External Personnel Security PS-7
Personnel Security · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PS-7 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Personnel Security family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PS-7 (External Personnel Security) is about holding outside providers — contractors, vendors, and managed service providers — to the same personnel security bar as your own staff. You set the requirements, require providers to follow your policies, require them to tell you when their people transfer or leave, and monitor that they comply. It is a Personnel Security control required at the Low baseline.
What good looks like
- Set personnel security requirements — roles and responsibilities — for external providers and their staff.
- Require providers to follow your personnel security policies and procedures.
- Document the requirements, usually in the contract or a written agreement.
- Require providers to notify you of any transfers or terminations among their people.
- Monitor that providers actually comply.
Framework mapping
- NIST CSF 2.0 — GV.RR-04 — Cybersecurity is included in human resources practices
How to move it toward Implemented
- Add your personnel security requirements to every external provider agreement — the screening, access agreements, and offboarding rules their staff must meet before touching this server.
- Require the provider to notify you when their people transfer or leave (within an agreed timeframe) so you can disable the matching accounts here quickly.
- Monitor compliance — keep a roster of external accounts on the server (for example, from
getent passwd) mapped to the provider responsible, and reconcile it on a schedule. - Save the provider requirements and the reconciliation record as dated files, then attach them as hardening evidence on the asset, naming
PS-7in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.