7.15 Personnel Safety & Security
7.15 Personnel Safety & Security
Security exists to protect organisations, information and technology.
But during an emergency or threatening situation, one principle overrides almost everything else:
people come first.
Employees may travel to unfamiliar locations, face social engineering, encounter insider threats, receive malicious MFA prompts, work alone, experience emergencies or be placed under physical or psychological pressure.
Personnel safety and security therefore means preparing people to: recognise risk, avoid unnecessary exposure, communicate problems, respond appropriately and obtain help when necessary.
Travel
Protect people, devices, information and credentials away from the normal controlled environment.
PREPARE BEFORE YOU GOAwareness
Help personnel recognise insider risk, social-media exposure and authentication attacks.
RECOGNISE & REPORTEmergency & Duress
Give people practical ways to reach safety and request assistance under abnormal or threatening conditions.
PEOPLE FIRSTAddress Personnel Safety and Security Concerns
The current CISSP Exam Outline explicitly identifies four areas.
Protect personnel and organisational assets while employees are away from normal working environments.
Includes topics such as insider threat, social-media impacts and two-factor authentication fatigue.
Prepare personnel to respond safely and effectively when an emergency occurs.
Provide ways for personnel to obtain assistance when they are under coercion, threat or immediate danger.
Official 7.15 Topics
Domain 1.8 vs Domain 7.15
Focuses on organisational personnel-security processes.
MANAGE THE PERSONNEL LIFECYCLE
Focuses on protecting personnel during security operations.
KEEP PEOPLE SAFE
Human Life Takes Priority
Engineer notices: critical storage systems are still running.
Fire alarm activates and evacuation is ordered.
Should the engineer remain behind to perform a graceful shutdown?
No.
Safety and Security Are Related but Different
Protect people from injury, illness and dangerous conditions.
Protect people from intentional threats and hostile activity.
Personnel Protection Should Be Risk-Based
Not every employee faces the same risk.
Travel Security
Travel moves employees outside many of the controls normally available inside the organisation.
Travellers may be exposed to unfamiliar locations, transportation, political conditions or crime.
Laptops and mobile devices may be lost, stolen or physically accessed.
Travellers may depend on networks outside organisational control.
Sensitive information may be exposed through devices, conversations, documents or observation.
Laws, customs requirements and privacy expectations may differ across jurisdictions.
Employees need to know how to contact the organisation and obtain assistance.
Travel Security Lifecycle
Pre-Travel Risk Assessment
What security, political, health or environmental risks exist?
What activities will the traveller perform?
What sensitive information does the traveller genuinely need?
Which devices and services are required?
Does the traveller's role make them a particularly valuable target?
How can the traveller contact the organisation during an emergency?
🧳 Travel Security Briefing Prepare the employee before departure
Take Only What You Need
Laptop contains: ten years of locally stored customer records.
None are required for: the conference.
Travel Data Principle
Travel Devices
Depending on risk, organisations may provide: managed devices specifically prepared for travel.
💻 Higher-Risk Travel Device Reduce information and access exposed to the journey
For some higher-risk travel, an organisation may choose a device that contains only:
After return, organisational procedure may require: inspection, secure erasure or rebuilding of the device.
Treat Uncontrolled Networks as Untrusted
Employee sees:
Which one is genuine? Not immediately obvious.
Organisation-approved approaches may include:
External Interfaces Matter While Travelling
Avoid connecting unknown storage devices or peripherals.
Use organisation-approved charging arrangements where required rather than connecting devices unnecessarily to unknown systems.
Disable unnecessary wireless interfaces when they are not required.
Treat unknown accessories as potential security risks.
Maintain Control of Devices
Employee leaves corporate laptop: unattended in a public meeting room during lunch.
The Laptop in the Taxi
Employee leaves: corporate laptop in a taxi.
Priority should not be: personally chasing the vehicle through an unfamiliar city.
Hotel & Temporary Workspace Security
Employee notices: laptop bag and device are arranged differently.
Best approach is not: simply ignore it and continue working.
The Airport Lounge Conversation
Two employees discuss: an upcoming confidential acquisition.
Nearby passengers can hear: the entire conversation.
The Conference Badge
Employee travels through the airport wearing: a corporate security badge showing company, role and full name.
Communication & Check-In
Depending on travel risk, an organisation may establish:
🌍 Legal & Cultural Environment Travel can change the rules around the employee
Travellers should receive appropriate guidance on:
Security Training & Awareness
ISC2 specifically calls out:
Awareness should help personnel:
Trusted Access Can Still Create Risk
An insider has some level of legitimate relationship, knowledge or access associated with the organisation.
The risk may involve:
Deliberate theft, sabotage, fraud or misuse.
Unintentional actions that expose information or systems.
A legitimate person's credentials or device may be controlled or manipulated by an external attacker.
Awareness Should Focus on Behaviour and Events
Relevant concerns might include:
📣 Make Reporting Easy Employees should know what to do when something looks wrong
Personnel should know:
The Unusual Download
Employee suddenly downloads: thousands of files outside their normal responsibility.
Best conclusion is not immediately: "the employee is stealing data."
Best operational response: validate the activity and investigate the context.
Social Media Impacts
Publicly shared information can help an attacker build a convincing picture of:
The Perfect Phishing Email
Employee posts publicly:
Attacker sends:
"Urgent Acme Cloud project document - your manager needs this reviewed before tomorrow's conference."
Real-Time Location Can Create Physical Risk
"Away with the whole family for the next three weeks."
Their public profile also reveals: home location.
The New Job Selfie
Employee posts: a high-resolution photograph of their corporate badge.
Photograph reveals:
2FA / MFA Fatigue
An attacker may already know or have stolen a user's password.
They repeatedly attempt to log in, causing the legitimate user's device to receive authentication prompts.
MFA Fatigue
Unexpected MFA Prompt = Security Signal
Is watching television at home.
Phone displays: "Approve corporate VPN sign-in?"
Employee did not initiate: any login.
Unexpected MFA Prompt
🔐 Training + Better Technology Do not make the user carry the entire defence
User awareness is important, but organisations can also reduce the opportunity for MFA-fatigue attacks.
Stronger authentication mechanisms can remove much of the attacker's ability to trick users through simple push approval.
Requires additional context rather than simply tapping an unqualified "Approve" button.
Repeated authentication attempts may indicate credential compromise.
Users need a clear way to report unexpected authentication prompts.
Twenty Push Notifications
Employee receives: 20 MFA prompts in five minutes.
They approve the twentieth because: "maybe the system is broken."
Awareness Must Produce Behaviour
Emergency Management
Personnel should know what to do when ordinary security operations are replaced by an emergency.
Alarm, evacuation, accountability and emergency response.
Obtain appropriate medical assistance quickly.
Severe weather, flooding, earthquake or other environmental event.
Chemical, electrical or other dangerous workplace condition.
Threatening or violent activity requiring emergency security procedures.
Loss of power, communications or safe access to the workplace.
Emergency Action Plan
A useful emergency plan should make critical actions clear before an emergency happens.
How is the emergency reported?
How are people warned?
What protective action should personnel take?
How do personnel reach safety?
How does the organisation determine whether people are safe?
Who performs specialised emergency tasks?
How are employees and responders kept informed?
Do employees know the procedures?
Emergency Personnel Flow
Evacuation
The Laptop Left Behind
Employee evacuates during a fire alarm.
At the assembly point they remember: their laptop is still on the desk.
They should not: re-enter the building to retrieve it.
Who Is Safe?
After evacuation, the organisation may need to account for:
Visitor log says: three contractors entered.
Nobody knows: whether they left before the alarm.
🏃 Evacuation Is Not Always the Correct Response The safest action depends on the hazard
Move away from a dangerous location when leaving is the safer option.
Some external or security hazards may make remaining in a protected location safer than leaving.
Emergency Alarms Must Produce Action
Fire alarm triggers: several times every month because of false alarms.
Employees begin: ignoring it.
Practise Before the Emergency
Teach personnel the required actions.
Practise procedures under controlled conditions.
Identify confusion, delays and unsafe behaviour.
Correct weaknesses before a real emergency.
Emergency Preparedness
Emergency Plans Must Include Everyone
Plans should consider personnel who may require additional assistance because of:
Lone & Remote Workers
Some personnel may work:
Relevant controls can include:
Duress
Duress occurs when a person is under threat, coercion or pressure and may not be able to communicate normally or act freely.
Employee is being threatened and cannot safely say:
"Call the police. I am in danger."
A duress mechanism can provide: a discreet way to signal that assistance is required.
Duress Controls
Allows personnel to signal for assistance during a threatening situation.
Portable mechanism useful for lone or mobile workers.
Allows personnel to contact security or emergency support.
Failure to check in can trigger escalation for a lone worker.
Some environments may use predefined signals or procedures to indicate that a person is not communicating freely.
The alarm must connect to an appropriate and understood response process.
Duress System
🆘 A Panic Button Is Only Useful If Someone Responds Alarm + monitoring + procedure
Panic button: installed.
Nobody knows:
Discretion Can Matter
In some threatening situations, an obvious alarm may increase danger.
Depending on the risk and environment, organisations may therefore use appropriately designed:
Personnel Must Know How the Control Works
Under what circumstances should it be used?
How is the alarm or signal activated?
Who receives the alert?
What response should the person expect?
How is the system tested without accidentally causing an emergency response?
What should happen after an activation or incident?
The Threatened Receptionist
An aggressive individual demands access to: a restricted office.
Receptionist feels unable to openly call security without increasing the threat.
A properly designed silent duress mechanism can: alert security without requiring an obvious confrontation.
The Engineer Who Misses Check-In
Engineer works alone at: a remote infrastructure facility.
Procedure requires: check-in every two hours.
Check-in is missed.
Workplace Violence & Aggression
Personnel security planning may need to consider:
Possible controls include:
Do Not Turn Employees Into Security Enforcers
Employees should understand: when to disengage and obtain professional assistance.
Employee sees: a threatening individual attempting to force entry.
They should not automatically: physically confront the person.
The Suspicious Person
Employee notices: an unidentified person repeatedly attempting restricted doors.
Appropriate action is generally: follow organisational reporting/security procedures.
Higher-Risk Personnel Events
Some organisational events may justify additional coordination between:
Organisation believes a particular termination presents: an elevated security or safety risk.
Personnel, physical-access and logical-access actions may need: careful coordination.
High-Profile Personnel
Executives or other high-profile personnel may face additional risks from:
"Flying to Singapore Tomorrow!"
Senior administrator publicly posts:
"Flying to Singapore tomorrow for our data-centre migration!"
Post reveals:
Normal Communication May Fail
Organisation shuts down: corporate identity and email.
Emergency plan requires: emailing employees.
Emergency Contact Information
Contact information should be:
A Security Incident Can Become a Personnel-Safety Incident
May disrupt building access, communications or safety systems.
May place employees in direct danger.
May involve both information misuse and threats toward personnel.
Cyber effects may create real-world operational hazards.
The Building Access Failure
Cyberattack disrupts: electronic access-control system.
Security team focuses on: restoring the server.
But physical-security team also needs to understand:
Generic Annual Training Is Not Enough
A receptionist may need different safety training from a remote system administrator.
International travellers may need additional travel guidance.
Training should evolve as threats change.
Personnel should know exactly what action to take.
Personnel Safety Should Be Exercised
Learn From Personnel-Safety Events
⚠️ Near Misses Matter Too Do not wait for somebody to be injured before improving a control
Lone worker presses: personal alarm.
Alarm reaches: an unmonitored mailbox.
Worker eventually reaches safety independently.
🎓 CISSP Scenarios Recognise the personnel safety and security principle being tested
Fire alarm activates while an administrator is performing a critical server upgrade.
First priority?
Personnel safety and evacuation.
An employee wants to re-enter an evacuated building for a laptop.
Best response?
Do not re-enter until authorised and safe.
An international traveller is carrying years of customer data that is not needed for the trip.
Best principle?
Data minimisation.
A high-risk traveller needs only email and presentation access.
Useful approach?
Provide appropriately restricted, managed travel capability rather than unnecessary broad access.
Employee connects a corporate laptop to an unknown USB device found at a conference.
Primary concern?
Untrusted peripheral / interface risk.
Employee uses unfamiliar public Wi-Fi while travelling.
Best principle?
Treat uncontrolled networks as untrusted and follow approved secure-connectivity policy.
Corporate laptop is stolen while travelling.
First security action after ensuring personal safety?
Report the loss promptly according to organisational procedure.
An employee believes their hotel-room laptop may have been tampered with.
Best response?
Report suspected compromise and follow organisational handling procedures.
Two employees discuss confidential merger details in an airport lounge.
Primary risk?
Information disclosure through overheard conversation.
Employee wears a corporate access badge publicly throughout their journey.
Primary concern?
Unnecessary disclosure of identity, role and organisational affiliation.
Employee posts live details of a sensitive business trip on social media.
Which 7.15 concerns overlap?
Travel and social-media security.
Public social profile reveals employee's manager, supplier and current project.
How can an attacker use this?
To create more convincing targeted social engineering.
An employee publicly posts a detailed image of their security badge.
Primary concern?
Exposure of physical-security and identity information.
User receives an MFA approval request without attempting to log in.
Best action?
Do not approve it and report the unexpected authentication attempt.
User receives dozens of authentication prompts and eventually approves one to make them stop.
Which attack?
MFA / 2FA fatigue or push bombing.
What organisational control can reduce simple push-approval attacks?
Examples?
Phishing-resistant MFA or stronger mechanisms such as number matching where appropriate.
Repeated unexpected MFA prompts occur.
What might this indicate?
An attacker may already possess the user's primary credential.
An employee downloads an unusually large amount of information.
Does this prove insider theft?
No. It is an indicator requiring context and investigation.
Insider-threat awareness causes staff to accuse colleagues based only on personal characteristics.
Primary problem?
Security should focus on relevant behaviour and evidence, not unsupported assumptions.
Employees are trained to identify suspicious behaviour but do not know how to report it.
Primary weakness?
No usable reporting path.
Building fire alarm activates.
What should personnel generally follow?
The established emergency procedure and evacuation instructions.
Employees evacuate but nobody knows whether visitors remain inside.
Which capability is weak?
Personnel accountability / visitor management.
An external hazard makes leaving the building more dangerous than remaining inside.
Must evacuation always occur?
No. The appropriate emergency procedure may require sheltering or another protective action.
Fire alarm generates frequent false alerts and staff begin ignoring it.
Primary risk?
Complacency / alarm fatigue affecting emergency response.
A mobility-impaired employee cannot use the normal evacuation route.
What should planning address?
Appropriate accessible emergency arrangements.
Employee works alone at a remote site.
Useful personnel-safety control?
Check-in, emergency communications or an appropriate lone-worker alarm system.
A lone worker misses a required check-in and cannot be contacted.
What should happen?
Follow the predefined escalation procedure.
An employee is threatened and cannot safely make an obvious call for help.
Which concept?
Duress.
A silent alarm allows a threatened receptionist to discreetly request assistance.
Which control?
Duress / panic alarm.
A panic button is installed but nobody monitors the alert.
Primary lesson?
Detection without response is incomplete.
Employees have duress alarms but have never been told when or how to use them.
Primary weakness?
Insufficient training and awareness.
A threatening visitor tries to force entry and an employee decides to physically stop them.
Best CISSP mindset?
Personnel should prioritise safety and follow established security/emergency procedures rather than create unnecessary personal danger.
An unfamiliar person repeatedly tries restricted doors.
Appropriate employee behaviour?
Report the concern through the appropriate security process.
A cyberattack disables electronic building access.
What else should responders consider besides server restoration?
Personnel safety, emergency egress and physical-access implications.
Corporate email is unavailable during an emergency.
What should exist?
An appropriate alternate emergency communication method.
An emergency contact list contains phone numbers belonging to former employees.
Primary problem?
Emergency information was not maintained.
A duress alarm works technically, but responders take 40 minutes because no response procedure exists.
Primary lesson?
Control effectiveness includes operational response, not only technical activation.
A worker survives a safety incident despite the emergency system failing.
Should the event still be reviewed?
Yes. Near misses can reveal serious weaknesses.
An executive receives much more targeted social engineering than ordinary employees.
What principle applies?
Personnel security should be risk-based and role-appropriate.
A security-awareness programme uses identical generic content for every employee.
Potential improvement?
Add role-specific and risk-specific training.
Employees can describe the evacuation procedure but have never practised it.
What would strengthen assurance?
An appropriate drill or exercise.
A traveller's device is compromised but no process exists for post-travel assessment.
Which lifecycle phase is weak?
Return / post-travel security handling.
Management asks what the current 7.15 awareness examples are.
Answer?
Insider threat, social-media impacts and 2FA fatigue.
Management asks what four areas make up 7.15.
Answer?
Travel, security training and awareness, emergency management and duress.
Management asks for the central principle of personnel safety and security.
Best answer?
Protect people first, prepare them for the risks associated with their roles and travel, teach them how to recognise and report security concerns, maintain effective emergency procedures and provide reliable ways to obtain assistance when they are under threat or duress.
Recognise the Clue Words
Immediate Danger
Highest priority.
Personnel SafetyTravelling Employee
Official topic.
Travel SecurityOnly Necessary Data
Travel exposure.
MinimiseHigher-Risk Journey
Prepare first.
Travel Risk AssessmentUntrusted Hotel Network
Connectivity.
Approved Secure AccessLost Laptop
After personal safety.
Report PromptlyHotel Device Tampering
Potential compromise.
Report / AssessEmployee Collecting Unusual Data
Trusted access.
Insider RiskSuspicious Behaviour
Not proof.
Report + InvestigateLinkedIn Reveals Project
Attack preparation.
Social-Media ExposureRepeated MFA Prompts
Official example.
MFA FatigueUnexpected MFA Prompt
User action.
Deny + ReportStrongest MFA Direction
Technical mitigation.
Phishing-Resistant MFAFire Alarm
Safety.
Emergency ManagementAssembly Point
Who is safe?
Personnel AccountabilityWorker Cannot Evacuate Normally
Inclusive planning.
AccessibilityWorker Alone
Safety.
Check-In / Personal AlarmThreatened Person
Official topic.
DuressSilent Panic Button
Request help.
Duress AlarmAlarm With Nobody Monitoring
Incomplete control.
No Effective ResponseEmployee Wants to Confront Threat
CISSP priority.
Protect the PersonFalse Emergency Alarms
Behaviour.
Complacency / Alarm FatiguePlan Known but Never Practised
Readiness.
ExerciseNo Injury but Control Failed
Learning.
Near Miss⚠️ Common CISSP Mistakes People come before systems
Protect people first.
Equipment should not take priority over personal safety.
Different physical, technical and legal risks may apply.
Minimise devices, information and privileges where appropriate.
Physical protection remains important.
Follow approved secure-connectivity procedures.
Report and allow appropriate organisational response.
Public posts can expose organisational information and enable targeting.
Physical-access information may be exposed.
Investigate relevant indicators and behaviour.
Validate context before drawing conclusions.
Train personnel to recognise and report relevant risk, not make unsupported accusations.
Some mechanisms remain vulnerable to social-engineering techniques.
It may indicate attempted account compromise.
Deny unexpected attempts and report them.
Stronger authentication design can reduce the underlying opportunity.
Follow the emergency action appropriate to the situation.
Personnel accountability may still be required.
Visitors and contractors may also need accounting.
Personnel need to understand their responsibilities.
Exercises can reveal problems that classroom instruction does not.
It must be monitored and connected to an effective response.
Someone must receive, understand and act on it.
Communication and assistance arrangements may need additional controls.
Follow established security procedures and prioritise personal safety.
Near misses can expose serious weaknesses.
Domain 1.8 addresses personnel-security policies and lifecycle. Domain 7.15 addresses operational personnel safety and security.
Quick Reference
| If you see... | Think... |
|---|---|
| Threat to human life | People First |
| International employee journey | Travel Security |
| Destination risk | Pre-Travel Assessment |
| Unnecessary information on travel device | Data Minimisation |
| Higher-risk journey | Restricted / Managed Travel Capability |
| Untrusted network | Approved Secure Connectivity |
| Lost travel device | Report Promptly |
| Suspected hotel-device tampering | Potential Compromise |
| Public information used for targeted attack | Social-Media Exposure |
| Trusted employee behaving unusually | Insider Risk |
| Suspicious activity without proof | Investigate Context |
| Repeated MFA prompts | MFA Fatigue / Push Bombing |
| Unexpected MFA prompt | Deny + Report |
| Reduce push-fatigue weakness | Phishing-Resistant MFA / Stronger MFA |
| Fire / major safety event | Emergency Management |
| Who is safe after evacuation? | Personnel Accountability |
| Alternative to evacuation | Shelter / Appropriate Protective Action |
| Worker alone | Lone-Worker Controls |
| Threat / coercion | Duress |
| Silent request for assistance | Duress / Panic Alarm |
| Alarm has no responder | Incomplete Control |
| Practice emergency procedure | Drill / Exercise |
| Incident where nobody was hurt | Near Miss |
| Screening / onboarding / termination | Domain 1.8 |
| Travel / emergency / duress | Domain 7.15 |
Official 7.15 Memory Aid
Travel Memory Aid
MFA Fatigue Memory Aid
Emergency Memory Aid
Duress Memory Aid
7.15 Master Memory Aid
Prepare → Recognise → Protect → Report → Respond
The Personnel Security Leader's Questions
Key Takeaways
CISSP 7.15 is officially: Address personnel safety and security concerns.
The current CISSP outline explicitly identifies four areas: travel, security training and awareness, emergency management and duress.
Security exists to protect people as well as information and technology.
During an immediate threat to human safety: people come first.
An employee should not remain inside a dangerous facility merely to protect a server, application or dataset.
Human life > equipment > data availability.
Personnel safety and personnel security overlap but are not identical.
Safety addresses hazards and injury. Security also addresses intentional threats such as coercion, violence, targeted social engineering and insider activity.
Personnel protection should be risk-based.
A travelling executive, lone engineer and ordinary office worker may need different controls.
Travel moves personnel away from many normal organisational safeguards.
Travel planning should therefore consider the destination, activity, employee profile, technology, information and available support.
Travel security begins before departure.
Personnel travelling to higher-risk environments may require additional preparation and more restrictive technology arrangements.
A core travel principle is minimisation.
Personnel should carry only the information, devices and access required for the trip where practical.
What does not travel cannot be lost from the travel device.
Organisations may use appropriately prepared travel devices containing limited data and access.
Devices should be appropriately patched, encrypted, authenticated and managed.
Travellers should maintain appropriate physical control of their devices.
Encryption reduces data exposure but does not eliminate the operational consequences of a lost laptop.
Networks outside organisational control should be treated as untrusted.
Employees should follow organisational policy for approved secure remote connectivity.
Unknown USB devices, charging connections and wireless peripherals can introduce additional technical risk.
Personnel should avoid exposing sensitive information through public conversations, unattended documents or visible screens.
A confidential conversation in an airport lounge can disclose information just as effectively as an email sent to the wrong person.
Personnel should also avoid unnecessarily advertising security badges, organisational access or sensitive business affiliation while travelling.
Lost or stolen equipment should be reported quickly.
Employees should not put themselves in danger attempting to personally retrieve equipment.
Person first. Device incident second.
Suspected physical tampering with travelling devices should be treated as a potential security concern.
Travel plans may also need to account for different legal and cultural environments.
Organisational policy does not override the laws of the jurisdiction in which the traveller is operating.
Travel programmes should provide usable emergency contact and escalation mechanisms.
The current ISC2 objective specifically mentions insider threat as part of security awareness.
Insider risk can arise when trusted organisational access is intentionally misused, negligently handled or compromised by another party.
Insider-threat awareness should not create an environment where everyone automatically suspects everyone else.
Security decisions should be based on relevant behaviour, events, evidence and context.
Indicator ≠ proof.
Personnel should know how to report suspicious activity safely and appropriately.
Awareness without a usable reporting mechanism is incomplete.
Social-media impact is another explicit CISSP 7.15 awareness topic.
Public information about employees, projects, suppliers, travel, roles and reporting lines can help attackers construct convincing social engineering.
Small individual pieces of information can become valuable when combined.
Social-media exposure can create physical-security risk as well as cybersecurity risk.
Publicly advertising travel, home location or a detailed corporate badge may reveal information useful to a malicious actor.
The current CISSP outline also explicitly includes two-factor authentication fatigue.
MFA fatigue occurs when an attacker repeatedly triggers authentication requests hoping the legitimate user will eventually approve one.
Repeated unexpected MFA prompts should be treated as a potential security signal.
If you did not initiate the login, do not approve the authentication request merely to make the prompts disappear.
Personnel should deny and report unexpected authentication attempts using established organisational procedures.
Training is only one layer of protection against MFA-fatigue attacks.
Organisations can also implement stronger authentication mechanisms.
CISA recommends movement toward phishing-resistant MFA and identifies number matching as a stronger alternative to simple push approval where phishing-resistant authentication cannot yet be deployed.
User awareness + stronger authentication = better defence.
Emergency management is the third official 7.15 area.
Personnel should know how emergencies are reported, how alarms are communicated, what protective action is required and how people will be accounted for.
Emergency plans may address fire, medical emergencies, hazardous conditions, natural hazards, infrastructure failures and security events.
Evacuation is an important emergency response but is not necessarily the correct response to every hazard.
Some situations may require personnel to remain or shelter in an appropriate safe location.
Personnel should follow the established emergency procedure relevant to the threat.
Emergency plans should include routes, alarms, responsibilities, communications and personnel accountability.
Visitors and contractors matter too.
Knowing that employees evacuated is insufficient if the organisation cannot determine whether visitors remain inside.
Accessibility should be included in emergency planning.
Personnel who cannot use the normal evacuation route may require appropriate alternative arrangements.
Emergency plans should be trained and practised.
Plan written ≠ people prepared.
Drills and exercises can reveal confusing instructions, blocked routes, communication problems and other weaknesses before a genuine emergency.
Repeated false alarms can create complacency and weaken emergency response.
Alarm systems should therefore be maintained and personnel should understand what the alarms mean.
Lone and remote workers may require additional arrangements because immediate assistance may not be nearby.
Check-in procedures, emergency communication and personal-safety devices may form part of this protection.
A missed check-in can itself trigger an escalation procedure.
Duress is the final explicit CISSP 7.15 area.
Duress concerns situations where personnel are threatened, coerced or otherwise unable to communicate freely.
Appropriate controls may include panic alarms, personal alarms, monitored check-in systems and other predefined methods of requesting assistance.
In some environments the signal may need to be discreet because an obvious request for help could increase the danger to the person.
Duress = request assistance when normal communication may not be safe.
A duress alarm alone is not sufficient.
Someone needs to receive the signal and understand how to respond.
Alarm + monitoring + response = usable duress capability.
Personnel also need training on when and how the duress mechanism should be used.
Duress systems should be tested appropriately so that organisations know the signal reaches the intended responder.
Personnel should not be expected to physically confront threatening individuals when doing so would create unnecessary personal danger.
Employees should follow established security and emergency procedures and obtain assistance where appropriate.
Cybersecurity incidents can also affect personnel safety.
A cyberattack against building access, communications, industrial systems or safety technology may create physical consequences.
Security operations should therefore consider: what does this technical incident mean for people?
Security training should be role-specific where appropriate.
A receptionist facing public interaction, a privileged administrator, a lone engineer and an international traveller may need different preparation.
Personnel-safety incidents and near misses should be reviewed.
The fact that nobody was injured does not prove that a safety control functioned correctly.
No injury ≠ no problem.
Lessons should feed into improved procedures, technology and training.
Domain 1.8 and 7.15 should not be confused.
Domain 1.8 addresses personnel-security policies such as screening, onboarding, transfers, termination and contractor arrangements.
Domain 7.15 addresses operational concerns affecting the safety and security of personnel.
The four official topics can be remembered simply as:
TRAVEL → AWARENESS → EMERGENCY → DURESS
The central CISSP principle is:
understand the risks personnel face, prepare them before exposure, minimise unnecessary information and access, teach them to recognise and report suspicious activity, protect human life before technology, maintain effective emergency procedures and ensure people have a reliable way to obtain help when they are threatened or under duress.
📚 Sources & Further Reading Personnel safety, travel, awareness, emergency and duress references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - CISA - More Than a Password
View CISA MFA guidance - CISA - Insider Threat Mitigation Resources and Tools
View CISA insider-threat resources - CISA - HR's Role in Preventing Insider Threats
View CISA insider-risk guidance - UK NCSC - Research and Innovation Security Resources
View NCSC and NPSA travel-security resources - UK NCSC - Device Security Guidance
View NCSC device-security guidance - UK NCSC - Spotting Cyber Attacks
View NCSC social-media and attack-awareness guidance - UK NPSA - Personal Safety: Calling for Help
View NPSA personal-safety guidance - UK HSE - Emergency Procedures
View workplace emergency guidance - UK HSE - Preventing Violence and Aggression at Work
View workplace personal-safety guidance - OSHA - Emergency Action Plans
View emergency-action planning guidance - NIST SP 800-53 Rev. 5 - Security and Privacy Controls
View NIST SP 800-53
