ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Personnel Security Audit Checklist

Personnel Security Audit Checklist

1. Purpose

The Personnel Security Audit Checklist provides a structured method for reviewing whether personnel-security controls are defined, implemented, operating effectively, and supported by evidence.

The checklist covers the personnel lifecycle:

Define → Screen → Onboard → Train → Authorize → Monitor → Change → Reassess → Offboard → Verify

It can be used for:

  • Internal audits
  • Security reviews
  • ISO 27001 readiness assessments
  • Periodic personnel-security reviews
  • Compliance assessments
  • Supplier/contractor reviews
  • Investigation follow-up
  • Management reviews
  • Control-effectiveness testing

2. Scope

The checklist may cover:

☐ Employees
☐ Contractors
☐ Consultants
☐ Interns
☐ Temporary workers
☐ Remote workers
☐ Third-party personnel
☐ Privileged users
☐ Developers
☐ Cloud administrators
☐ Security personnel
☐ Personnel handling customer information
☐ Personnel handling personal data
☐ Other: ______________________


3. Audit Information

FieldDetails
Audit ID
Assessment Date
Audit Period
Auditor
Business Owner
HR Owner
Security Owner
Scope
Locations
Departments
Sample Size
Previous Audit
Overall Result

4. Audit Objectives

Determine whether:

☐ Personnel-security requirements are defined
☐ Responsibilities are assigned
☐ Screening is risk-based and appropriate
☐ Employment security requirements are documented
☐ Confidentiality requirements are established
☐ Security responsibilities are communicated
☐ Security awareness is provided
☐ Access is appropriately provisioned
☐ Access changes are managed
☐ Privileged access is controlled
☐ Personnel security requirements apply to contractors
☐ Security responsibilities continue during employment
☐ Security incidents are reported
☐ Violations are managed appropriately
☐ Offboarding is effective
☐ Evidence is maintained
☐ Controls operate effectively


5. Audit Methodology

Use a combination of:

☐ Document review
☐ Personnel-record sampling
☐ HR interviews
☐ Manager interviews
☐ Employee interviews
☐ Access-record review
☐ Training-record review
☐ Screening-record review
☐ System testing
☐ Observation
☐ Sample-based testing
☐ Evidence verification

Important

The auditor should avoid reviewing unnecessary sensitive HR information. Evidence should be limited to what is required to establish control effectiveness.


6. Personnel Security Governance

Verify:

☐ Personnel-security policy exists
☐ Policy is approved
☐ Policy owner is identified
☐ Roles and responsibilities are defined
☐ HR responsibilities are defined
☐ Information Security responsibilities are defined
☐ Manager responsibilities are defined
☐ Employee responsibilities are defined
☐ Contractor responsibilities are defined
☐ Legal/privacy responsibilities are defined where applicable
☐ Policy review frequency is defined
☐ Policy changes are controlled

Evidence

Result

☐ Compliant
☐ Partially Compliant
☐ Non-Compliant
☐ Not Applicable


7. Personnel Security Risk Assessment

Verify that personnel-security risks are identified.

☐ Sensitive roles identified
☐ Privileged roles identified
☐ Production-access roles identified
☐ Customer-data roles identified
☐ Personal-data roles identified
☐ Security roles identified
☐ Financially sensitive roles identified
☐ High-risk roles identified
☐ Contractor risks considered
☐ Remote-working risks considered
☐ Key-person risks considered

Evidence


8. Role Definition

Verify:

☐ Job descriptions exist
☐ Security responsibilities are included where appropriate
☐ Access requirements are defined
☐ Information responsibilities are defined
☐ Privileged responsibilities are defined
☐ Segregation-of-duties requirements are considered
☐ Security-sensitive roles are identified

Sample Tested

Employee/RoleJob DescriptionSecurity ResponsibilitiesAccess Defined

9. Sensitive Role Identification

Verify that the organization identifies roles requiring enhanced security controls.

Examples:

  • System administrators
  • Cloud administrators
  • Database administrators
  • Security personnel
  • Developers with production access
  • Finance personnel
  • HR personnel
  • Personnel handling restricted information
  • Personnel with privileged access

☐ Sensitive roles documented
☐ Criteria defined
☐ Risk assessment performed
☐ Enhanced controls identified
☐ Screening requirements defined
☐ Training requirements defined
☐ Access controls defined


10. Employee Screening

Verify:

☐ Screening requirements are defined
☐ Screening is risk-based
☐ Appropriate authorization obtained
☐ Applicable legal requirements considered
☐ Identity verified where appropriate
☐ Employment history checked where appropriate
☐ Role-specific checks performed where justified
☐ Screening evidence is protected
☐ Exceptions are documented
☐ Screening results are reviewed appropriately

Sample Testing

EmployeeRoleScreening RequiredCompletedEvidenceException

Sensitive personal information should not be copied unnecessarily into the audit working papers.


11. Contractor Screening

Verify:

☐ Contractor screening requirements defined
☐ Contractor role risk assessed
☐ Screening responsibility assigned
☐ Supplier screening evidence reviewed where applicable
☐ Confidentiality requirements established
☐ Security responsibilities defined
☐ Access requirements defined
☐ Offboarding requirements defined


12. Employment Terms

Verify that applicable employment agreements or engagement terms address:

☐ Information-security responsibilities
☐ Confidentiality
☐ Acceptable use
☐ Intellectual property
☐ Data protection
☐ Security incident reporting
☐ Compliance with organizational policies
☐ Return of organizational assets
☐ Post-employment confidentiality where applicable

Legal review should be obtained where appropriate.


13. Confidentiality

Verify:

☐ Confidentiality requirements defined
☐ NDA/confidentiality agreement used where appropriate
☐ Employees acknowledge confidentiality obligations
☐ Contractors are covered
☐ Third-party personnel are covered
☐ Confidential information handling is explained
☐ Obligations continue after termination where applicable
☐ Confidentiality records are protected


14. Employee Security Responsibilities

Verify employees understand:

☐ Their security responsibilities
☐ Access restrictions
☐ Information-handling requirements
☐ Incident-reporting requirements
☐ Acceptable-use requirements
☐ Password/MFA requirements
☐ Confidentiality obligations
☐ Security policies
☐ Consequences of serious violations

Evidence


15. Security Awareness

Verify:

☐ New employees receive security awareness training
☐ Annual training is provided
☐ Role-based training is provided where required
☐ Phishing awareness is addressed
☐ Password/MFA security is addressed
☐ Information classification is addressed
☐ Privacy is addressed
☐ Incident reporting is addressed
☐ Remote-working security is addressed
☐ AI security is addressed where relevant
☐ Training completion is tracked
☐ Overdue training is followed up


16. Training Effectiveness

Do not rely only on training completion.

Verify whether the organization evaluates:

☐ Knowledge
☐ Understanding
☐ Practical behavior
☐ Phishing response
☐ Incident-reporting behavior
☐ Policy compliance
☐ Security incidents linked to awareness gaps
☐ Recurring training-related violations

Evidence


17. Employee Onboarding

Verify that new employees receive security onboarding.

☐ Identity verified
☐ Role defined
☐ Security responsibilities communicated
☐ Confidentiality requirements completed
☐ Required screening completed
☐ Security training assigned
☐ Policies communicated
☐ Access approved
☐ MFA configured
☐ Device issued securely
☐ Security tools configured
☐ Access validated
☐ Evidence recorded

Sample

EmployeeStart DateTrainingScreeningAccess ApprovalMFAComplete

18. Access Provisioning

Verify:

☐ Access request exists
☐ Business need documented
☐ Manager approval obtained
☐ System owner approval obtained where required
☐ Access matches job role
☐ Least privilege applied
☐ MFA enabled where required
☐ Privileged access separately controlled
☐ Access provisioning is recorded
☐ Access is validated after provisioning


19. Joiner-Mover-Leaver Process

Verify that personnel changes trigger access review.

Joiner

☐ Identity created
☐ Appropriate access granted
☐ Training assigned
☐ MFA configured

Mover

☐ Role change identified
☐ Existing access reviewed
☐ Unnecessary access removed
☐ New access approved
☐ Responsibilities updated

Leaver

☐ Termination communicated
☐ Access revoked
☐ Privileged access revoked
☐ VPN access removed
☐ Cloud access removed
☐ SaaS access removed
☐ Physical access removed
☐ Assets returned


20. Role Changes

Test whether access changes when personnel responsibilities change.

☐ Role change documented
☐ New risk assessed
☐ Existing access reviewed
☐ Unnecessary access removed
☐ New access approved
☐ Privileged access reassessed
☐ Production access reassessed
☐ Security responsibilities updated
☐ Training updated where required

Sample

EmployeeOld RoleNew RoleAccess ReviewedExcess Access Removed

21. Privileged Users

Verify:

☐ Privileged users identified
☐ Business justification exists
☐ Named accounts used
☐ Shared privileged accounts avoided
☐ MFA enabled
☐ Privileged access approved
☐ Access limited to required systems
☐ Administrative actions logged where appropriate
☐ Periodic review performed
☐ Access removed when no longer required


22. Production Access

Verify:

☐ Production users identified
☐ Production access approved
☐ Access is role-based
☐ Access is least privilege
☐ MFA enabled
☐ Access reviewed periodically
☐ Production data access is controlled
☐ Emergency access is controlled
☐ Production activity is logged where appropriate


23. Cloud Access

For AWS or other cloud environments:

☐ Cloud administrators identified
☐ IAM roles reviewed
☐ Individual identities used
☐ MFA enabled
☐ Privileged roles restricted
☐ Root-account access restricted
☐ Access keys controlled
☐ Temporary access used where practical
☐ Cloud access reviewed
☐ Departed personnel removed


24. Source-Code Access

For software organizations:

☐ Repository access approved
☐ Individual accounts used
☐ MFA enabled
☐ Access matches role
☐ Privileged repository access restricted
☐ Former employees removed
☐ Contractors reviewed
☐ Sensitive repositories separately controlled
☐ Repository access periodically reviewed


25. Security Responsibilities by Role

Verify that personnel with security-sensitive responsibilities understand their roles.

Examples:

☐ Developers
☐ DevOps
☐ Cloud administrators
☐ Security team
☐ Database administrators
☐ IT administrators
☐ Incident responders
☐ Internal auditors
☐ Privacy personnel
☐ System owners

Evidence


26. Acceptable Use

Verify employees understand acceptable-use requirements for:

☐ Company devices
☐ Email
☐ Internet
☐ Cloud services
☐ SaaS applications
☐ Software
☐ AI tools
☐ Removable media
☐ Company networks
☐ Business information


27. Remote Working

Verify:

☐ Remote-working policy exists
☐ Employees receive guidance
☐ Approved devices are used
☐ MFA is enabled
☐ Secure remote access is provided
☐ Sensitive information is protected
☐ Physical privacy is considered
☐ Lost devices are reported
☐ Public Wi-Fi risks are addressed


28. Mobile Devices

Verify:

☐ Mobile devices are identified
☐ Device security requirements exist
☐ Screen locking is enabled
☐ Encryption is used where appropriate
☐ Security updates are applied
☐ Organizational data is protected
☐ Lost devices are reported
☐ Remote-wipe capability exists where appropriate


29. Security Incident Reporting

Verify employees know how to report:

☐ Phishing
☐ Malware
☐ Lost devices
☐ Credential compromise
☐ Unauthorized access
☐ Data disclosure
☐ Security weaknesses
☐ Suspicious activity
☐ Privacy incidents

Testing

Ask sampled employees:

“If you accidentally send customer information to the wrong person, what would you do?”

Result


30. Security Policy Violations

Verify:

☐ Policy violations can be reported
☐ Violations are recorded where appropriate
☐ Investigation process exists
☐ Severity classification exists
☐ Evidence is preserved
☐ Corrective action is tracked
☐ HR/legal involvement occurs where appropriate
☐ Repeated violations are monitored
☐ Employees are treated consistently


31. Disciplinary Process

Verify:

☐ Disciplinary policy exists
☐ Security violations are handled through defined processes
☐ Intent is considered appropriately
☐ Impact is considered
☐ Evidence supports decisions
☐ HR involvement is defined
☐ Legal requirements are considered
☐ Confidentiality is maintained
☐ Non-retaliation for good-faith reporting is supported


32. Contractor and Third-Party Personnel

Verify:

☐ Third-party personnel are identified
☐ Security responsibilities are defined
☐ Confidentiality requirements exist
☐ Screening is addressed where appropriate
☐ Access is approved
☐ Access is limited
☐ Training/awareness is addressed
☐ Supplier requirements flow down
☐ Access is reviewed
☐ Offboarding is completed


33. Temporary and Intern Personnel

Verify:

☐ Temporary personnel identified
☐ Role risk assessed
☐ Access limited
☐ Confidentiality addressed
☐ Training provided
☐ Manager assigned
☐ Access reviewed
☐ End date recorded
☐ Access removed at end of engagement


34. Security Responsibilities During Employment

Verify that personnel continue to understand security requirements after onboarding.

☐ Annual awareness
☐ Policy updates
☐ Role-based training
☐ Security communications
☐ Phishing campaigns
☐ Incident lessons learned
☐ New technology guidance
☐ AI-security guidance
☐ Refresher training following significant changes


35. Personnel Monitoring

Where monitoring is appropriate and lawful:

☐ Security monitoring requirements defined
☐ Monitoring purpose documented
☐ Appropriate systems monitored
☐ Access logs maintained
☐ Privileged activity monitored where appropriate
☐ Monitoring complies with applicable privacy/employment requirements
☐ Monitoring data is protected
☐ Access to monitoring data is restricted


36. Security Violations and Investigations

Verify that suspected violations are handled consistently.

☐ Report received
☐ Initial assessment completed
☐ Immediate risk assessed
☐ Evidence preserved
☐ Investigation authorized
☐ Investigator appropriately independent
☐ Facts documented
☐ Intent considered
☐ Impact assessed
☐ Root cause considered
☐ Corrective action identified
☐ Closure documented


37. Employee Privacy

Personnel-security processes should protect employee privacy.

Verify:

☐ Personal information minimized
☐ Screening information protected
☐ Investigation records restricted
☐ Access limited to authorized personnel
☐ Retention requirements defined
☐ Sensitive HR information not unnecessarily copied
☐ Applicable privacy requirements considered
☐ Employee monitoring is appropriately governed


38. Personnel Security During Business Disruption

Verify that personnel-security arrangements remain effective during:

☐ Disaster
☐ Major outage
☐ Cyberattack
☐ Remote-working emergency
☐ Office closure
☐ Workforce disruption
☐ Loss of key personnel

Consider:

  • Emergency access
  • Alternate personnel
  • Contact information
  • Privileged access
  • Critical roles
  • Key-person dependency

39. Key-Person Dependency

Identify roles where loss of a person could materially affect security or business continuity.

☐ Critical roles identified
☐ Backup personnel identified
☐ Knowledge transfer performed
☐ Documentation exists
☐ Cross-training performed
☐ Emergency contact information maintained
☐ Succession/continuity arrangements considered


40. Offboarding

Verify:

☐ Termination notice received
☐ Access removal initiated promptly
☐ Accounts disabled
☐ MFA removed
☐ VPN removed
☐ Cloud access removed
☐ Source-code access removed
☐ Database access removed
☐ SaaS access removed
☐ Physical access removed
☐ Assets returned
☐ Confidentiality obligations communicated
☐ Organizational information returned/deleted where required
☐ Exit evidence retained


41. High-Risk Termination

Where appropriate, verify enhanced controls for high-risk departures.

Consider:

☐ Privileged access
☐ Production access
☐ Source-code access
☐ Customer data
☐ Financial information
☐ Security systems
☐ Active sessions
☐ Tokens/API keys
☐ Cloud credentials
☐ Physical access

Enhanced measures should be proportionate, lawful, authorized, and consistent with organizational procedures.


42. Access Revocation Testing

Sample recently departed personnel.

PersonDeparture DateAccount DisabledCloud RevokedSaaS RevokedPhysical Access Removed

Result


43. Asset Return

Verify departing personnel return:

☐ Laptop
☐ Mobile device
☐ Access card
☐ Security token
☐ Storage media
☐ Company documents
☐ Other equipment
☐ Other assets

Evidence


44. Secrets and Credentials During Offboarding

Where necessary:

☐ Passwords reset
☐ API tokens revoked
☐ SSH keys revoked
☐ Cloud credentials removed
☐ Service-account ownership reviewed
☐ Certificates reviewed
☐ Shared secrets rotated where appropriate
☐ Emergency credentials reviewed


45. Personnel Security Exceptions

Verify:

☐ Exceptions are formally recorded
☐ Business justification exists
☐ Risk assessed
☐ Compensating controls identified
☐ Approval obtained
☐ Expiry/review date defined
☐ Exceptions are monitored


46. Personnel Security Findings

Record audit findings.

Finding IDAreaRequirementConditionEvidenceRiskActionOwnerDue Date

47. Evidence Sampling

Recommended sample areas:

☐ New employees
☐ Recent role changes
☐ Recent departures
☐ Privileged users
☐ Production users
☐ Cloud administrators
☐ Developers
☐ Contractors
☐ High-risk roles
☐ Security personnel

Sample Selection Method

Sample Size

Sampling Rationale


48. Interview Questions

HR

  1. How are security-sensitive roles identified?
  2. How is screening determined?
  3. How are employee departures communicated?
  4. How are screening records protected?
  5. How are contractors handled?

Managers

  1. How do you request employee access?
  2. What happens when an employee changes role?
  3. How do you report a security concern?
  4. How do you ensure required training is completed?

Employees

  1. What security responsibilities apply to your role?
  2. How do you report a security incident?
  3. What would you do if your password were compromised?
  4. Can you access customer information? Why?
  5. What security training have you received?

IT/Security

  1. How are accounts provisioned?
  2. How are privileged accounts controlled?
  3. How are departed users removed?
  4. How are access reviews performed?
  5. How are security violations investigated?

49. Control Effectiveness Assessment

For each sampled control, assess:

☐ Designed appropriately
☐ Implemented
☐ Operating
☐ Evidence available
☐ Consistently applied
☐ Risk appropriately addressed

Overall Effectiveness

☐ Effective
☐ Partially Effective
☐ Ineffective

Rationale


50. Corrective Actions

For identified weaknesses:

Action IDFindingRoot CauseCorrective ActionOwnerDue DateStatusVerification

Corrective actions should address underlying causes where appropriate, rather than only correcting individual records.


51. Personnel Security Risk Assessment

Summarize identified risks.

Risk IDRiskLikelihoodImpactRatingTreatmentOwner

52. Audit Summary

AreaResultFindingsRisk
Governance
Screening
Employment Security
Awareness
Onboarding
Access
Privileged Access
Contractors
Role Changes
Incident Reporting
Violations
Offboarding
Privacy
Overall

53. Overall Assessment

☐ Effective
☐ Generally Effective – Minor Improvements Required
☐ Partially Effective – Improvement Required
☐ Ineffective – Significant Improvement Required
☐ Critical Issues Identified

Overall Conclusion


54. Management Response

Management Comments

Resource Requirements

Agreed Actions


55. Review Frequency

The personnel-security audit frequency should be based on:

  • Risk
  • Organization size
  • Workforce changes
  • Privileged-access exposure
  • Customer requirements
  • Regulatory requirements
  • Previous findings
  • Security incidents
  • Significant organizational changes

Additional reviews may be triggered by:

☐ Major security incident
☐ Data breach
☐ Significant employee turnover
☐ New privileged-access environment
☐ Major acquisition
☐ New regulatory requirement
☐ Major HR/system change
☐ Repeated security violations
☐ Significant audit findings


56. AWS SaaS Startup Example

Scenario

An AWS SaaS startup has:

  • 25 employees
  • 4 developers
  • 2 DevOps engineers
  • 1 cloud administrator
  • Remote workforce
  • GitHub source code
  • AWS production environment
  • Customer data

Audit Testing

Sample:

  • 5 employees
  • 2 developers
  • 2 privileged users
  • 1 recent joiner
  • 1 recent role change
  • 1 recent leaver
  • 1 contractor

Test Results

Verify:

  • MFA enabled
  • AWS IAM access approved
  • GitHub access appropriate
  • Production access restricted
  • Security training completed
  • Confidentiality agreements completed
  • Screening completed where required
  • Leaver access removed
  • Role-change access updated

Example Finding

Finding: Former contractor’s GitHub access remained active for two days after contract termination.

Risk: Unauthorized access to source code.

Root Cause: Contractor termination was communicated to HR but not automatically connected to the access-revocation workflow.

Corrective Action:

Implement a formal contractor offboarding workflow linking HR/supplier termination notification to IT and application access revocation.

Verification:

Test the next contractor termination and verify that GitHub, AWS, SaaS, VPN, and other applicable access are removed within the defined timeframe.


57. Startup-Friendly Personnel Security Audit

A small startup does not need a complex HR audit program.

Focus first on:

People

Who has access?

Roles

What should each person be able to access?

Screening

Are high-risk roles appropriately checked?

Training

Do people understand security responsibilities?

Access

Does access match the role?

Changes

Is access updated when roles change?

Offboarding

Is access removed promptly?

Evidence

Can the startup prove these activities occurred?

A small organization can manage much of this using:

  • HR records
  • Access-management records
  • Training register
  • Joiner-Mover-Leaver checklist
  • Personnel-security register
  • Security violation register
  • Offboarding checklist

58. Common Mistakes

Avoid:

  • Treating personnel security as only an HR responsibility.
  • Giving employees access before approval.
  • Failing to identify sensitive roles.
  • Performing the same screening for every role without considering risk.
  • Keeping excessive sensitive screening information.
  • Failing to review access after role changes.
  • Allowing former employees to retain access.
  • Ignoring contractor access.
  • Assuming training completion means training effectiveness.
  • Failing to test actual access.
  • Not reviewing privileged users.
  • Ignoring cloud and source-code access.
  • Failing to investigate repeated security violations.
  • Mixing disciplinary decisions with security investigations without proper HR/legal involvement.
  • Failing to maintain evidence.

59. Relationship With Other ISMS Documents

DocumentRelationship
Human Resources Security PolicyDefines personnel-security requirements
Employee Screening PolicyDefines screening principles
Background Verification ProcedurePerforms screening
Role-Based Screening MatrixDetermines screening by role risk
Employee Onboarding ChecklistControls secure onboarding
Joiner-Mover-Leaver ProcedureManages personnel lifecycle
Access Management ProcedureControls access
Role-Based Security Responsibilities MatrixDefines security responsibilities
Security Awareness PolicyDefines awareness requirements
Security Training ProcedureManages security training
Security Policy Acknowledgement RegisterRecords acknowledgement
Employee Security Conduct GuidelinesDefines expected behavior
Security Policy Violation RegisterTracks violations
Security Violation Investigation ProcedureInvestigates violations
Disciplinary ProcessManages disciplinary matters
Employee Offboarding ProcedureControls secure exit
Asset Return ProcedureRecovers organizational assets
Personnel Security Risk AssessmentEvaluates personnel-related risk
Corrective Action TrackerTracks remediation

60. ISO 27001 Connection

Personnel security is an important component of an organization’s information-security management system because employees, contractors, and other personnel may have access to organizational information, systems, facilities, and security-sensitive processes.

This checklist itself is not a universally mandatory ISO/IEC 27001 form. The organization should determine the appropriate personnel-security controls, review frequency, sampling, evidence, and records based on:

  • ISMS scope
  • Risk assessment
  • Roles and responsibilities
  • Information handled
  • System access
  • Applicable Annex A controls
  • Legal and regulatory requirements
  • Customer requirements
  • Contractual obligations
  • Previous findings
  • Security incidents

The audit should verify both control design and actual operation.


61. Final Audit Checklist

Before completing the personnel-security audit:

☐ Scope defined
☐ Audit criteria defined
☐ Personnel-security policy reviewed
☐ Roles and responsibilities reviewed
☐ Sensitive roles identified
☐ Screening reviewed
☐ Contractor screening reviewed
☐ Confidentiality reviewed
☐ Employee responsibilities reviewed
☐ Security awareness reviewed
☐ Training effectiveness reviewed
☐ New employee onboarding tested
☐ Access provisioning tested
☐ Joiner-Mover-Leaver process tested
☐ Role changes tested
☐ Privileged access tested
☐ Production access tested
☐ Cloud access tested
☐ Source-code access tested
☐ Remote-working controls reviewed
☐ Incident reporting tested
☐ Security violations reviewed
☐ Disciplinary process reviewed where applicable
☐ Contractor controls reviewed
☐ Employee privacy considered
☐ Offboarding tested
☐ Access revocation tested
☐ Asset return tested
☐ Credentials/secrets addressed
☐ Exceptions reviewed
☐ Evidence sampled
☐ Findings documented
☐ Risk assessed
☐ Corrective actions assigned
☐ Management response obtained
☐ Conclusion documented
☐ Follow-up date established


62. Final Audit Trail

For personnel security, the organization should be able to demonstrate:

Who works for or on behalf of the organization?
What security responsibilities apply to each role?
Which roles require screening?
Was screening performed appropriately?
Were confidentiality obligations established?
Were employees trained?
Was access properly approved?
Does access match the employee’s current role?
Are privileged users appropriately controlled?
Are contractors controlled?
Are security incidents and violations reported?
What happens when someone changes role?
What happens when someone leaves?
Is access revoked?
Are organizational assets returned?
Is evidence available to demonstrate these controls operate?
Are weaknesses corrected and verified?

Final Principle

Personnel security is effective when the organization can demonstrate that the right people are appropriately screened, informed, trained, authorized, monitored, and offboarded—and that personnel-related security controls actually operate as intended.