External Personnel Security
Description
a. Establish personnel security requirements, including security roles and responsibilities for external providers; b. Require external providers to comply with personnel security policies and procedures established by the organization; c. Document personnel security requirements; d. Require external providers to notify [organization-defined parameter] of any personnel transfers or terminations of external personnel who possess organizational credentials and/or badges, or who have system privileges within [organization-defined parameter] ; and e. Monitor provider compliance with personnel security requirements.
Mapped SPARTA techniques
2 techniques
PS-7 (External Personnel Security) addresses external-staff governance for ATLO contractors and integrators.
PS-7 (External Personnel Security) addresses governance of third-party personnel who have access to organizational systems and information. REC-0008.04 reconnaissance targets the structure of those third-party relationships to identify weakly-governed entry points; PS-7 documentation and access governance reduce the residual exposure that such reconnaissance would exploit.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Referenced by 2 in NIST Cybersecurity Framework 2.0
Cite as SafeMode Space, nist-80053-rev5 PS-7.