NIST SP 800-53 Rev. 5
PS-7
Personnel Security

External Personnel Security

Description

a. Establish personnel security requirements, including security roles and responsibilities for external providers; b. Require external providers to comply with personnel security policies and procedures established by the organization; c. Document personnel security requirements; d. Require external providers to notify [organization-defined parameter] of any personnel transfers or terminations of external personnel who possess organizational credentials and/or badges, or who have system privileges within [organization-defined parameter] ; and e. Monitor provider compliance with personnel security requirements.

Mapped SPARTA techniques

2 techniques

  • PS-7 (External Personnel Security) addresses external-staff governance for ATLO contractors and integrators.

  • REC-0008.04Business RelationshipsST0001
    addresses
    moderate

    PS-7 (External Personnel Security) addresses governance of third-party personnel who have access to organizational systems and information. REC-0008.04 reconnaissance targets the structure of those third-party relationships to identify weakly-governed entry points; PS-7 documentation and access governance reduce the residual exposure that such reconnaissance would exploit.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Cite as SafeMode Space, nist-80053-rev5 PS-7.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.