Position Descriptions PS-9
Personnel Security · Low baseline ✗ Not implemented
Status — program-wide
What references this control
No risks name this control in their Framework field yet.
No policies reference it yet.
Link a risk or policy to this control
Attaching adds PS-9 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.
Source: NIST SP 800-53 Rev.5, Personnel Security family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.
Control guide — plain-English, per NIST SP 800-53
PS-9 (Position Descriptions) is about writing security and privacy responsibilities into the job description itself, so the duties that keep a system safe are part of the role rather than an afterthought. It is a Personnel Security control in the Low baseline, and it is new in NIST (National Institute of Standards and Technology) Special Publication 800-53, Revision 5. When the person who administers this lab server has ‘patching, account reviews, and log monitoring’ written into their position description, those duties survive staff turnover and drive the training that person needs.
What good looks like
- Spell out security and privacy duties in the position description — for example ‘maintains patching, reviews accounts, monitors logs’ — not just ‘administers the server’.
- Make the duties specific to the role so the person, their manager, and Human Resources (HR) all read the same expectations.
- Use the description to drive role-based training — the responsibilities you list are what that person should be trained and evaluated on.
- Cover every role that touches the system, including part-time admins and contractors, so no security duty is left unowned.
- Review the description when the role changes — when duties move to a new system or a new person, update it so it stays true.
Framework mapping
- NIST CSF 2.0 — GV.RR-04 — Cybersecurity is included in human resources practices
How to move it toward Implemented
- Write or update the position description for whoever administers this server, listing the concrete security duties (patching cadence, monthly account review, log monitoring, and incident reporting).
- Cross-check those duties against the controls this asset actually needs — if PS-8 sanctions, AC-2 account management, or audit-log review live on this box, the responsible role should say so.
- Feed the description into a role-based training list — each duty you named becomes something that person is trained on and can be measured against.
- Have Human Resources and the manager sign off so the description is authoritative, and set a review date so it is refreshed when the role or the system changes.
- Attach the updated position description as hardening evidence on the asset, naming
PS-9in the Requirement field — that moves it from ‘To assess’ toward ‘Completed’.