk positions |
| Treatment of overdue rescreening | [treatment] | PS-3 (b) |
| Additional screening criteria for specially protected information | [criteria] | PS-3(3)(b) MUST: as required by specific information. Moderate and above |
| Access disable period on termination | [period] | PS-4 (a) MUST: four (4) hours |
| Exit interview security topics | [topics] | PS-4 © |
| Transfer or reassignment actions | [actions] | PS-5 (b) |
| Transfer action initiation period | [period] | PS-5 (b) MUST: twenty-four (24) hours |
| Transfer notification recipients | [recipients] | PS-5 (d) MUST: including access control personnel responsible for the system. Moderate and above; no FedRAMP-defined value at Low |
| Transfer notification period | [period] | PS-5 (d) MUST: twenty-four (24) hours |
| Access agreements in force | [agreements] | PS-6 (a) |
| Access agreement review cadence | [cadence] | PS-6 (b) MUST: at least annually |
| Access agreement re-signing cadence | [cadence] | PS-6 ©(2) MUST: at least annually and any time there is a change to the user's level of access |
| Agreement to account reconciliation cadence | [cadence] | PS-6 ©, evidence for KSI-CED-RAT |
| External provider contract mechanism | [mechanism] | PS-7 (a), PS-7 (b) |
| External personnel notification recipients | [recipients] | PS-7 (d) MUST: including access control personnel responsible for the system and/or facilities, as appropriate |
| External personnel notification period | [period] | PS-7 (d) MUST: within twenty-four (24) hours |
| External provider compliance review cadence | [cadence] | PS-7 (e) |
| Sanctions process owner and policy reference | [role; reference] | PS-8 (a) |
| Sanctions notification recipients | [recipients] | PS-8 (b) MUST: to include the ISSO and/or similar role within the organization |
| Sanctions notification period | [period] | PS-8 (b) MUST: 24 hours. Moderate and above; no FedRAMP-defined value at Low |
| CMMC personnel security values | [per contract] | Per contract (PS.L2-3.9.1, PS.L2-3.9.2) |
| Document owner | [role] | Fills the authority section |
Evidence¶
The GRC-ITSM platform does not screen your people, hold your background check results, or run your sanctions process. It gates access on the screening outcome, carries the personnel actions as records, and evidences that the practice ran. See the Access Management Policy and Procedures for the User Access Request lifecycle these records live in, and the Continuous Monitoring and Reporting Policy and Procedures for the validation tree and check cadences.
| Practice | What the platform records |
|---|---|
| Screening before access | The User Access Request that grants access, approved through the User Access Request Approvers CAB; the approval is the gate that screening must clear first |
| Rescreening | A recurring compliance task the organization configures on its rescreening cadence; overdue rescreenings open Issues tracked to closure |
| Access agreements | The Access agreements review recurring compliance task, annually; the signed set reconciled against active accounts |
| Transfer | An Account Modification User Access Request carrying the access change and its approval |
| Termination | An Account Termination or Account Disable User Access Request, with dated machine validation evidence on the decision |
| Sanctions affecting access | The resulting User Access Request, on the same record path as any other access change |
| External personnel | The external provider as a Component of type Service, with its personnel security contract terms among the documented measures |
The recurring account recertification and the privileged and non-privileged account compliance reviews that surface stale access are owned by the Continuous Monitoring and Reporting Policy and Procedures; the account records they operate on are owned by Access Management. This template governs the personnel practice behind them.
Authority, review, and revision¶
Client fills. Name the executive who issues this document, the role that owns personnel security, the review cadence for the policy and the separate cadence for the procedures, and the approval path for exceptions. State the scope of the policy and how it coordinates among the organizational entities involved, since personnel security spans HR, legal, and security. State that the policy is consistent with the applicable laws, executive orders, directives, regulations, policies, standards, and guidelines that govern your screening program, and name where that register is held. Record the issue date and the revision history below.
PS-1 asks for two review cadences, not one: the policy at least every three years, the procedures at least annually and following significant changes. If you adopt this as a single combined document, state both commitments separately.
| Version | Date | Author | Change |
|---|---|---|---|
| [0.1] | [date] | [author] | Initial draft from template |