1.8 Personnel Security
Personnel Security at a glance
People require access to information, systems and facilities in order to do their jobs — but that access also creates risk.
Personnel security applies appropriate controls throughout the entire relationship with an employee, contractor, consultant or supplier: before access is granted, while responsibilities change, and when the relationship ends.
Before Access
Screen appropriately and establish security responsibilities.
Should access be granted?During Employment
Keep access aligned with the person's current role.
Does access still match the job?When They Leave
Remove access and recover organisational assets promptly.
What must be revoked?Why personnel security matters
Cybersecurity is not only about protecting systems from external attackers.
Employees, contractors and suppliers may legitimately have access to sensitive information, privileged accounts, buildings and critical business systems.
This creates both intentional and accidental risk.
A trusted individual deliberately steals, damages or misuses information.
Someone unintentionally exposes information or ignores security requirements.
An attacker gains control of a legitimate user's credentials or device.
A user accumulates permissions that are no longer required.
Personnel security is not simply a background check performed before somebody joins.
It is a lifecycle that continues for as long as the individual has a relationship with the organisation.
The Personnel Security Lifecycle
1 Candidate Screening and Hiring Establish appropriate trust before granting access
Why screen personnel?
Organisations may assess candidates before granting access to information, facilities or systems.
The level of screening should reflect the role, the sensitivity of the access and applicable legal or regulatory requirements.
A person requiring highly privileged access to sensitive systems may justify a different level of screening from someone performing a role with very limited access.
Screening may include
Depending on jurisdiction, role and organisational requirements, additional checks may sometimes be appropriate.
An organisation is hiring an administrator who will have privileged access to highly sensitive financial systems.
Appropriate pre-employment checks are completed before privileged access is authorised.
The screening level reflects the sensitivity of the role.Screening should be appropriate
Screening should not simply involve collecting as much information as possible.
Organisations should consider:
- the sensitivity of the role;
- the level of system or data access;
- applicable employment law;
- privacy requirements;
- regulatory obligations;
- the relevance of the information being checked.
Personnel controls should be proportionate to risk and consistent with applicable law and organisational policy.
🎯 Position sensitivity and risk Not every role presents the same security exposure
Personnel requirements should consider what an individual will actually be able to access or influence.
May have access to everyday business applications and information.
May be able to change security settings, create accounts and access multiple systems.
May be able to modify application code and potentially influence production systems.
May possess privileged tools, sensitive vulnerability information or broad investigative access.
May be able to initiate or approve financial transactions.
May receive temporary privileged access for support purposes.
Screening, access control, monitoring and oversight should reflect what the role is capable of doing.
2 Employment Agreements and Security Requirements Make responsibilities clear
Employees should understand their security obligations before being given access to organisational resources.
Requirements may be established through contracts, employment agreements and organisational policies.
Protect sensitive information obtained through employment.
Define appropriate use of organisational systems and services.
Explain requirements for sensitive data and organisational assets.
Explain relevant organisational monitoring practices where appropriate.
Employees may be required to report suspicious activity or security incidents.
Define relevant rights and responsibilities concerning work products and proprietary information.
🤐 Non-Disclosure Agreements — NDAs Protecting confidential information
What is an NDA?
A Non-Disclosure Agreement establishes contractual obligations relating to confidential information.
NDAs may be used with:
A penetration tester receives detailed architecture diagrams, credentials and information about unpatched vulnerabilities.
Confidentiality obligations help establish how that information must be protected and restrict inappropriate disclosure.Confidentiality obligations may continue after the employment or contractual relationship ends.
💻 Acceptable Use Policies Defining appropriate behaviour
An Acceptable Use Policy defines how organisational technology and information may be used.
It may address:
An employee uploads confidential company information to an unapproved public AI service.
An appropriate Acceptable Use Policy may clearly prohibit this behaviour and direct users toward approved services.
Users cannot reasonably be expected to follow security requirements they have never been informed about.
3 Onboarding — The Joiner Process Grant the right access to the right person
Security begins before the first login
Onboarding should ensure that new personnel receive the access, equipment and security information required for their role — but no more than necessary.
Ensure the organisation is provisioning access to the correct person.
Understand which responsibilities the person will perform.
Obtain appropriate authorisation for system and information access.
Create only the accounts needed for the role.
Record organisational devices, badges, keys or other assets.
Ensure relevant security responsibilities are understood.
Provide appropriate awareness and role-specific training.
Access should be based on legitimate business requirements rather than simply copying every permission held by another employee.
🔑 Least Privilege and Need-to-Know Personnel should receive only necessary access
Provide only the privileges needed to perform authorised duties.
Think: What can you DO?
Provide access only to information needed for the person's duties.
Think: What information do you NEED?
An HR employee needs access to employee records but does not require administrator access to the HR database server.
A database administrator may need technical administrative privileges but does not automatically require permission to use confidential HR information for unrelated purposes.
Seniority alone should not automatically result in unrestricted access to information.
4 Transfers and Role Changes — The Mover Process Access must change when responsibilities change
A new role means a new access requirement
Employees may move between teams, receive promotions, take temporary assignments or change responsibilities.
Their security access should change accordingly.
An employee moves from Finance into Marketing.
New marketing permissions are added, but the employee's previous payment-system access is never removed.
Over time, the employee accumulates more access than their current role requires.This is privilege creep
Privilege creep occurs when users accumulate permissions over time as roles change without old access being appropriately removed.
Do not ask only: "What new access does this person need?"
Also ask: "What old access is no longer required?"
Role-change review
- review current system access;
- remove obsolete permissions;
- grant newly required access;
- review privileged accounts;
- update physical access where necessary;
- update security groups and distribution lists;
- review assets assigned to the individual;
- provide role-specific training if required.
Privilege creep memory aid
Role changed? Access must change too.
🔍 Periodic Access Reviews Does everybody still need what they have?
Personnel access should not be assumed to remain appropriate forever.
Periodic access reviews help identify:
During an annual review, an application owner discovers that several former project members still have privileged access to the system.
Access certification provides an opportunity to remove permissions that are no longer justified.Security or IAM systems can show who has access, but the relevant business or information owner is often best placed to determine whether that access remains necessary.
5 Termination — The Leaver Process Remove access when the relationship ends
Why termination is security-critical
When an employee leaves, their legitimate need for organisational access normally ends.
Access should therefore be removed according to established procedures and appropriate timing.
Disable normal system and application access.
Remove administrative and elevated privileges.
Revoke tokens, sessions, certificates or other credentials where appropriate.
Disable badges and recover keys or access devices.
Recover laptops, phones, removable media and other organisational assets.
Ensure organisational information is appropriately returned, transferred or retained.
Timing matters
An employee is dismissed for suspected malicious activity at 10:00, but their administrator account remains active until the nightly IAM process runs at midnight.
The delay may create unnecessary security exposure.When termination is sensitive or involuntary, access removal may need to be carefully coordinated so that access is disabled at or before the appropriate point in the termination process.
✅ Leaver Security Checklist What should be considered?
Disable the individual's primary organisational identity.
Ensure connected and standalone applications are covered.
Identify administrator, emergency and elevated accounts.
Remove VPN and other remote-access capabilities.
Disable badges, tokens and building access.
Laptops, phones, storage devices, keys and other equipment.
Reassign files, accounts, repositories and business responsibilities.
Determine whether shared passwords, keys or other secrets known to the individual need to be changed.
Confidentiality or other contractual obligations may continue after departure.
⚠️ High-risk termination scenarios When coordination becomes especially important
Some departures create greater security risk than others.
Examples may include:
Scenario
A senior administrator with broad production access is being dismissed following suspected misconduct.
HR informs the employee of the dismissal before the security team has disabled their privileged accounts.
HR, management, security and IAM teams should coordinate timing so access removal happens appropriately and does not create an avoidable window of exposure.
🔐 Shared credentials and personnel changes Leavers may know secrets that remain valid
Disabling a user's personal account may not remove every way they can access organisational resources.
The individual may know:
A departing administrator knew the shared emergency administrator password used by the infrastructure team.
Their personal account is disabled.
The shared credential may still need to be changed because the former employee still knows it.Unique user identities make access easier to control, revoke and audit than widely shared credentials.
6 Vendors, Consultants and Contractors External personnel still create personnel-security risk
Personnel security controls should not apply only to permanent employees.
External personnel may have access to the same sensitive systems and information.
Questions to consider
Does the supplier perform appropriate screening before assigning personnel?
Limit supplier access according to legitimate business need.
Temporary access should not remain indefinitely.
Ensure agreements appropriately protect organisational information.
Higher-risk external access may require stronger oversight and logging.
The organisation needs to know when supplier personnel change or leave.
🧑🔧 Worked example: external support engineer Apply personnel security to a third party
A software vendor needs temporary privileged access to troubleshoot a production system.
Access should be associated with an identifiable authorised engineer.
Grant only the systems and privileges needed for the support activity.
Access may be time-limited rather than permanently enabled.
Privileged activity may be logged or supervised according to policy.
Appropriate contractual obligations protect information encountered during support.
Access is removed when the support activity is complete.
Access should remain controlled even when the supplier is reputable and has worked with the organisation for many years.
📄 Third-Party Agreements Put security expectations into the relationship
Contracts and agreements can establish personnel-security expectations for suppliers.
Requirements might address:
Appropriate checks for personnel assigned to sensitive work.
Protection of information accessed by supplier personnel.
Required awareness or role-specific training.
Restrictions governing systems and information.
Notification when authorised supplier personnel change roles or leave.
Requirements for removing access when the relationship ends.
If the organisation expects a supplier to perform personnel screening or notify it immediately when a contractor leaves, that expectation should be established clearly rather than assumed.
🕵️ Insider Risk Trusted access can still be misused
What is insider risk?
Insider risk arises when people with legitimate access create security risk intentionally or unintentionally.
Deliberately steals information, commits fraud or sabotages systems.
Causes exposure through mistakes, poor judgement or failure to follow security requirements.
An external attacker gains control of legitimate credentials or a trusted endpoint.
An insider may cooperate with an external party.
Controls should not rely on trust alone
The goal is not to treat every employee as malicious.
The goal is to design controls so that legitimate access does not become unlimited or unaccountable access.
🧩 Related personnel-control concepts Useful concepts that appear elsewhere in CISSP too
Several other security concepts strongly support personnel security. They appear in greater detail elsewhere in the CISSP domains.
Split critical responsibilities so one person cannot complete a sensitive process alone.
Rotate responsibilities periodically, reducing dependence on one person and potentially exposing irregular activity.
Grant only the permissions required to perform authorised duties.
Limit information access according to legitimate business need.
One employee creates a supplier payment and another independently approves it.
No single employee can create and approve the entire transaction.🤖 Joiner, Mover, Leaver automation Reduce human error in personnel processes
Large organisations may employ thousands of people and process many personnel changes every day.
Manual processes can easily result in:
Automation can connect systems
The organisation still needs accurate role definitions, access rules, approvals and exception processes.
⚠️ Common mistakes Personnel-security concepts people often overlook
Personnel security continues throughout onboarding, transfers, employment and termination.
Old permissions should also be reviewed and removed where they are no longer required.
Standalone applications, cloud services, privileged accounts, physical access and shared credentials may also need attention.
If contractor personnel access your organisation's systems or data, their access creates risk that must be managed.
Access should be based on business need rather than organisational seniority.
Trust does not eliminate the need for appropriate accountability and security controls.
Delayed offboarding creates an unnecessary period during which access may remain usable.
Contractual obligations should be supported by technical and administrative security controls.
Access should reflect actual responsibilities, which can differ even between people with similar job titles.
Think about the entire personnel lifecycle
Personnel-security questions often describe a problem at a particular point in someone's relationship with the organisation.
First determine whether you are dealing with a candidate, joiner, mover, leaver or third party.
🔍 Before employment
🔑 During employment
🔄 Role change
🚪 Termination
🤝 Third parties
🕵️ Insider risk
📝 Practice scenarios Apply personnel-security thinking
Scenario 1
A candidate is applying for a highly privileged security administrator position.
What should happen before access is granted?
Appropriate screening should be completed in accordance with the sensitivity of the role and applicable requirements.
Scenario 2
A new employee needs access to the customer database.
Their manager says to copy all permissions from the previous employee because it is quicker.
What is the better approach?
Determine the access actually required for the new employee's role and grant permissions according to business need and least privilege.
Scenario 3
An employee transfers from Finance to Marketing but retains payment approval access.
What security problem has occurred?
Privilege creep caused by inadequate access review during the mover process.
Scenario 4
An administrator is dismissed following suspected misconduct.
What is particularly important?
Coordinating termination and access revocation so privileged access does not remain available unnecessarily.
Scenario 5
A departing employee's normal account is disabled, but their building pass remains active.
What failed?
The termination process did not consider physical access.
Scenario 6
An external support engineer receives permanent administrator access even though they perform support only once every six months.
What principle should be reconsidered?
Least privilege and the duration of third-party access.
Scenario 7
A supplier replaces one of its engineers but does not inform the customer. The former engineer's customer account remains active.
What control was missing?
An effective third-party personnel-change and termination process.
Scenario 8
A user has accumulated permissions from four previous jobs inside the organisation.
What should help identify this?
Effective mover processes and periodic access reviews.
Scenario 9
A former infrastructure engineer's personal account has been disabled, but they still know a shared emergency administrator password.
What additional action may be necessary?
Change or otherwise secure shared credentials known to the departing employee.
Scenario 10
A highly trusted employee processes and approves their own sensitive financial transactions.
Which related security principle could reduce this risk?
Separation of Duties.
Joiner → Mover → Leaver
Quick memory aid
Screen. Grant. Review. Revoke.
Personnel Security questions
Key takeaways
Personnel security is a lifecycle rather than a one-time background check.
Candidate screening should reflect the sensitivity and risk of the role and applicable legal or regulatory requirements.
Employment agreements and organisational policies should clearly establish security responsibilities, confidentiality obligations and acceptable behaviour.
Onboarding should provide only the access needed for the individual's legitimate responsibilities.
Transfers and role changes require review of both new and existing permissions.
Failing to remove obsolete permissions can create privilege creep.
Termination should revoke logical and physical access and recover organisational assets promptly.
Shared credentials and other secrets known by departing personnel may require additional action even after individual accounts are disabled.
Contractors, consultants and supplier personnel should be subject to appropriate personnel-security controls rather than being automatically trusted because they work for a third party.
Third-party agreements can establish requirements for screening, confidentiality, access, personnel changes and termination.
Insider risk can be malicious, negligent or the result of a legitimate account being compromised.
Most importantly: access should exist only while there is a legitimate business requirement for it.
📚 Sources & Further Reading Authoritative references
- ISC2 — CISSP Certification Exam Outline
View official CISSP exam outline - NIST SP 800-53 Rev. 5 — Security and Privacy Controls
View NIST publication - NIST SP 800-171 Rev. 3 — Personnel Security
View NIST publication
