Organizational Control: Third-party Personnel Security
Control ID: PS-7 Third-party Personnel Security | Family: Personnel Security | Source: NIST 800-53r4 |
Control: The organization:
|
||
Supplemental Guidance: Third-party providers include, for example, service bureaus, contractors, and other organizations providing information system development, information technology services, outsourced applications, and network and security management. Organizations explicitly include personnel security requirements in acquisition-related documents. Third-party providers may have personnel working at organizational facilities with credentials, badges, or information system privileges issued by organizations. Notifications of third-party personnel changes ensure appropriate termination of privileges and credentials. Organizations define the transfers and terminations deemed reportable by security-related characteristics that include, for example, functions, roles, and nature of credentials/privileges associated with individuals transferred or terminated. Related Controls: PS-2, PS-3, PS-4, PS-5, PS-6, SA-9, SA-21 |
||
Control Enhancements: N/A | ||
References: NIST Special Publication 800-35. | ||
Mechanisms: | ||
Protocol Implementation Conformance Statements: N/A |