Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

PS-3 — Personnel Screening

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

4Enhancements
3Parameters
3Baseline memberships
3Assessment methods

PS — Personnel Security · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Screen individuals prior to authorizing access to the system; and
  2. b.Rescreen individuals in accordance with [Organization-defined: organization-defined conditions requiring rescreening and, where rescreening is so indicated, the frequency of rescreening].
Official NIST discussion

Discussion

Personnel screening and rescreening activities reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, and specific criteria established for the risk designations of assigned positions. Examples of personnel screening include background investigations and agency checks. Organizations may define different rescreening conditions and frequencies for personnel accessing systems based on types of information processed, stored, or transmitted by the systems.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

organization-defined conditions requiring rescreening and, where rescreening is so indicated, the frequency of rescreening
conditions requiring rescreeningconditions requiring rescreening of individuals are defined;
frequencythe frequency of rescreening individuals where it is so indicated is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Personnel Screening as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to personnel risk, screening, agreements, transfer, termination, and access consequences.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • screening and suitability records
  • access agreements
  • transfer and termination checklists
  • role change and offboarding evidence

Common failure patterns

  • access persists after transfer or separation
  • contractor lifecycle handled outside normal controls
  • sensitive-role screening not risk based
  • termination actions cannot be shown to occur promptly

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. PS-03a.individuals are screened prior to authorizing access to the system;
  2. PS-03b.
    1. PS-03b.[01]individuals are rescreened in accordance with [Organization-defined: conditions requiring rescreening];
    2. PS-03b.[02]where rescreening is so indicated, individuals are rescreened [Organization-defined: frequency].

Examine

  • Personnel security policy
  • procedures addressing personnel screening
  • records of screened personnel
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with personnel security responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for personnel screening
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

PS-3(1) — Classified Information

Verify that individuals accessing a system processing, storing, or transmitting classified information are cleared and indoctrinated to the highest classification level of the information to which they have access on the system.

Official discussion

Classified information is the most sensitive information that the Federal Government processes, stores, or transmits. It is imperative that individuals have the requisite security clearances and system access authorizations prior to gaining access to such information. Access authorizations are enforced by system access controls (see [AC-3](#ac-3) ) and flow controls (see [AC-4](#ac-4)).

Assessment objectives and methods
  1. PS-03(01)[01]individuals accessing a system processing, storing, or transmitting classified information are cleared;
  2. PS-03(01)[02]individuals accessing a system processing, storing, or transmitting classified information are indoctrinated to the highest classification level of the information to which they have access on the system.

Examine

  • Personnel security policy
  • procedures addressing personnel screening
  • records of screened personnel
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with personnel security responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for clearing and indoctrinating personnel for access to classified information
Related controls
Official NIST control enhancement

PS-3(2) — Formal Indoctrination

Verify that individuals accessing a system processing, storing, or transmitting types of classified information that require formal indoctrination, are formally indoctrinated for all the relevant types of information to which they have access on the system.

Official discussion

Types of classified information that require formal indoctrination include Special Access Program (SAP), Restricted Data (RD), and Sensitive Compartmented Information (SCI).

Assessment objectives and methods

individuals accessing a system processing, storing, or transmitting types of classified information that require formal indoctrination are formally indoctrinated for all of the relevant types of information to which they have access on the system.

Examine

  • Personnel security policy
  • procedures addressing personnel screening
  • indoctrination documents
  • records of screened personnel
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with personnel security responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for formal indoctrination for all relevant types of information to which personnel have access
Related controls
Official NIST control enhancement

PS-3(3) — Information Requiring Special Protective Measures

Verify that individuals accessing a system processing, storing, or transmitting information requiring special protection:

  1. (a)Have valid access authorizations that are demonstrated by assigned official government duties; and
  2. (b)Satisfy [Organization-defined: additional personnel screening criteria].
Official discussion

Organizational information that requires special protection includes controlled unclassified information. Personnel security criteria include position sensitivity background screening requirements.

Organization-defined parameters (1)
additional personnel screening criteriaadditional personnel screening criteria to be satisfied for individuals accessing a system processing, storing, or transmitting information requiring special protection are defined;
Assessment objectives and methods
  1. PS-03(03)(a)individuals accessing a system processing, storing, or transmitting information requiring special protection have valid access authorizations that are demonstrated by assigned official government duties;
  2. PS-03(03)(b)individuals accessing a system processing, storing, or transmitting information requiring special protection satisfy [Organization-defined: additional personnel screening criteria].

Examine

  • Personnel security policy
  • access control policy, procedures addressing personnel screening
  • records of screened personnel
  • screening criteria
  • records of access authorizations
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with personnel security responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for ensuring valid access authorizations for information requiring special protection
  • organizational process for additional personnel screening for information requiring special protection
Official NIST control enhancement

PS-3(4) — Citizenship Requirements

Verify that individuals accessing a system processing, storing, or transmitting [Organization-defined: information types] meet [Organization-defined: citizenship requirements].

Official discussion

None.

Organization-defined parameters (2)
information typesinformation types that are processed, stored, or transmitted by a system that require individuals accessing the system to meet {{ insert: param, ps-03.04_odp.02 }} are defined;
citizenship requirementscitizenship requirements to be met by individuals to access a system processing, storing, or transmitting information are defined;
Assessment objectives and methods

individuals accessing a system processing, storing, or transmitting [Organization-defined: information types] meet [Organization-defined: citizenship requirements].

Examine

  • Personnel security policy
  • access control policy, procedures addressing personnel screening
  • records of screened personnel
  • screening criteria
  • records of access authorizations
  • system security plan
  • other relevant documents or records

Interview

  • Organizational personnel with personnel security responsibilities
  • organizational personnel with information security responsibilities

Test

  • Organizational processes for ensuring valid access authorizations for information requiring citizenship
  • organizational process for additional personnel screening for information requiring citizenship
Source record

Authoritative sources