Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

PS — Personnel Security

Study this control family as a connected set of risk outcomes, implementation decisions, evidence expectations, and assessment questions.

9Base controls
9Enhancements
18Family records
1Withdrawn records

Control family

Personnel Security

Use the family as a planning boundary, but assess each selected control against the system context, inherited services, organization-defined parameters, and evidence available from real operations.

9 base controls9 enhancementsRelease 5.2.0
PS

Family catalog

Search Personnel Security controls.

Base controls open full profiles. Enhancement results link directly to the corresponding enhancement section on the parent control page.

PS-1control

Policy and Procedures

Personnel security policy and procedures for the controls in the PS family that are implemented within systems and organizations. The risk management strategy is an important factor in establishing such policies and procedures. Policies and procedures contribute to security and privacy assurance. Therefore, it is important that security and privacy programs

PS-2control

Position Risk Designation

Position risk designations reflect Office of Personnel Management (OPM) policy and guidance. Proper position designation is the foundation of an effective and consistent suitability and personnel security program. The Position Designation System (PDS) assesses the duties and responsibilities of a position to determine the degree of potential damage to the ef

PS-3control

Personnel Screening

Personnel screening and rescreening activities reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, and specific criteria established for the risk designations of assigned positions. Examples of personnel screening include background investigations and agency checks. Organizations may define different rescreeni

PS-4control

Personnel Termination

System property includes hardware authentication tokens, system administration technical manuals, keys, identification cards, and building passes. Exit interviews ensure that terminated individuals understand the security constraints imposed by being former employees and that proper accountability is achieved for system-related property. Security topics at e

PS-5control

Personnel Transfer

Personnel transfer applies when reassignments or transfers of individuals are permanent or of such extended duration as to make the actions warranted. Organizations define actions appropriate for the types of reassignments or transfers, whether permanent or extended. Actions that may be required for personnel transfers or reassignments to other positions wit

PS-6control

Access Agreements

Access agreements include nondisclosure agreements, acceptable use agreements, rules of behavior, and conflict-of-interest agreements. Signed access agreements include an acknowledgement that individuals have read, understand, and agree to abide by the constraints associated with organizational systems to which access is authorized. Organizations can use ele

PS-7control

External Personnel Security

External provider refers to organizations other than the organization operating or acquiring the system. External providers include service bureaus, contractors, and other organizations that provide system development, information technology services, testing or assessment services, outsourced applications, and network/security management. Organizations expl

PS-8control

Personnel Sanctions

Organizational sanctions reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Sanctions processes are described in access agreements and can be included as part of general personnel policies for organizations and/or specified in security and privacy policies. Organizations consult with the Office of the Gen

PS-9control

Position Descriptions

Specification of security and privacy roles in individual organizational position descriptions facilitates clarity in understanding the security or privacy responsibilities associated with the roles and the role-based security and privacy training requirements for the roles.

PS-3(1)enhancement

Classified Information

Classified information is the most sensitive information that the Federal Government processes, stores, or transmits. It is imperative that individuals have the requisite security clearances and system access authorizations prior to gaining access to such information. Access authorizations are enforced by system access controls (see [AC-3](#ac-3) ) and flow

PS-3(2)enhancement

Formal Indoctrination

Types of classified information that require formal indoctrination include Special Access Program (SAP), Restricted Data (RD), and Sensitive Compartmented Information (SCI).

PS-4(1)enhancement

Post-employment Requirements

Organizations consult with the Office of the General Counsel regarding matters of post-employment requirements on terminated individuals.

PS-4(2)enhancement

Automated Actions

In organizations with many employees, not all personnel who need to know about termination actions receive the appropriate notifications, or if such notifications are received, they may not occur in a timely manner. Automated mechanisms can be used to send automatic alerts or notifications to organizational personnel or roles when individuals are terminated.

PS-6(2)enhancement

Classified Information Requiring Special Protection

Classified information that requires special protection includes collateral information, Special Access Program (SAP) information, and Sensitive Compartmented Information (SCI). Personnel security criteria reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

PS-6(3)enhancement

Post-employment Requirements

Organizations consult with the Office of the General Counsel regarding matters of post-employment requirements on terminated individuals.

Planned Academy connection

Bare Metal Cyber course coverage for this family.

These titles come from the approved NIST SP 800-53 course plan. They are shown as planned coverage and do not claim a public lesson URL before publication.

  1. Episode 79: Personnel Security — Part One: Purpose, scope, and roles
  2. Episode 80: Personnel Security — Part Two: Screening, agreements, and access lifecycle
  3. Episode 81: Personnel Security — Part Three: Evidence, sanctions, and pitfalls