Control statement
- a.Screen individuals prior to authorizing access to the system; and
- b.Rescreen individuals in accordance with [Organization-defined: organization-defined conditions requiring rescreening and, where rescreening is so indicated, the frequency of rescreening].
Discussion
Personnel screening and rescreening activities reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, and specific criteria established for the risk designations of assigned positions. Examples of personnel screening include background investigations and agency checks. Organizations may define different rescreening conditions and frequencies for personnel accessing systems based on types of information processed, stored, or transmitted by the systems.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Personnel Screening as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to personnel risk, screening, agreements, transfer, termination, and access consequences.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- screening and suitability records
- access agreements
- transfer and termination checklists
- role change and offboarding evidence
Common failure patterns
- access persists after transfer or separation
- contractor lifecycle handled outside normal controls
- sensitive-role screening not risk based
- termination actions cannot be shown to occur promptly
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- PS-03a.individuals are screened prior to authorizing access to the system;
- PS-03b.
- PS-03b.[01]individuals are rescreened in accordance with [Organization-defined: conditions requiring rescreening];
- PS-03b.[02]where rescreening is so indicated, individuals are rescreened [Organization-defined: frequency].
Examine
- Personnel security policy
- procedures addressing personnel screening
- records of screened personnel
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with personnel security responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for personnel screening
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
PS-3(1) — Classified Information
Verify that individuals accessing a system processing, storing, or transmitting classified information are cleared and indoctrinated to the highest classification level of the information to which they have access on the system.
Official discussion
Classified information is the most sensitive information that the Federal Government processes, stores, or transmits. It is imperative that individuals have the requisite security clearances and system access authorizations prior to gaining access to such information. Access authorizations are enforced by system access controls (see [AC-3](#ac-3) ) and flow controls (see [AC-4](#ac-4)).
Assessment objectives and methods
- PS-03(01)[01]individuals accessing a system processing, storing, or transmitting classified information are cleared;
- PS-03(01)[02]individuals accessing a system processing, storing, or transmitting classified information are indoctrinated to the highest classification level of the information to which they have access on the system.
Examine
- Personnel security policy
- procedures addressing personnel screening
- records of screened personnel
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with personnel security responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for clearing and indoctrinating personnel for access to classified information
Related controls
PS-3(2) — Formal Indoctrination
Verify that individuals accessing a system processing, storing, or transmitting types of classified information that require formal indoctrination, are formally indoctrinated for all the relevant types of information to which they have access on the system.
Official discussion
Types of classified information that require formal indoctrination include Special Access Program (SAP), Restricted Data (RD), and Sensitive Compartmented Information (SCI).
Assessment objectives and methods
individuals accessing a system processing, storing, or transmitting types of classified information that require formal indoctrination are formally indoctrinated for all of the relevant types of information to which they have access on the system.
Examine
- Personnel security policy
- procedures addressing personnel screening
- indoctrination documents
- records of screened personnel
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with personnel security responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for formal indoctrination for all relevant types of information to which personnel have access
Related controls
PS-3(3) — Information Requiring Special Protective Measures
Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection:
- (a)Have valid access authorizations that are demonstrated by assigned official government duties; and
- (b)Satisfy [Organization-defined: additional personnel screening criteria].
Official discussion
Organizational information that requires special protection includes controlled unclassified information. Personnel security criteria include position sensitivity background screening requirements.
Organization-defined parameters (1)
Assessment objectives and methods
- PS-03(03)(a)individuals accessing a system processing, storing, or transmitting information requiring special protection have valid access authorizations that are demonstrated by assigned official government duties;
- PS-03(03)(b)individuals accessing a system processing, storing, or transmitting information requiring special protection satisfy [Organization-defined: additional personnel screening criteria].
Examine
- Personnel security policy
- access control policy, procedures addressing personnel screening
- records of screened personnel
- screening criteria
- records of access authorizations
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with personnel security responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for ensuring valid access authorizations for information requiring special protection
- organizational process for additional personnel screening for information requiring special protection
PS-3(4) — Citizenship Requirements
Verify that individuals accessing a system processing, storing, or transmitting [Organization-defined: information types] meet [Organization-defined: citizenship requirements].
Official discussion
None.
Organization-defined parameters (2)
Assessment objectives and methods
individuals accessing a system processing, storing, or transmitting [Organization-defined: information types] meet [Organization-defined: citizenship requirements].
Examine
- Personnel security policy
- access control policy, procedures addressing personnel screening
- records of screened personnel
- screening criteria
- records of access authorizations
- system security plan
- other relevant documents or records
Interview
- Organizational personnel with personnel security responsibilities
- organizational personnel with information security responsibilities
Test
- Organizational processes for ensuring valid access authorizations for information requiring citizenship
- organizational process for additional personnel screening for information requiring citizenship
Authoritative sources
- EO 13526 ↗
- EO 13587 ↗
- FIPS 199 ↗
- FIPS 201-2 ↗
- SP 800-60-1 ↗
- SP 800-60-2 ↗
- SP 800-73-4 ↗
- SP 800-76-2 ↗
- SP 800-78-4 ↗
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.