1.8 Personnel Security

CISSP Domain 1 · 1.8

Personnel Security at a glance

People require access to information, systems and facilities in order to do their jobs — but that access also creates risk.

Personnel security applies appropriate controls throughout the entire relationship with an employee, contractor, consultant or supplier: before access is granted, while responsibilities change, and when the relationship ends.

🔍

Before Access

Screen appropriately and establish security responsibilities.

Should access be granted?
🔑

During Employment

Keep access aligned with the person's current role.

Does access still match the job?
🚪

When They Leave

Remove access and recover organisational assets promptly.

What must be revoked?

Why personnel security matters

Cybersecurity is not only about protecting systems from external attackers.

Employees, contractors and suppliers may legitimately have access to sensitive information, privileged accounts, buildings and critical business systems.

This creates both intentional and accidental risk.

Malicious insider

A trusted individual deliberately steals, damages or misuses information.

Negligent insider

Someone unintentionally exposes information or ignores security requirements.

Compromised insider

An attacker gains control of a legitimate user's credentials or device.

Excessive access

A user accumulates permissions that are no longer required.

Key principle

Personnel security is not simply a background check performed before somebody joins.

It is a lifecycle that continues for as long as the individual has a relationship with the organisation.

The Personnel Security Lifecycle

🔍 Candidate → Screen appropriately
🤝 Hire → Establish responsibilities and agreements
🔑 Onboard → Grant appropriate access
🔄 Transfer → Review and adjust access
🚪 Termination → Revoke access and recover assets
1 Candidate Screening and Hiring Establish appropriate trust before granting access

Why screen personnel?

Organisations may assess candidates before granting access to information, facilities or systems.

The level of screening should reflect the role, the sensitivity of the access and applicable legal or regulatory requirements.

Risk-based screening

A person requiring highly privileged access to sensitive systems may justify a different level of screening from someone performing a role with very limited access.

Screening may include

Identity Verification Employment History Qualifications References Right to Work Role-Specific Checks

Depending on jurisdiction, role and organisational requirements, additional checks may sometimes be appropriate.

Example

An organisation is hiring an administrator who will have privileged access to highly sensitive financial systems.

Appropriate pre-employment checks are completed before privileged access is authorised.

The screening level reflects the sensitivity of the role.

Screening should be appropriate

Screening should not simply involve collecting as much information as possible.

Organisations should consider:

  • the sensitivity of the role;
  • the level of system or data access;
  • applicable employment law;
  • privacy requirements;
  • regulatory obligations;
  • the relevance of the information being checked.
CISSP mindset

Personnel controls should be proportionate to risk and consistent with applicable law and organisational policy.

🎯 Position sensitivity and risk Not every role presents the same security exposure

Personnel requirements should consider what an individual will actually be able to access or influence.

Standard User

May have access to everyday business applications and information.

Administrator

May be able to change security settings, create accounts and access multiple systems.

Developer

May be able to modify application code and potentially influence production systems.

Security Professional

May possess privileged tools, sensitive vulnerability information or broad investigative access.

Finance Employee

May be able to initiate or approve financial transactions.

Third-Party Engineer

May receive temporary privileged access for support purposes.

Higher privilege = potentially greater impact

Screening, access control, monitoring and oversight should reflect what the role is capable of doing.

2 Employment Agreements and Security Requirements Make responsibilities clear

Employees should understand their security obligations before being given access to organisational resources.

Requirements may be established through contracts, employment agreements and organisational policies.

Confidentiality

Protect sensitive information obtained through employment.

Acceptable Use

Define appropriate use of organisational systems and services.

Information Handling

Explain requirements for sensitive data and organisational assets.

Monitoring

Explain relevant organisational monitoring practices where appropriate.

Incident Reporting

Employees may be required to report suspicious activity or security incidents.

Intellectual Property

Define relevant rights and responsibilities concerning work products and proprietary information.

🤐 Non-Disclosure Agreements — NDAs Protecting confidential information

What is an NDA?

A Non-Disclosure Agreement establishes contractual obligations relating to confidential information.

NDAs may be used with:

Employees Contractors Consultants Suppliers Business Partners
Example

A penetration tester receives detailed architecture diagrams, credentials and information about unpatched vulnerabilities.

Confidentiality obligations help establish how that information must be protected and restrict inappropriate disclosure.
Important

Confidentiality obligations may continue after the employment or contractual relationship ends.

💻 Acceptable Use Policies Defining appropriate behaviour

An Acceptable Use Policy defines how organisational technology and information may be used.

It may address:

Email Internet Software Installation Cloud Services Removable Media Personal Use Credentials Data Handling
Example

An employee uploads confidential company information to an unapproved public AI service.

An appropriate Acceptable Use Policy may clearly prohibit this behaviour and direct users toward approved services.

Communication matters

Users cannot reasonably be expected to follow security requirements they have never been informed about.

3 Onboarding — The Joiner Process Grant the right access to the right person

Security begins before the first login

Onboarding should ensure that new personnel receive the access, equipment and security information required for their role — but no more than necessary.

Identity established

Ensure the organisation is provisioning access to the correct person.

Role confirmed

Understand which responsibilities the person will perform.

Access approved

Obtain appropriate authorisation for system and information access.

Accounts provisioned

Create only the accounts needed for the role.

Equipment issued

Record organisational devices, badges, keys or other assets.

Policies acknowledged

Ensure relevant security responsibilities are understood.

Security training completed

Provide appropriate awareness and role-specific training.

Least privilege begins at onboarding

Access should be based on legitimate business requirements rather than simply copying every permission held by another employee.

🔑 Least Privilege and Need-to-Know Personnel should receive only necessary access
Least Privilege

Provide only the privileges needed to perform authorised duties.

Think: What can you DO?

Need-to-Know

Provide access only to information needed for the person's duties.

Think: What information do you NEED?

Example

An HR employee needs access to employee records but does not require administrator access to the HR database server.

A database administrator may need technical administrative privileges but does not automatically require permission to use confidential HR information for unrelated purposes.

Access is based on business need

Seniority alone should not automatically result in unrestricted access to information.

4 Transfers and Role Changes — The Mover Process Access must change when responsibilities change

A new role means a new access requirement

Employees may move between teams, receive promotions, take temporary assignments or change responsibilities.

Their security access should change accordingly.

Example

An employee moves from Finance into Marketing.

New marketing permissions are added, but the employee's previous payment-system access is never removed.

Over time, the employee accumulates more access than their current role requires.

This is privilege creep

Privilege creep occurs when users accumulate permissions over time as roles change without old access being appropriately removed.

Movers require both addition and removal

Do not ask only: "What new access does this person need?"

Also ask: "What old access is no longer required?"

Role-change review

  • review current system access;
  • remove obsolete permissions;
  • grant newly required access;
  • review privileged accounts;
  • update physical access where necessary;
  • update security groups and distribution lists;
  • review assets assigned to the individual;
  • provide role-specific training if required.

Privilege creep memory aid

Old Role Access A + B
New Role Needs Access C + D
Bad Process A + B + C + D
Good Process Remove A + B, grant C + D

Role changed? Access must change too.

🔍 Periodic Access Reviews Does everybody still need what they have?

Personnel access should not be assumed to remain appropriate forever.

Periodic access reviews help identify:

Excessive Access Old Accounts Privilege Creep Orphan Accounts Unused Access Incorrect Roles
Example

During an annual review, an application owner discovers that several former project members still have privileged access to the system.

Access certification provides an opportunity to remove permissions that are no longer justified.
The business owner matters

Security or IAM systems can show who has access, but the relevant business or information owner is often best placed to determine whether that access remains necessary.

5 Termination — The Leaver Process Remove access when the relationship ends

Why termination is security-critical

When an employee leaves, their legitimate need for organisational access normally ends.

Access should therefore be removed according to established procedures and appropriate timing.

User Accounts

Disable normal system and application access.

Privileged Accounts

Remove administrative and elevated privileges.

Authentication

Revoke tokens, sessions, certificates or other credentials where appropriate.

Physical Access

Disable badges and recover keys or access devices.

Equipment

Recover laptops, phones, removable media and other organisational assets.

Information

Ensure organisational information is appropriately returned, transferred or retained.

Timing matters

Example

An employee is dismissed for suspected malicious activity at 10:00, but their administrator account remains active until the nightly IAM process runs at midnight.

The delay may create unnecessary security exposure.
Higher-risk termination

When termination is sensitive or involuntary, access removal may need to be carefully coordinated so that access is disabled at or before the appropriate point in the termination process.

✅ Leaver Security Checklist What should be considered?
Disable identity

Disable the individual's primary organisational identity.

Remove application access

Ensure connected and standalone applications are covered.

Remove privileged access

Identify administrator, emergency and elevated accounts.

Revoke remote access

Remove VPN and other remote-access capabilities.

Revoke physical access

Disable badges, tokens and building access.

Recover assets

Laptops, phones, storage devices, keys and other equipment.

Transfer ownership

Reassign files, accounts, repositories and business responsibilities.

Review shared secrets

Determine whether shared passwords, keys or other secrets known to the individual need to be changed.

Remind about continuing obligations

Confidentiality or other contractual obligations may continue after departure.

⚠️ High-risk termination scenarios When coordination becomes especially important

Some departures create greater security risk than others.

Examples may include:

Involuntary Termination Privileged Administrator Security Staff Active Investigation Commercial Dispute Access to Trade Secrets

Scenario

A senior administrator with broad production access is being dismissed following suspected misconduct.

HR informs the employee of the dismissal before the security team has disabled their privileged accounts.

Better approach

HR, management, security and IAM teams should coordinate timing so access removal happens appropriately and does not create an avoidable window of exposure.

🔐 Shared credentials and personnel changes Leavers may know secrets that remain valid

Disabling a user's personal account may not remove every way they can access organisational resources.

The individual may know:

Shared Passwords Service Credentials API Keys Wi-Fi Keys Safe Codes Emergency Credentials
Example

A departing administrator knew the shared emergency administrator password used by the infrastructure team.

Their personal account is disabled.

The shared credential may still need to be changed because the former employee still knows it.
This is one reason individual accountability is preferable

Unique user identities make access easier to control, revoke and audit than widely shared credentials.

6 Vendors, Consultants and Contractors External personnel still create personnel-security risk

Personnel security controls should not apply only to permanent employees.

External personnel may have access to the same sensitive systems and information.

Contractors Consultants Managed Service Providers Support Engineers Temporary Workers Supplier Personnel

Questions to consider

Who performs screening?

Does the supplier perform appropriate screening before assigning personnel?

What access is required?

Limit supplier access according to legitimate business need.

How long is access required?

Temporary access should not remain indefinitely.

What confidentiality obligations apply?

Ensure agreements appropriately protect organisational information.

How is activity monitored?

Higher-risk external access may require stronger oversight and logging.

How will access be terminated?

The organisation needs to know when supplier personnel change or leave.

🧑‍🔧 Worked example: external support engineer Apply personnel security to a third party
Business requirement

A software vendor needs temporary privileged access to troubleshoot a production system.

Identity

Access should be associated with an identifiable authorised engineer.

Access scope

Grant only the systems and privileges needed for the support activity.

Duration

Access may be time-limited rather than permanently enabled.

Monitoring

Privileged activity may be logged or supervised according to policy.

Confidentiality

Appropriate contractual obligations protect information encountered during support.

Completion

Access is removed when the support activity is complete.

Third-party does not mean trusted forever

Access should remain controlled even when the supplier is reputable and has worked with the organisation for many years.

📄 Third-Party Agreements Put security expectations into the relationship

Contracts and agreements can establish personnel-security expectations for suppliers.

Requirements might address:

Screening

Appropriate checks for personnel assigned to sensitive work.

Confidentiality

Protection of information accessed by supplier personnel.

Security Training

Required awareness or role-specific training.

Access Control

Restrictions governing systems and information.

Personnel Changes

Notification when authorised supplier personnel change roles or leave.

Termination

Requirements for removing access when the relationship ends.

Contractual clarity matters

If the organisation expects a supplier to perform personnel screening or notify it immediately when a contractor leaves, that expectation should be established clearly rather than assumed.

🕵️ Insider Risk Trusted access can still be misused

What is insider risk?

Insider risk arises when people with legitimate access create security risk intentionally or unintentionally.

Malicious

Deliberately steals information, commits fraud or sabotages systems.

Negligent

Causes exposure through mistakes, poor judgement or failure to follow security requirements.

Compromised

An external attacker gains control of legitimate credentials or a trusted endpoint.

Collusive

An insider may cooperate with an external party.

Controls should not rely on trust alone

Least Privilege Logging Access Reviews DLP Separation of Duties Monitoring Training Strong Offboarding
Personnel security should be balanced

The goal is not to treat every employee as malicious.

The goal is to design controls so that legitimate access does not become unlimited or unaccountable access.

🧩 Related personnel-control concepts Useful concepts that appear elsewhere in CISSP too

Several other security concepts strongly support personnel security. They appear in greater detail elsewhere in the CISSP domains.

Separation of Duties

Split critical responsibilities so one person cannot complete a sensitive process alone.

Job Rotation

Rotate responsibilities periodically, reducing dependence on one person and potentially exposing irregular activity.

Least Privilege

Grant only the permissions required to perform authorised duties.

Need-to-Know

Limit information access according to legitimate business need.

Separation of duties example

One employee creates a supplier payment and another independently approves it.

No single employee can create and approve the entire transaction.
Separation of Duties, least privilege and job rotation appear explicitly elsewhere in the CISSP outline, particularly Security Architecture and Security Operations. They are included here because they are closely related to personnel risk.
🤖 Joiner, Mover, Leaver automation Reduce human error in personnel processes

Large organisations may employ thousands of people and process many personnel changes every day.

Manual processes can easily result in:

Missed Leavers Delayed Revocation Privilege Creep Incorrect Access Orphan Accounts

Automation can connect systems

👥 HR System → Employment status changes
🪪 Identity Platform → Identity updated automatically
🔑 Applications → Access provisioned or removed
📋 Audit → Actions recorded
Automation does not remove governance

The organisation still needs accurate role definitions, access rules, approvals and exception processes.

⚠️ Common mistakes Personnel-security concepts people often overlook
"Personnel security ends after the background check."

Personnel security continues throughout onboarding, transfers, employment and termination.

"When someone changes role, just add their new access."

Old permissions should also be reviewed and removed where they are no longer required.

"Disabling Active Directory means the leaver is fully removed."

Standalone applications, cloud services, privileged accounts, physical access and shared credentials may also need attention.

"Contractors are the supplier's security problem."

If contractor personnel access your organisation's systems or data, their access creates risk that must be managed.

"Senior employees should have broad access."

Access should be based on business need rather than organisational seniority.

"A trusted employee does not need monitoring."

Trust does not eliminate the need for appropriate accountability and security controls.

"The account can be disabled later because the employee has already left."

Delayed offboarding creates an unnecessary period during which access may remain usable.

"An NDA means information is technically protected."

Contractual obligations should be supported by technical and administrative security controls.

"Everybody in the same team should have identical access."

Access should reflect actual responsibilities, which can differ even between people with similar job titles.

CISSP Exam Perspective

Think about the entire personnel lifecycle

Personnel-security questions often describe a problem at a particular point in someone's relationship with the organisation.

First determine whether you are dealing with a candidate, joiner, mover, leaver or third party.

🔍 Before employment

Screening Identity Qualifications Role Risk Hiring

🔑 During employment

Least Privilege Policy Training Monitoring Access Review

🔄 Role change

Transfer Privilege Creep Remove Old Access Grant New Access

🚪 Termination

Disable Revoke Recover Assets Physical Access Credentials

🤝 Third parties

Contractors Agreements Temporary Access Monitoring Termination

🕵️ Insider risk

Trust Accountability Access Monitoring Behaviour
📝 Practice scenarios Apply personnel-security thinking

Scenario 1

A candidate is applying for a highly privileged security administrator position.

What should happen before access is granted?

Appropriate screening should be completed in accordance with the sensitivity of the role and applicable requirements.

Scenario 2

A new employee needs access to the customer database.

Their manager says to copy all permissions from the previous employee because it is quicker.

What is the better approach?

Determine the access actually required for the new employee's role and grant permissions according to business need and least privilege.

Scenario 3

An employee transfers from Finance to Marketing but retains payment approval access.

What security problem has occurred?

Privilege creep caused by inadequate access review during the mover process.

Scenario 4

An administrator is dismissed following suspected misconduct.

What is particularly important?

Coordinating termination and access revocation so privileged access does not remain available unnecessarily.

Scenario 5

A departing employee's normal account is disabled, but their building pass remains active.

What failed?

The termination process did not consider physical access.

Scenario 6

An external support engineer receives permanent administrator access even though they perform support only once every six months.

What principle should be reconsidered?

Least privilege and the duration of third-party access.

Scenario 7

A supplier replaces one of its engineers but does not inform the customer. The former engineer's customer account remains active.

What control was missing?

An effective third-party personnel-change and termination process.

Scenario 8

A user has accumulated permissions from four previous jobs inside the organisation.

What should help identify this?

Effective mover processes and periodic access reviews.

Scenario 9

A former infrastructure engineer's personal account has been disabled, but they still know a shared emergency administrator password.

What additional action may be necessary?

Change or otherwise secure shared credentials known to the departing employee.

Scenario 10

A highly trusted employee processes and approves their own sensitive financial transactions.

Which related security principle could reduce this risk?

Separation of Duties.

Joiner → Mover → Leaver

👋 Joiner → Grant appropriate access
🔄 Mover → Remove old access + grant new access
🚪 Leaver → Remove access completely

Quick memory aid

Candidate SCREEN appropriately
Joiner GRANT required access
Mover REVIEW and CHANGE access
Leaver REVOKE access
Third Party CONTROL external access

Screen. Grant. Review. Revoke.

Personnel Security questions

Before access Can we appropriately TRUST this person?
During access Do they still NEED it?
Role change What should be REMOVED?
Departure What must be REVOKED?
Supplier Who CONTROLS their access?

Key takeaways

Personnel security is a lifecycle rather than a one-time background check.

Candidate screening should reflect the sensitivity and risk of the role and applicable legal or regulatory requirements.

Employment agreements and organisational policies should clearly establish security responsibilities, confidentiality obligations and acceptable behaviour.

Onboarding should provide only the access needed for the individual's legitimate responsibilities.

Transfers and role changes require review of both new and existing permissions.

Failing to remove obsolete permissions can create privilege creep.

Termination should revoke logical and physical access and recover organisational assets promptly.

Shared credentials and other secrets known by departing personnel may require additional action even after individual accounts are disabled.

Contractors, consultants and supplier personnel should be subject to appropriate personnel-security controls rather than being automatically trusted because they work for a third party.

Third-party agreements can establish requirements for screening, confidentiality, access, personnel changes and termination.

Insider risk can be malicious, negligent or the result of a legitimate account being compromised.

Most importantly: access should exist only while there is a legitimate business requirement for it.

📚 Sources & Further Reading Authoritative references