PS-2: Position Risk Designation

PS-02 requires organizations to assign a risk designation to every position, establish screening criteria that match the risk level, and

Quick-reference card

FieldValue
Control IDPS-02
Control NamePosition Risk Designation
FrameworkNIST SP 800-53 Revision 5
Control FamilyPersonnel Security
BaselinesLOW MODERATE HIGH
RelevanceOrganization (First Party and Third Party)
Risk SeverityMedium

What this control requires

PS-02 requires organizations to assign a risk designation to every position, establish screening criteria that match the risk level, and review those designations on a defined schedule. The control applies across all roles, not just those with system access, because any position can introduce risk to organizational operations depending on its duties and responsibilities.

The foundation of this requirement is the Position Designation System (PDS), which assesses how much damage a role’s incumbent could cause to the efficiency or integrity of services. PDS evaluations also determine whether a position could create a material adverse effect on national security, establishing both risk level and sensitivity level for each role. These two assessments together drive the depth and type of background investigation required before an individual fills that position.

Without position risk designations in place, organizations lack a consistent basis for deciding who gets screened, how thoroughly, and what level of access they should receive. The result is an ad hoc screening process where high-risk roles may receive the same cursory background check as low-risk administrative positions, leaving gaps that auditors and adversaries alike can identify.

Why it matters

Most organizations treat personnel screening as a binary decision: run a background check or don’t. PS-02 exists because that approach fails to account for the spectrum of risk that different roles introduce. A contractor with access to critical infrastructure data poses fundamentally different risks than a receptionist, and the screening process should reflect that difference.

Failure to maintain position risk designations introduces audit risk and may result in certification withdrawal or regulatory findings. Federal agencies that don’t comply with 5 CFR Parts 731 and 1400 face potential enforcement actions from the Office of Personnel Management (OPM). For organizations pursuing or maintaining a NIST-based authorization to operate (ATO), gaps in position categorization can stall the entire assessment process.

The compliance exposure extends beyond federal mandates. Third-party assessors reviewing your security program will check whether position risk designations exist, whether they’re current, and whether screening criteria match the assigned risk levels. Outdated or missing designations signal a systemic weakness in your personnel security program.

What attackers exploit

  • Unscreened high-risk positions where individuals gain privileged access without background investigations proportional to the role’s sensitivity level
  • Stale designations that haven’t been updated to reflect changes in duties, allowing personnel to retain access levels that exceed their current responsibilities
  • Inconsistent screening criteria across departments, creating gaps where insider threats can operate in roles that bypass organizational security controls
  • Missing designation reviews that fail to catch positions reclassified by organizational restructuring, mergers, or mission changes

How to implement

For your organization

The primary challenge with PS-02 isn’t creating initial designations but maintaining them as roles evolve. Organizations that treat position risk designation as a one-time exercise during onboarding consistently fail audits because their designations drift out of alignment with actual duties.

Start by inventorying every position in the organization, including contractors and temporary staff. For each role, apply the Position Designation System to assess two dimensions: the potential for damage to service efficiency or integrity, and the potential for adverse effects on national security. The PDS produces both a risk level (determining investigation type) and a sensitivity level for each position.

Establish documented screening criteria that map directly to the risk designations you’ve assigned. High-risk positions should require more extensive background investigations than moderate or low-risk roles. Align your investigation tiers with OPM guidance and the requirements in 5 CFR Parts 731 and 1400, which establish the regulatory baseline for position evaluation.

Build a recurring review cycle into your personnel security program. Position risk designations should be reviewed when roles change, when organizational structures shift, and at a defined periodic interval. Document every review, including the rationale for any designation changes.

Common mistakes:

  • Designating risk levels based on job titles rather than actual duties and access requirements
  • Applying a single risk level to all positions within a department rather than evaluating each role individually
  • Failing to update designations when responsibilities change due to promotions, lateral moves, or reorganizations
  • Treating the review cycle as optional during periods of organizational stability

For your vendors

Vendor personnel who access your systems, data, or facilities present the same position-level risks as internal staff. The challenge is that most vendor management programs evaluate the vendor organization’s overall security posture without examining whether individual vendor roles handling your data have appropriate risk designations.

When assessing vendors for PS-02 compliance, request evidence that they maintain a position risk designation process for all roles that interact with your organization’s information or systems. The vendor risk assessment should confirm that designations are documented, screening criteria are defined for each risk level, and periodic reviews occur.

Ask specific questions during vendor assessments. Does the vendor use a formal position designation methodology, such as the PDS or an equivalent risk-based classification system? Can they provide the risk designations for personnel assigned to your account? Do their screening criteria align with the sensitivity of the data they handle on your behalf?

Verify that vendor review cycles are active, not just documented. Request records of the most recent designation review and confirm that changes in vendor personnel assignments trigger re-evaluation of position risk designations.

Red flags:

  • Vendors who cannot articulate their position classification methodology
  • Absence of documented screening criteria mapped to risk levels
  • No evidence of periodic reviews or reviews that haven’t occurred within the defined cycle
  • Vendor personnel with access to sensitive systems whose roles lack a formal risk designation

Evidence examples

Evidence typeExample artifact
Position risk designation policyPersonnel security policy defining the methodology for assigning risk and sensitivity levels to all organizational positions
Position designation inventoryComplete list of organizational positions with assigned risk designations, sensitivity levels, and corresponding investigation tiers
Screening criteria documentationProcedures establishing screening requirements for each risk designation level, aligned with 5 CFR Parts 731 and 1400
Designation review recordsDocumented reviews of position risk designations including review dates, reviewer names, outcomes, and rationale for any changes
Federal regulations referenceCopies of applicable sections from 5 CFR Parts 731 and 1400 referenced in the organization’s designation methodology
System security planSystem security plan sections documenting how position risk designations inform access authorization decisions

Cross-framework mapping

No cross-framework mappings are currently configured for PS-02.

  • AC-05 — Separation of Duties: ensures that position risk designations inform the division of critical functions across multiple roles, preventing any single position from accumulating unchecked access
  • AT-03 — Role-based Training: aligns training requirements with the risk designation assigned to each position, so higher-risk roles receive proportionally deeper security training
  • PE-02 — Physical Access Authorizations: uses position risk designations to determine the level of physical access appropriate for each role within secured facilities
  • PE-03 — Physical Access Control: enforces the physical access boundaries that position risk designations establish for different role categories
  • PL-02 — System Security and Privacy Plans: documents how position risk designations integrate into the broader security program and inform access decisions
  • PS-03 — Personnel Screening: directly depends on position risk designations to determine the type and depth of background investigations conducted for each role
  • PS-06 — Access Agreements: requires individuals to acknowledge security responsibilities proportional to the risk designation assigned to their position
  • SA-05 — System Documentation: includes documentation of how position risk designations map to system-level access controls and role definitions
  • SA-21 — Developer Screening: applies enhanced screening criteria to developer positions based on the risk designation assigned to roles with code-level system access
  • SI-12 — Information Management and Retention: governs how long position risk designation records and review documentation must be retained

Frequently asked questions

What is NIST SP 800-53 PS-02

PS-02 is the NIST SP 800-53 control that requires organizations to assign a risk designation to every position, establish screening criteria matched to those designations, and review them periodically. The control ensures that personnel screening isn’t applied uniformly but instead scales with the potential damage an incumbent could cause. It applies to all three baseline impact levels (low, moderate, and high) and uses the Position Designation System to assess both risk level and sensitivity level for each role.

What happens if PS-02 is not implemented

Without PS-02 implementation, organizations lack a defensible basis for their personnel screening decisions, which exposes them to audit findings and potential certification withdrawal. Assessors will flag the absence of documented position risk designations as a systemic gap in the personnel security program. The practical consequence is that high-risk positions may receive inadequate screening, increasing the likelihood of insider threats going undetected. Federal agencies also risk noncompliance with 5 CFR Parts 731 and 1400, which mandate position evaluation for suitability and security programs.

How do you audit PS-02

Auditing PS-02 starts with verifying that a complete position designation inventory exists, covering every organizational role with an assigned risk level and sensitivity level. Assessors then review the screening criteria documentation to confirm that investigation requirements match the risk designations. The third checkpoint is evidence of periodic reviews, including dated records showing when designations were last evaluated, who conducted the review, and whether any positions were reclassified. Auditors will also check that the designation methodology aligns with OPM guidance and applicable federal regulations.

What are the three position risk designation levels

The three position risk designation levels defined by the Position Designation System are low risk, moderate risk, and high risk. Each level reflects the degree of potential damage to the efficiency or integrity of organizational services that an incumbent could cause through misconduct. Low-risk positions involve duties with limited potential for adverse impact, while high-risk positions carry the potential for exceptionally serious damage. The assigned risk level directly determines the type and rigor of background investigation required before an individual fills the position.

Experience superior visibility and a simpler approach to cyber risk management