Skip to main content

πŸ’Ό GV.RR-04: Cybersecurity is included in human resources practices

Description​

  1. Integrate cybersecurity risk management considerations into human resources processes (e.g., personnel screening, onboarding, change notification, offboarding)
  2. Consider cybersecurity knowledge to be a positive factor in hiring, training, and retention decisions
  3. Conduct background checks prior to onboarding new personnel for sensitive roles, and periodically repeat background checks for personnel with such roles
  4. Define and enforce obligations for personnel to be aware of, adhere to, and uphold security policies as they relate to their roles

Similar​

  • Sections
    • /frameworks/nist-csf-v1.1/pr-ip/11
    • /frameworks/nist-sp-800-53-r5/pm/13
    • /frameworks/nist-sp-800-53-r5/ps/01
    • /frameworks/nist-sp-800-53-r5/ps/07
    • /frameworks/nist-sp-800-53-r5/ps/09

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-11: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening)
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PM-13 Security and Privacy Workforce
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PS-1 Policy and Procedures
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PS-7 External Personnel Security
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό PS-9 Position Descriptions

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags