|
controlPS-7

External Personnel Security (PS-7)

Establish personnel security requirements, including security roles and responsibilities for external providers; Require external providers to comply with personnel security policies and procedures established by the organization; Document personnel security requirements; Require external providers to notify [organization-defined] of any personnel transfers or terminations of external personnel who possess organizational credentials and/or badges, or who have system privileges within [organizati

Security Baselines

LOWMODERATEHIGH
personnel-securityscreeningtermination

Why These Connect

Maps To6

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports30

These related controls work together — a change to one may affect the others.

Cross-Framework Mappings(6)

DE.CM-06DE.CM-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RR-04GV.RR-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule8 mappingsFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
DE.CM-06DE.CM-06Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
GV.RR-04GV.RR-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(2)

Assignmentorganization-defined personnel or roles
Assignmentorganization-defined time period