7.15 Personnel Safety & Security

CISSP Domain 7 · Security Operations

7.15 Personnel Safety & Security

Security exists to protect organisations, information and technology.

But during an emergency or threatening situation, one principle overrides almost everything else:

people come first.

Employees may travel to unfamiliar locations, face social engineering, encounter insider threats, receive malicious MFA prompts, work alone, experience emergencies or be placed under physical or psychological pressure.

Personnel safety and security therefore means preparing people to: recognise risk, avoid unnecessary exposure, communicate problems, respond appropriately and obtain help when necessary.

✈️

Travel

Protect people, devices, information and credentials away from the normal controlled environment.

PREPARE BEFORE YOU GO
🧠

Awareness

Help personnel recognise insider risk, social-media exposure and authentication attacks.

RECOGNISE & REPORT
🚨

Emergency & Duress

Give people practical ways to reach safety and request assistance under abnormal or threatening conditions.

PEOPLE FIRST
Current CISSP 7.15 Scope

Address Personnel Safety and Security Concerns

The current CISSP Exam Outline explicitly identifies four areas.

Travel

Protect personnel and organisational assets while employees are away from normal working environments.

Security Training & Awareness

Includes topics such as insider threat, social-media impacts and two-factor authentication fatigue.

Emergency Management

Prepare personnel to respond safely and effectively when an emergency occurs.

Duress

Provide ways for personnel to obtain assistance when they are under coercion, threat or immediate danger.

Official 7.15 Topics

TRAVEL Protect away from home base
AWARENESS Recognise risk
EMERGENCY Respond safely
DURESS Request help safely
Cross-Domain Distinction

Domain 1.8 vs Domain 7.15

1.8 Personnel Security Policies

Focuses on organisational personnel-security processes.

Screening Hiring Agreements Onboarding Transfers Termination Contractors

MANAGE THE PERSONNEL LIFECYCLE

7.15 Personnel Safety & Security

Focuses on protecting personnel during security operations.

Travel Awareness Emergencies Duress

KEEP PEOPLE SAFE

1.8 manages personnel security requirements. 7.15 addresses personnel safety and operational security concerns.
CISSP Priority

Human Life Takes Priority

Data centre fire

Engineer notices: critical storage systems are still running.

Fire alarm activates and evacuation is ordered.

Should the engineer remain behind to perform a graceful shutdown?

No.

Protect people before equipment, applications, data or availability.

Safety and Security Are Related but Different

Safety

Protect people from injury, illness and dangerous conditions.

Fire Medical Emergency Flood Hazardous Environment
Security

Protect people from intentional threats and hostile activity.

Violence Coercion Stalking Insider Threat Social Engineering
Personnel protection often requires both safety and security controls.

Personnel Protection Should Be Risk-Based

Not every employee faces the same risk.

International Travellers Executives Security Personnel Lone Workers Public-Facing Employees Investigators Privileged Administrators Employees Handling Valuable Assets
Personnel security measures should reflect the person's role, environment and exposure to threats.
Official 7.15 Topic 1

Travel Security

Travel moves employees outside many of the controls normally available inside the organisation.

Personal Safety

Travellers may be exposed to unfamiliar locations, transportation, political conditions or crime.

Device Security

Laptops and mobile devices may be lost, stolen or physically accessed.

Network Security

Travellers may depend on networks outside organisational control.

Information Security

Sensitive information may be exposed through devices, conversations, documents or observation.

Legal Environment

Laws, customs requirements and privacy expectations may differ across jurisdictions.

Emergency Support

Employees need to know how to contact the organisation and obtain assistance.

Travel Security Lifecycle

ASSESS Destination risk
BRIEF Prepare traveller
MINIMISE Take only what is needed
PROTECT Person + device + data
COMMUNICATE Maintain contact
REPORT Problems quickly
RETURN Review device / incident risk
Before Travel

Pre-Travel Risk Assessment

Destination

What security, political, health or environmental risks exist?

Purpose

What activities will the traveller perform?

Information

What sensitive information does the traveller genuinely need?

Technology

Which devices and services are required?

Profile

Does the traveller's role make them a particularly valuable target?

Support

How can the traveller contact the organisation during an emergency?

🧳 Travel Security Briefing Prepare the employee before departure
Destination Risks Emergency Contacts Communication Expectations Device Policy Data Handling Transportation Incident Reporting Local Requirements
Travel security should start before the traveller reaches the airport.
Travel Principle

Take Only What You Need

Employee travelling for three-day conference

Laptop contains: ten years of locally stored customer records.

None are required for: the conference.

Data that does not travel cannot be lost from the travel device.

Travel Data Principle

LESS DATA Less exposure
LESS ACCESS Less impact
LESS PRIVILEGE Less compromise potential

Travel Devices

Depending on risk, organisations may provide: managed devices specifically prepared for travel.

Minimal Local Data Current Patches Encryption Strong Authentication Limited Privileges Approved Applications Remote Management
The objective is to reduce the impact if the travelling device is lost, stolen or compromised.
💻 Higher-Risk Travel Device Reduce information and access exposed to the journey

For some higher-risk travel, an organisation may choose a device that contains only:

Required Applications Required Data Limited Credentials Temporary Access

After return, organisational procedure may require: inspection, secure erasure or rebuilding of the device.

Do not expose the entire corporate environment when the traveller needs only a small subset of it.
Travel Connectivity

Treat Uncontrolled Networks as Untrusted

Hotel Wi-Fi

Employee sees:

HotelGuest Hotel_Guest FREE-HOTEL-WIFI

Which one is genuine? Not immediately obvious.

Organisation-approved approaches may include:

Managed Cellular Connection Approved VPN / Remote Access Encrypted Services Organisation Security Policy
Travellers should follow organisational policy for connecting through networks outside organisational control.

External Interfaces Matter While Travelling

USB

Avoid connecting unknown storage devices or peripherals.

Charging

Use organisation-approved charging arrangements where required rather than connecting devices unnecessarily to unknown systems.

Bluetooth

Disable unnecessary wireless interfaces when they are not required.

Peripheral Devices

Treat unknown accessories as potential security risks.

A connection intended only for convenience may also provide a technical path into the device.
Physical Travel Security

Maintain Control of Devices

Conference

Employee leaves corporate laptop: unattended in a public meeting room during lunch.

Encryption reduces data exposure but does not make losing the device a good outcome.
Keep Devices With You Where Practical Lock Screen When Away Use Secure Storage Avoid Unattended Equipment Report Loss Quickly
Travel Scenario

The Laptop in the Taxi

Employee leaves: corporate laptop in a taxi.

Priority should not be: personally chasing the vehicle through an unfamiliar city.

Person → Remain Safe
Loss → Report Promptly
Organisation → Protect Account / Device
Incident → Assess Data Exposure
Protect the person first, then manage the security incident.

Hotel & Temporary Workspace Security

Do Not Leave Sensitive Material Exposed Lock Devices Protect Screens Avoid Sensitive Conversations in Public Areas Use Approved Storage Report Suspected Tampering
Return to hotel room

Employee notices: laptop bag and device are arranged differently.

Best approach is not: simply ignore it and continue working.

Suspected device tampering should be reported according to organisational procedure.
Travel Awareness Scenario

The Airport Lounge Conversation

Two employees discuss: an upcoming confidential acquisition.

Nearby passengers can hear: the entire conversation.

Information can be exposed through conversation just as easily as through a computer.
Travel OPSEC Scenario

The Conference Badge

Employee travels through the airport wearing: a corporate security badge showing company, role and full name.

Avoid unnecessarily advertising organisational access, role or sensitive affiliation when outside the controlled workplace.
Traveller Safety

Communication & Check-In

Depending on travel risk, an organisation may establish:

Emergency Contact Travel Itinerary Check-In Expectations Escalation Process Emergency Assistance Alternative Communication Method
The organisation should know how to contact and assist personnel when normal arrangements fail.
🌍 Legal & Cultural Environment Travel can change the rules around the employee

Travellers should receive appropriate guidance on:

Local Laws Entry Requirements Technology Restrictions Privacy Expectations Emergency Contacts Organisation Policy
Security policy does not override local law. Travel plans should account for the jurisdiction in which personnel will operate.
Official 7.15 Topic 2

Security Training & Awareness

ISC2 specifically calls out:

Insider Threat Social Media Impacts 2FA Fatigue

Awareness should help personnel:

Risk → Recognise
Suspicious Situation → Respond Safely
Concern → Report
Organisation → Investigate Appropriately
Insider Threat

Trusted Access Can Still Create Risk

An insider has some level of legitimate relationship, knowledge or access associated with the organisation.

The risk may involve:

Malicious Behaviour

Deliberate theft, sabotage, fraud or misuse.

Negligent Behaviour

Unintentional actions that expose information or systems.

Compromised Personnel

A legitimate person's credentials or device may be controlled or manipulated by an external attacker.

Insider risk does not mean assuming every employee is malicious. It means recognising that trusted access can be misused, mishandled or compromised.

Awareness Should Focus on Behaviour and Events

Relevant concerns might include:

Attempting Unnecessary Access Unusual Data Collection Repeated Policy Bypass Unauthorised Removal of Assets Suspicious Privilege Use Unexplained Security-Control Evasion
A suspicious event should be reported and assessed. It should not automatically be treated as proof that the person is malicious.
📣 Make Reporting Easy Employees should know what to do when something looks wrong

Personnel should know:

What to Report Where to Report How to Report Urgently What Information Helps
Awareness without a usable reporting path leaves the employee knowing something is wrong but not knowing what to do about it.
Insider Risk Scenario

The Unusual Download

Employee suddenly downloads: thousands of files outside their normal responsibility.

Best conclusion is not immediately: "the employee is stealing data."

Best operational response: validate the activity and investigate the context.

Indicator ≠ proof.
Official Awareness Example

Social Media Impacts

Publicly shared information can help an attacker build a convincing picture of:

Employee Names Job Roles Reporting Lines Travel Technology Projects Suppliers Office Locations Personal Interests
Information that seems harmless individually can become useful when an attacker combines many pieces together.
Social-Media Scenario

The Perfect Phishing Email

Employee posts publicly:

"Starting a new project with Acme Cloud" Manager's Name Conference Location Project Has Tight Deadline

Attacker sends:

"Urgent Acme Cloud project document - your manager needs this reviewed before tomorrow's conference."

Social-media information can make social engineering significantly more convincing.

Real-Time Location Can Create Physical Risk

Executive posts

"Away with the whole family for the next three weeks."

Their public profile also reveals: home location.

Social-media security can affect personal safety as well as information security.
Social-Media Scenario

The New Job Selfie

Employee posts: a high-resolution photograph of their corporate badge.

Photograph reveals:

Full Name Employee Number Badge Design Organisation Office Location
Personnel should understand that physical-security information can also be exposed digitally.
Official Awareness Example

2FA / MFA Fatigue

An attacker may already know or have stolen a user's password.

They repeatedly attempt to log in, causing the legitimate user's device to receive authentication prompts.

Password → Compromised
Attacker → Attempts Login
User → Receives MFA Prompt
Attacker → Repeats
User → Becomes Frustrated / Confused
User Approves → Attacker Authenticated

MFA Fatigue

PUSH Unexpected prompt
REPEAT Attacker keeps trying
FATIGUE User pressured
APPROVE Attacker gets in

Unexpected MFA Prompt = Security Signal

Employee

Is watching television at home.

Phone displays: "Approve corporate VPN sign-in?"

Employee did not initiate: any login.

Unexpected MFA Prompt

DO NOT APPROVE You did not initiate it
DENY Where supported
REPORT Security may need to investigate
Never approve an unexpected authentication request merely to make the prompts stop.
🔐 Training + Better Technology Do not make the user carry the entire defence

User awareness is important, but organisations can also reduce the opportunity for MFA-fatigue attacks.

Phishing-Resistant MFA

Stronger authentication mechanisms can remove much of the attacker's ability to trick users through simple push approval.

Number Matching

Requires additional context rather than simply tapping an unqualified "Approve" button.

Monitoring

Repeated authentication attempts may indicate credential compromise.

Reporting

Users need a clear way to report unexpected authentication prompts.

Awareness is one layer. Secure authentication design is another.
MFA Scenario

Twenty Push Notifications

Employee receives: 20 MFA prompts in five minutes.

They approve the twentieth because: "maybe the system is broken."

The correct security lesson is not "users are annoying." Repeated unexpected prompts can indicate an active authentication attack and should be reported.
Security Culture

Awareness Must Produce Behaviour

Training → Recognise
Recognise → Act Safely
Concern → Report
Report → Organisation Responds
Experience → Improve Training
Awareness is useful when it changes what people actually do.
Official 7.15 Topic 3

Emergency Management

Personnel should know what to do when ordinary security operations are replaced by an emergency.

Fire

Alarm, evacuation, accountability and emergency response.

Medical Emergency

Obtain appropriate medical assistance quickly.

Natural Hazard

Severe weather, flooding, earthquake or other environmental event.

Hazardous Condition

Chemical, electrical or other dangerous workplace condition.

Violence / Security Threat

Threatening or violent activity requiring emergency security procedures.

Major Infrastructure Failure

Loss of power, communications or safe access to the workplace.

Emergency Planning

Emergency Action Plan

A useful emergency plan should make critical actions clear before an emergency happens.

Report

How is the emergency reported?

Alarm

How are people warned?

Evacuate / Shelter

What protective action should personnel take?

Routes

How do personnel reach safety?

Accountability

How does the organisation determine whether people are safe?

Responsibilities

Who performs specialised emergency tasks?

Communication

How are employees and responders kept informed?

Training

Do employees know the procedures?

Emergency Personnel Flow

ALERT Recognise emergency
PROTECT Take safe action
MOVE Evacuate / shelter as required
ACCOUNT Know who is safe
COMMUNICATE Coordinate response
WAIT Return only when authorised

Evacuation

Recognisable Alarm Clear Exit Routes Assembly / Muster Location Trained Personnel Accessibility Needs Visitor Accountability Alternative Route
The goal is safe and orderly movement away from danger - not protection of equipment.
Emergency Scenario

The Laptop Left Behind

Employee evacuates during a fire alarm.

At the assembly point they remember: their laptop is still on the desk.

They should not: re-enter the building to retrieve it.

Equipment can be replaced. People cannot.
Emergency Accountability

Who Is Safe?

After evacuation, the organisation may need to account for:

Employees Visitors Contractors Temporary Personnel
Problem

Visitor log says: three contractors entered.

Nobody knows: whether they left before the alarm.

Visitor management can become a life-safety issue during an emergency.
🏃 Evacuation Is Not Always the Correct Response The safest action depends on the hazard
Evacuate

Move away from a dangerous location when leaving is the safer option.

Shelter / Remain in Safe Area

Some external or security hazards may make remaining in a protected location safer than leaving.

Follow the established emergency procedure appropriate to the hazard.

Emergency Alarms Must Produce Action

Office

Fire alarm triggers: several times every month because of false alarms.

Employees begin: ignoring it.

Repeated false alarms can create dangerous complacency. Alarms should be reliable, maintained and understood.
Preparation

Practise Before the Emergency

Training

Teach personnel the required actions.

Drills

Practise procedures under controlled conditions.

Observation

Identify confusion, delays and unsafe behaviour.

Improvement

Correct weaknesses before a real emergency.

Emergency Preparedness

PLAN Define actions
TRAIN Teach people
PRACTISE Exercise safely
IMPROVE Fix weaknesses

Emergency Plans Must Include Everyone

Plans should consider personnel who may require additional assistance because of:

Mobility Vision Hearing Temporary Injury Other Accessibility Needs
An evacuation plan that works only for some employees is incomplete.
Personnel Outside Normal Workplace

Lone & Remote Workers

Some personnel may work:

Alone At Night At Customer Sites In Remote Locations From Home While Travelling

Relevant controls can include:

Check-In Procedures Emergency Contacts Personal Alarm Lone-Worker Device Escalation Procedure Communication Capability
If nobody else is nearby, the worker needs a reliable way to obtain assistance.
Official 7.15 Topic 4

Duress

Duress occurs when a person is under threat, coercion or pressure and may not be able to communicate normally or act freely.

Example

Employee is being threatened and cannot safely say:

"Call the police. I am in danger."

A duress mechanism can provide: a discreet way to signal that assistance is required.

Duress Controls

Panic / Duress Alarm

Allows personnel to signal for assistance during a threatening situation.

Personal Alarm

Portable mechanism useful for lone or mobile workers.

Emergency Communication

Allows personnel to contact security or emergency support.

Check-In System

Failure to check in can trigger escalation for a lone worker.

Prearranged Duress Signal

Some environments may use predefined signals or procedures to indicate that a person is not communicating freely.

Security Response

The alarm must connect to an appropriate and understood response process.

Duress System

THREAT Person is at risk
SIGNAL Request help discreetly
RECEIVE Alarm reaches responder
ASSESS Understand situation
RESPOND Provide appropriate assistance
🆘 A Panic Button Is Only Useful If Someone Responds Alarm + monitoring + procedure
Reception desk

Panic button: installed.

Nobody knows:

Where Alarm Is Received Who Monitors It What Response Is Triggered Whether It Still Works
Duress capability should be trained, tested and connected to a defined response.

Discretion Can Matter

In some threatening situations, an obvious alarm may increase danger.

Depending on the risk and environment, organisations may therefore use appropriately designed:

Silent Alarms Personal Safety Devices Predefined Signals Monitored Check-In Systems
Duress controls should be designed around the safety of the person using them - not merely around technical convenience.
Duress Readiness

Personnel Must Know How the Control Works

When

Under what circumstances should it be used?

How

How is the alarm or signal activated?

Who

Who receives the alert?

What Happens

What response should the person expect?

Testing

How is the system tested without accidentally causing an emergency response?

Reporting

What should happen after an activation or incident?

Duress Scenario

The Threatened Receptionist

An aggressive individual demands access to: a restricted office.

Receptionist feels unable to openly call security without increasing the threat.

A properly designed silent duress mechanism can: alert security without requiring an obvious confrontation.

Duress controls are intended to help personnel request assistance when ordinary communication may not be safe.
Lone Worker Scenario

The Engineer Who Misses Check-In

Engineer works alone at: a remote infrastructure facility.

Procedure requires: check-in every two hours.

Check-in is missed.

Missed Check-In → Contact Worker
No Response → Escalate
Potential Emergency → Appropriate Assistance
A missed check-in can itself become a safety signal.
Personnel Security

Workplace Violence & Aggression

Personnel security planning may need to consider:

Aggressive Visitors Threats Harassment Physical Assault Targeted Individuals Domestic Issues Affecting Workplace Safety

Possible controls include:

Risk Assessment Access Controls Security Personnel Alarms Reporting Procedures Training Emergency Response

Do Not Turn Employees Into Security Enforcers

Employees should understand: when to disengage and obtain professional assistance.

Situation

Employee sees: a threatening individual attempting to force entry.

They should not automatically: physically confront the person.

Personal safety takes priority over attempting to personally enforce a security control.
Personnel Scenario

The Suspicious Person

Employee notices: an unidentified person repeatedly attempting restricted doors.

Appropriate action is generally: follow organisational reporting/security procedures.

Awareness should encourage reporting, not unsafe confrontation.
Personnel Risk

Higher-Risk Personnel Events

Some organisational events may justify additional coordination between:

Management Human Resources Physical Security Cybersecurity Legal
Example

Organisation believes a particular termination presents: an elevated security or safety risk.

Personnel, physical-access and logical-access actions may need: careful coordination.

Personnel safety can require coordinated physical, technical and administrative controls.

High-Profile Personnel

Executives or other high-profile personnel may face additional risks from:

Targeted Phishing Social Engineering Doxxing Stalking Travel Exposure Public Event Exposure
Security measures should reflect threat and exposure rather than assume one programme fits every employee.
Combined Scenario

"Flying to Singapore Tomorrow!"

Senior administrator publicly posts:

"Flying to Singapore tomorrow for our data-centre migration!"

Post reveals:

Travel Date Destination Role Technical Project
Travel and social-media risk can combine to make targeted attacks easier.
Emergency Communications

Normal Communication May Fail

Cyber incident

Organisation shuts down: corporate identity and email.

Emergency plan requires: emailing employees.

SMS Emergency Notification Platform Telephone External Status Service Alternate Contact Process
Emergency communication should not depend entirely on the system the emergency may disable.

Emergency Contact Information

Contact information should be:

Current Appropriately Protected Available When Needed Accessible to Authorised Responders
A perfect emergency plan with obsolete phone numbers is not a perfect emergency plan.
Security Operations

A Security Incident Can Become a Personnel-Safety Incident

Ransomware

May disrupt building access, communications or safety systems.

Physical Intrusion

May place employees in direct danger.

Insider Threat

May involve both information misuse and threats toward personnel.

Critical Infrastructure Attack

Cyber effects may create real-world operational hazards.

Cybersecurity decisions should consider consequences for people, not just consequences for systems.
Cyber-Physical Scenario

The Building Access Failure

Cyberattack disrupts: electronic access-control system.

Security team focuses on: restoring the server.

But physical-security team also needs to understand:

Can Employees Exit? Can Emergency Responders Enter? Are Restricted Doors Secure? Is Manual Control Needed?
Technology recovery should include its personnel-safety implications.
Training Quality

Generic Annual Training Is Not Enough

Role-Specific

A receptionist may need different safety training from a remote system administrator.

Risk-Specific

International travellers may need additional travel guidance.

Current

Training should evolve as threats change.

Practical

Personnel should know exactly what action to take.

Good awareness answers: "What should I actually do if this happens?"

Personnel Safety Should Be Exercised

Evacuation Drill Emergency Communication Test Travel Incident Tabletop Lone-Worker Check-In Test Duress Alarm Test Workplace Threat Exercise
A safety control that has never been practised may fail when people are under real pressure.
After an Event

Learn From Personnel-Safety Events

Incident → Protect People
After Immediate Risk → Document
Event → Analyse
Weakness → Correct
Corrective Action → Train / Retest
Personnel-safety programmes should improve from incidents, near misses and exercises.
⚠️ Near Misses Matter Too Do not wait for somebody to be injured before improving a control
Incident

Lone worker presses: personal alarm.

Alarm reaches: an unmonitored mailbox.

Worker eventually reaches safety independently.

No injury does not mean the control worked.
🎓 CISSP Scenarios Recognise the personnel safety and security principle being tested
Scenario 1

Fire alarm activates while an administrator is performing a critical server upgrade.

First priority?

Personnel safety and evacuation.

Scenario 2

An employee wants to re-enter an evacuated building for a laptop.

Best response?

Do not re-enter until authorised and safe.

Scenario 3

An international traveller is carrying years of customer data that is not needed for the trip.

Best principle?

Data minimisation.

Scenario 4

A high-risk traveller needs only email and presentation access.

Useful approach?

Provide appropriately restricted, managed travel capability rather than unnecessary broad access.

Scenario 5

Employee connects a corporate laptop to an unknown USB device found at a conference.

Primary concern?

Untrusted peripheral / interface risk.

Scenario 6

Employee uses unfamiliar public Wi-Fi while travelling.

Best principle?

Treat uncontrolled networks as untrusted and follow approved secure-connectivity policy.

Scenario 7

Corporate laptop is stolen while travelling.

First security action after ensuring personal safety?

Report the loss promptly according to organisational procedure.

Scenario 8

An employee believes their hotel-room laptop may have been tampered with.

Best response?

Report suspected compromise and follow organisational handling procedures.

Scenario 9

Two employees discuss confidential merger details in an airport lounge.

Primary risk?

Information disclosure through overheard conversation.

Scenario 10

Employee wears a corporate access badge publicly throughout their journey.

Primary concern?

Unnecessary disclosure of identity, role and organisational affiliation.

Scenario 11

Employee posts live details of a sensitive business trip on social media.

Which 7.15 concerns overlap?

Travel and social-media security.

Scenario 12

Public social profile reveals employee's manager, supplier and current project.

How can an attacker use this?

To create more convincing targeted social engineering.

Scenario 13

An employee publicly posts a detailed image of their security badge.

Primary concern?

Exposure of physical-security and identity information.

Scenario 14

User receives an MFA approval request without attempting to log in.

Best action?

Do not approve it and report the unexpected authentication attempt.

Scenario 15

User receives dozens of authentication prompts and eventually approves one to make them stop.

Which attack?

MFA / 2FA fatigue or push bombing.

Scenario 16

What organisational control can reduce simple push-approval attacks?

Examples?

Phishing-resistant MFA or stronger mechanisms such as number matching where appropriate.

Scenario 17

Repeated unexpected MFA prompts occur.

What might this indicate?

An attacker may already possess the user's primary credential.

Scenario 18

An employee downloads an unusually large amount of information.

Does this prove insider theft?

No. It is an indicator requiring context and investigation.

Scenario 19

Insider-threat awareness causes staff to accuse colleagues based only on personal characteristics.

Primary problem?

Security should focus on relevant behaviour and evidence, not unsupported assumptions.

Scenario 20

Employees are trained to identify suspicious behaviour but do not know how to report it.

Primary weakness?

No usable reporting path.

Scenario 21

Building fire alarm activates.

What should personnel generally follow?

The established emergency procedure and evacuation instructions.

Scenario 22

Employees evacuate but nobody knows whether visitors remain inside.

Which capability is weak?

Personnel accountability / visitor management.

Scenario 23

An external hazard makes leaving the building more dangerous than remaining inside.

Must evacuation always occur?

No. The appropriate emergency procedure may require sheltering or another protective action.

Scenario 24

Fire alarm generates frequent false alerts and staff begin ignoring it.

Primary risk?

Complacency / alarm fatigue affecting emergency response.

Scenario 25

A mobility-impaired employee cannot use the normal evacuation route.

What should planning address?

Appropriate accessible emergency arrangements.

Scenario 26

Employee works alone at a remote site.

Useful personnel-safety control?

Check-in, emergency communications or an appropriate lone-worker alarm system.

Scenario 27

A lone worker misses a required check-in and cannot be contacted.

What should happen?

Follow the predefined escalation procedure.

Scenario 28

An employee is threatened and cannot safely make an obvious call for help.

Which concept?

Duress.

Scenario 29

A silent alarm allows a threatened receptionist to discreetly request assistance.

Which control?

Duress / panic alarm.

Scenario 30

A panic button is installed but nobody monitors the alert.

Primary lesson?

Detection without response is incomplete.

Scenario 31

Employees have duress alarms but have never been told when or how to use them.

Primary weakness?

Insufficient training and awareness.

Scenario 32

A threatening visitor tries to force entry and an employee decides to physically stop them.

Best CISSP mindset?

Personnel should prioritise safety and follow established security/emergency procedures rather than create unnecessary personal danger.

Scenario 33

An unfamiliar person repeatedly tries restricted doors.

Appropriate employee behaviour?

Report the concern through the appropriate security process.

Scenario 34

A cyberattack disables electronic building access.

What else should responders consider besides server restoration?

Personnel safety, emergency egress and physical-access implications.

Scenario 35

Corporate email is unavailable during an emergency.

What should exist?

An appropriate alternate emergency communication method.

Scenario 36

An emergency contact list contains phone numbers belonging to former employees.

Primary problem?

Emergency information was not maintained.

Scenario 37

A duress alarm works technically, but responders take 40 minutes because no response procedure exists.

Primary lesson?

Control effectiveness includes operational response, not only technical activation.

Scenario 38

A worker survives a safety incident despite the emergency system failing.

Should the event still be reviewed?

Yes. Near misses can reveal serious weaknesses.

Scenario 39

An executive receives much more targeted social engineering than ordinary employees.

What principle applies?

Personnel security should be risk-based and role-appropriate.

Scenario 40

A security-awareness programme uses identical generic content for every employee.

Potential improvement?

Add role-specific and risk-specific training.

Scenario 41

Employees can describe the evacuation procedure but have never practised it.

What would strengthen assurance?

An appropriate drill or exercise.

Scenario 42

A traveller's device is compromised but no process exists for post-travel assessment.

Which lifecycle phase is weak?

Return / post-travel security handling.

Scenario 43

Management asks what the current 7.15 awareness examples are.

Answer?

Insider threat, social-media impacts and 2FA fatigue.

Scenario 44

Management asks what four areas make up 7.15.

Answer?

Travel, security training and awareness, emergency management and duress.

Scenario 45

Management asks for the central principle of personnel safety and security.

Best answer?

Protect people first, prepare them for the risks associated with their roles and travel, teach them how to recognise and report security concerns, maintain effective emergency procedures and provide reliable ways to obtain assistance when they are under threat or duress.

CISSP Exam Perspective

Recognise the Clue Words

Immediate Danger

Highest priority.

Personnel Safety

Travelling Employee

Official topic.

Travel Security

Only Necessary Data

Travel exposure.

Minimise

Higher-Risk Journey

Prepare first.

Travel Risk Assessment

Untrusted Hotel Network

Connectivity.

Approved Secure Access

Lost Laptop

After personal safety.

Report Promptly

Hotel Device Tampering

Potential compromise.

Report / Assess

Employee Collecting Unusual Data

Trusted access.

Insider Risk

Suspicious Behaviour

Not proof.

Report + Investigate

LinkedIn Reveals Project

Attack preparation.

Social-Media Exposure

Repeated MFA Prompts

Official example.

MFA Fatigue

Unexpected MFA Prompt

User action.

Deny + Report

Strongest MFA Direction

Technical mitigation.

Phishing-Resistant MFA

Fire Alarm

Safety.

Emergency Management

Assembly Point

Who is safe?

Personnel Accountability

Worker Cannot Evacuate Normally

Inclusive planning.

Accessibility

Worker Alone

Safety.

Check-In / Personal Alarm

Threatened Person

Official topic.

Duress

Silent Panic Button

Request help.

Duress Alarm

Alarm With Nobody Monitoring

Incomplete control.

No Effective Response

Employee Wants to Confront Threat

CISSP priority.

Protect the Person

False Emergency Alarms

Behaviour.

Complacency / Alarm Fatigue

Plan Known but Never Practised

Readiness.

Exercise

No Injury but Control Failed

Learning.

Near Miss
⚠️ Common CISSP Mistakes People come before systems
Data ≠ More Valuable Than Human Life

Protect people first.

Critical Server ≠ Reason to Ignore Evacuation

Equipment should not take priority over personal safety.

Travel ≠ Normal Office Environment

Different physical, technical and legal risks may apply.

Take Everything ≠ Best Travel Security

Minimise devices, information and privileges where appropriate.

Encryption ≠ Device Cannot Be Lost

Physical protection remains important.

Public Wi-Fi ≠ Trusted Corporate Network

Follow approved secure-connectivity procedures.

Lost Device ≠ Risk Personal Safety Retrieving It

Report and allow appropriate organisational response.

Social Media ≠ Only Personal Information

Public posts can expose organisational information and enable targeting.

Badge Photo ≠ Harmless Picture

Physical-access information may be exposed.

Insider Threat ≠ Every Employee Is Malicious

Investigate relevant indicators and behaviour.

Anomaly ≠ Proof

Validate context before drawing conclusions.

Awareness ≠ Suspicion Culture

Train personnel to recognise and report relevant risk, not make unsupported accusations.

MFA Enabled ≠ All MFA Equally Strong

Some mechanisms remain vulnerable to social-engineering techniques.

Unexpected MFA Prompt ≠ System Glitch

It may indicate attempted account compromise.

Repeated Pushes ≠ Approve to Stop Them

Deny unexpected attempts and report them.

User Training ≠ Only MFA Defence

Stronger authentication design can reduce the underlying opportunity.

Evacuate ≠ Always Correct for Every Hazard

Follow the emergency action appropriate to the situation.

Evacuated ≠ Everyone Safe

Personnel accountability may still be required.

Employee List ≠ Everyone in Building

Visitors and contractors may also need accounting.

Emergency Plan ≠ Useful Without Training

Personnel need to understand their responsibilities.

Training ≠ Practice

Exercises can reveal problems that classroom instruction does not.

Panic Button Installed ≠ Duress Capability Works

It must be monitored and connected to an effective response.

Alarm ≠ Response

Someone must receive, understand and act on it.

Lone Worker ≠ Ordinary Office Risk

Communication and assistance arrangements may need additional controls.

Suspicious Person ≠ Employee Must Confront Them

Follow established security procedures and prioritise personal safety.

No Injury ≠ Control Worked

Near misses can expose serious weaknesses.

Domain 1.8 ≠ Domain 7.15

Domain 1.8 addresses personnel-security policies and lifecycle. Domain 7.15 addresses operational personnel safety and security.

Quick Reference

If you see...Think...
Threat to human lifePeople First
International employee journeyTravel Security
Destination riskPre-Travel Assessment
Unnecessary information on travel deviceData Minimisation
Higher-risk journeyRestricted / Managed Travel Capability
Untrusted networkApproved Secure Connectivity
Lost travel deviceReport Promptly
Suspected hotel-device tamperingPotential Compromise
Public information used for targeted attackSocial-Media Exposure
Trusted employee behaving unusuallyInsider Risk
Suspicious activity without proofInvestigate Context
Repeated MFA promptsMFA Fatigue / Push Bombing
Unexpected MFA promptDeny + Report
Reduce push-fatigue weaknessPhishing-Resistant MFA / Stronger MFA
Fire / major safety eventEmergency Management
Who is safe after evacuation?Personnel Accountability
Alternative to evacuationShelter / Appropriate Protective Action
Worker aloneLone-Worker Controls
Threat / coercionDuress
Silent request for assistanceDuress / Panic Alarm
Alarm has no responderIncomplete Control
Practice emergency procedureDrill / Exercise
Incident where nobody was hurtNear Miss
Screening / onboarding / terminationDomain 1.8
Travel / emergency / duressDomain 7.15

Official 7.15 Memory Aid

TRAVEL Protect away from normal controls
AWARENESS Insider · social · MFA
EMERGENCY Protect people
DURESS Get help under threat

Travel Memory Aid

ASSESS Know destination risk
MINIMISE Data + devices + privilege
PROTECT Person + device
CONNECT Use approved secure access
REPORT Lost / stolen / suspicious
RETURN Assess residual risk

MFA Fatigue Memory Aid

UNEXPECTED? You did not initiate login
DENY Do not approve
REPORT Possible account attack
STRENGTHEN Use stronger MFA

Emergency Memory Aid

ALERT Something happened
PEOPLE Protect life first
ACTION Evacuate / shelter / respond
ACCOUNT Who is safe?
COMMUNICATE Coordinate
LEARN Improve

Duress Memory Aid

THREAT Person under pressure
SIGNAL Request help
MONITOR Someone receives it
RESPOND Provide assistance

7.15 Master Memory Aid

PREPARE Understand personnel risk
MINIMISE Reduce unnecessary exposure
RECOGNISE Spot suspicious situations
REPORT Raise concerns early
PROTECT People first
RESPOND Emergency / duress procedures
IMPROVE Learn from events

Prepare → Recognise → Protect → Report → Respond

The Personnel Security Leader's Questions

WHO? Which personnel face elevated risk?
WHERE? Are they travelling or working remotely?
WHAT DATA? What do they genuinely need?
WHAT DEVICE? Is the technology appropriate?
CONTACT? Can they obtain help?
AWARE? Do they recognise insider/social/MFA risk?
EMERGENCY? Do they know what to do?
ACCOUNTED? Can we determine who is safe?
DURESS? Can threatened personnel request help?
MONITORED? Will someone receive the signal?
RESPONSE? What happens next?
PRACTISED? Has the procedure been exercised?
IMPROVED? Did incidents change the programme?

Key Takeaways

CISSP 7.15 is officially: Address personnel safety and security concerns.

The current CISSP outline explicitly identifies four areas: travel, security training and awareness, emergency management and duress.

Security exists to protect people as well as information and technology.

During an immediate threat to human safety: people come first.

An employee should not remain inside a dangerous facility merely to protect a server, application or dataset.

Human life > equipment > data availability.

Personnel safety and personnel security overlap but are not identical.

Safety addresses hazards and injury. Security also addresses intentional threats such as coercion, violence, targeted social engineering and insider activity.

Personnel protection should be risk-based.

A travelling executive, lone engineer and ordinary office worker may need different controls.

Travel moves personnel away from many normal organisational safeguards.

Travel planning should therefore consider the destination, activity, employee profile, technology, information and available support.

Travel security begins before departure.

Personnel travelling to higher-risk environments may require additional preparation and more restrictive technology arrangements.

A core travel principle is minimisation.

Personnel should carry only the information, devices and access required for the trip where practical.

What does not travel cannot be lost from the travel device.

Organisations may use appropriately prepared travel devices containing limited data and access.

Devices should be appropriately patched, encrypted, authenticated and managed.

Travellers should maintain appropriate physical control of their devices.

Encryption reduces data exposure but does not eliminate the operational consequences of a lost laptop.

Networks outside organisational control should be treated as untrusted.

Employees should follow organisational policy for approved secure remote connectivity.

Unknown USB devices, charging connections and wireless peripherals can introduce additional technical risk.

Personnel should avoid exposing sensitive information through public conversations, unattended documents or visible screens.

A confidential conversation in an airport lounge can disclose information just as effectively as an email sent to the wrong person.

Personnel should also avoid unnecessarily advertising security badges, organisational access or sensitive business affiliation while travelling.

Lost or stolen equipment should be reported quickly.

Employees should not put themselves in danger attempting to personally retrieve equipment.

Person first. Device incident second.

Suspected physical tampering with travelling devices should be treated as a potential security concern.

Travel plans may also need to account for different legal and cultural environments.

Organisational policy does not override the laws of the jurisdiction in which the traveller is operating.

Travel programmes should provide usable emergency contact and escalation mechanisms.

The current ISC2 objective specifically mentions insider threat as part of security awareness.

Insider risk can arise when trusted organisational access is intentionally misused, negligently handled or compromised by another party.

Insider-threat awareness should not create an environment where everyone automatically suspects everyone else.

Security decisions should be based on relevant behaviour, events, evidence and context.

Indicator ≠ proof.

Personnel should know how to report suspicious activity safely and appropriately.

Awareness without a usable reporting mechanism is incomplete.

Social-media impact is another explicit CISSP 7.15 awareness topic.

Public information about employees, projects, suppliers, travel, roles and reporting lines can help attackers construct convincing social engineering.

Small individual pieces of information can become valuable when combined.

Social-media exposure can create physical-security risk as well as cybersecurity risk.

Publicly advertising travel, home location or a detailed corporate badge may reveal information useful to a malicious actor.

The current CISSP outline also explicitly includes two-factor authentication fatigue.

MFA fatigue occurs when an attacker repeatedly triggers authentication requests hoping the legitimate user will eventually approve one.

Repeated unexpected MFA prompts should be treated as a potential security signal.

If you did not initiate the login, do not approve the authentication request merely to make the prompts disappear.

Personnel should deny and report unexpected authentication attempts using established organisational procedures.

Training is only one layer of protection against MFA-fatigue attacks.

Organisations can also implement stronger authentication mechanisms.

CISA recommends movement toward phishing-resistant MFA and identifies number matching as a stronger alternative to simple push approval where phishing-resistant authentication cannot yet be deployed.

User awareness + stronger authentication = better defence.

Emergency management is the third official 7.15 area.

Personnel should know how emergencies are reported, how alarms are communicated, what protective action is required and how people will be accounted for.

Emergency plans may address fire, medical emergencies, hazardous conditions, natural hazards, infrastructure failures and security events.

Evacuation is an important emergency response but is not necessarily the correct response to every hazard.

Some situations may require personnel to remain or shelter in an appropriate safe location.

Personnel should follow the established emergency procedure relevant to the threat.

Emergency plans should include routes, alarms, responsibilities, communications and personnel accountability.

Visitors and contractors matter too.

Knowing that employees evacuated is insufficient if the organisation cannot determine whether visitors remain inside.

Accessibility should be included in emergency planning.

Personnel who cannot use the normal evacuation route may require appropriate alternative arrangements.

Emergency plans should be trained and practised.

Plan written ≠ people prepared.

Drills and exercises can reveal confusing instructions, blocked routes, communication problems and other weaknesses before a genuine emergency.

Repeated false alarms can create complacency and weaken emergency response.

Alarm systems should therefore be maintained and personnel should understand what the alarms mean.

Lone and remote workers may require additional arrangements because immediate assistance may not be nearby.

Check-in procedures, emergency communication and personal-safety devices may form part of this protection.

A missed check-in can itself trigger an escalation procedure.

Duress is the final explicit CISSP 7.15 area.

Duress concerns situations where personnel are threatened, coerced or otherwise unable to communicate freely.

Appropriate controls may include panic alarms, personal alarms, monitored check-in systems and other predefined methods of requesting assistance.

In some environments the signal may need to be discreet because an obvious request for help could increase the danger to the person.

Duress = request assistance when normal communication may not be safe.

A duress alarm alone is not sufficient.

Someone needs to receive the signal and understand how to respond.

Alarm + monitoring + response = usable duress capability.

Personnel also need training on when and how the duress mechanism should be used.

Duress systems should be tested appropriately so that organisations know the signal reaches the intended responder.

Personnel should not be expected to physically confront threatening individuals when doing so would create unnecessary personal danger.

Employees should follow established security and emergency procedures and obtain assistance where appropriate.

Cybersecurity incidents can also affect personnel safety.

A cyberattack against building access, communications, industrial systems or safety technology may create physical consequences.

Security operations should therefore consider: what does this technical incident mean for people?

Security training should be role-specific where appropriate.

A receptionist facing public interaction, a privileged administrator, a lone engineer and an international traveller may need different preparation.

Personnel-safety incidents and near misses should be reviewed.

The fact that nobody was injured does not prove that a safety control functioned correctly.

No injury ≠ no problem.

Lessons should feed into improved procedures, technology and training.

Domain 1.8 and 7.15 should not be confused.

Domain 1.8 addresses personnel-security policies such as screening, onboarding, transfers, termination and contractor arrangements.

Domain 7.15 addresses operational concerns affecting the safety and security of personnel.

The four official topics can be remembered simply as:

TRAVEL → AWARENESS → EMERGENCY → DURESS

The central CISSP principle is:

understand the risks personnel face, prepare them before exposure, minimise unnecessary information and access, teach them to recognise and report suspicious activity, protect human life before technology, maintain effective emergency procedures and ensure people have a reliable way to obtain help when they are threatened or under duress.

📚 Sources & Further Reading Personnel safety, travel, awareness, emergency and duress references