Personnel Screening PS-3
Personnel Security · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PS-3 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Personnel Security family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PS-3 (Personnel Screening) is about checking a person before you hand them access, and rescreening them when circumstances call for it. The depth of the check follows the role's risk designation from PS-2 (Position Risk Designation). It is a Personnel Security control required at the Low baseline.
What good looks like
- Screen the person before you authorize access, not after.
- Match the depth of the check to the role's risk designation from PS-2.
- Record that the screening happened and was approved — keep the evidence.
- Rescreen on defined conditions (for example, a move into a higher-risk role) and at a set frequency.
Framework mapping
How to move it toward Implemented
- Write a screening standard that says what check each role needs before access is granted, tied to the risk levels from PS-2.
- Keep a dated screening record for each person — who was screened, what check was done, who approved — and require it before the account is created (before you run
useradd). - Define the rescreening triggers and frequency (for example, when someone moves into a higher-risk role) so access stays earned, not just granted once.
- Save the screening log as a dated file and attach it as hardening evidence on the asset, naming
PS-3in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.