|
controlPS-7
External Personnel Security (PS-7)
Establish personnel security requirements, including security roles and responsibilities for external providers; Require external providers to comply with personnel security policies and procedures established by the organization; Document personnel security requirements; Require external providers to notify [organization-defined] of any personnel transfers or terminations of external personnel who possess organizational credentials and/or badges, or who have system privileges within [organizati
Security Baselines
LOWMODERATEHIGH
personnel-securityscreeningtermination
Why These Connect
Maps To6
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports30
These related controls work together — a change to one may affect the others.
Related Controls(17)
AC-2Account Management (AC-2)
LMH
AT-2Literacy Training and Awareness (AT-2)LMH
AT-3Role-based Training (AT-3)LMH
CA-7Continuous Monitoring (CA-7)LMH
MA-5Maintenance Personnel (MA-5)LMH
PE-3Physical Access Control (PE-3)LMH
PM-12Insider Threat Program (PM-12)PM-31Continuous Monitoring Strategy (PM-31)PS-3Personnel Screening (PS-3)LMH
PS-4Personnel Termination (PS-4)LMH
PS-5Personnel Transfer (PS-5)LMH
PS-6Access Agreements (PS-6)LMH
PS-2Position Risk Designation (PS-2)LMH
SA-5System Documentation (SA-5)LMH
SA-9External System Services (SA-9)LMH
SA-21Developer Screening (SA-21)H
SA-4Acquisition Process (SA-4)LMH
Cross-Framework Mappings(6)
DE.CM-06DE.CM-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RR-04GV.RR-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule8 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
DE.CM-06DE.CM-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RR-04GV.RR-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(2)
Assignmentorganization-defined personnel or roles
Assignmentorganization-defined time period