Policy and Procedures PS-1
Personnel Security · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PS-1 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Personnel Security family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PS-1 (Policy and Procedures) is about putting personnel security in writing: a documented policy that states what the organization expects, procedures that make it actionable, a named official who owns it, and a habit of reviewing and updating both on a schedule and after major changes. It is the foundation of the Personnel Security (PS) family and is required at the Low baseline.
What good looks like
- Write a personnel security policy that covers purpose, scope, roles, responsibilities, management commitment, and compliance — and keep it consistent with applicable laws and regulations.
- Back the policy with procedures — the concrete steps that put it into practice on this system.
- Name an official to own the policy and procedures.
- Disseminate both to the people and roles who have to follow them.
- Review and update the policy and procedures on a set frequency and after major events (a breach, an audit finding, a big system change).
Framework mapping
- NIST CSF 2.0 — GV.PO-01 — Policy for managing cybersecurity risks is established, communicated, and enforced
How to move it toward Implemented
- Draft a one- to two-page personnel security policy that states its purpose and scope, the roles and responsibilities, management commitment, and how it stays consistent with applicable laws and regulations.
- Write the matching procedures — the step-by-step for screening, access agreements, transfers, and offboarding on this server — so the policy is actually followed.
- Name the official who owns the policy and set a review cadence (for example, once a year and after any major change), recorded right in the document.
- Save the signed, dated policy and procedures as a file (for example,
/srv/grc/policies/personnel-security-policy.pdf), then attach it as hardening evidence on the asset, namingPS-1in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.