PS-3: Personnel Screening

PS-03 requires organizations to screen every individual before granting system access and rescreen them on a schedule tied to position risk.

Quick-reference card

FieldValue
Control IDPS-03
Control NamePersonnel Screening
FrameworkNIST SP 800-53 Revision 5
Control FamilyPersonnel Security
BaselinesLOW MODERATE HIGH
RelevanceOrganization (First Party and Third Party)
Risk SeverityHigh

What this control requires

PS-03 requires organizations to screen every individual before granting system access and rescreen them on a schedule tied to position risk. The control addresses one of the most persistent blind spots in security programs: organizations invest heavily in technical defenses while treating the people who operate those systems as trusted by default. Within the broader Personnel Security family, PS-03 is the mechanism that forces a documented, repeatable vetting process before anyone touches sensitive data.

In practice, this control means you must establish screening criteria that reflect the risk designation of each position, as defined under PS-02. Background investigations, criminal history checks, credit reviews, and reference verification all fall within scope depending on the sensitivity of the role. The screening must happen before access is provisioned, not retroactively.

Rescreening is equally critical. You need to define the conditions that trigger rescreening, such as role changes, security clearance renewals, or a fixed calendar interval, and document the frequency for each condition. Organizations that screen at hire but never revisit that decision carry accumulated risk that grows with every year of unchecked access.

Why it matters

Personnel screening failures don’t generate the same headlines as ransomware attacks, but they introduce a category of risk that’s harder to detect and slower to surface. An insider with legitimate credentials doesn’t need to exploit a vulnerability. They already have the keys.

Failure to maintain PS-03 introduces direct audit risk. Federal agencies and contractors operating under the Federal Information Security Modernization Act (FISMA) face potential findings during Office of Inspector General assessments if screening records are incomplete or rescreening intervals aren’t documented. For organizations pursuing or maintaining a NIST SP 800-53-based authorization to operate (ATO), a gap in personnel screening can stall the entire authorization process.

Beyond federal compliance, the principle behind PS-03 applies to any organization handling sensitive data. If your information security management system relies on role-based access controls, the integrity of those controls depends on knowing who you’ve granted access to and whether their risk profile has changed since the original screening.

The consequences compound over time. An employee screened five years ago may have developed financial pressures, changed affiliations, or accumulated access far beyond their original role. Without rescreening, you have no mechanism to detect these shifts before they become incidents.

What attackers exploit

  • Stale background checks that never catch changes in an individual’s risk profile after initial hire
  • Inconsistent screening standards across departments or business units, creating pockets of unvetted access
  • Contractor and temporary staff gaps where screening requirements are less rigorous than for full-time employees
  • Delayed provisioning pressure that leads managers to grant system access before screening is complete
  • Position reclassification without rescreening when roles are upgraded in sensitivity but the individual’s background check isn’t refreshed

How to implement

The most common failure with PS-03 isn’t the absence of a screening program. It’s the gap between what the policy says and what actually happens when a hiring manager needs someone onboarded by Monday.

For your organization

Start by aligning your screening criteria with the position risk designations you’ve established under PS-02. Each risk tier (low, moderate, high) should map to a specific screening depth. Low-risk positions may require only identity verification and a basic criminal background check. High-risk positions with access to classified or sensitive data typically require a full background investigation, credit check, and reference interviews.

Build a screening workflow that blocks system access provisioning until screening is complete. This requires coordination between human resources, IT, and the security team. Your identity and access management (IAM) system should enforce this gate, not rely on manual handoffs. Document the workflow in your personnel security procedures and make sure hiring managers understand that no exceptions exist without documented approval from a designated authority.

For rescreening, define specific trigger conditions. Common triggers include promotion or lateral transfer into a higher-risk position, adverse information from continuous evaluation programs, expiration of a security clearance, and fixed-interval rescreening (often every five years for moderate-risk roles). Record each rescreening event with the same rigor as the initial screening. Organizations subject to ISO 27001 requirements for terms and conditions of employment will find overlap here that can reduce duplicated effort.

Common mistakes include treating screening as an HR-only function with no security oversight, failing to document rescreening trigger conditions, and allowing temporary access during “pending” screening periods without compensating controls.

For your vendors

When you rely on third-party service providers who access your systems or data, PS-03 extends to their personnel. Your vendor risk management process should verify that vendors maintain screening programs equivalent to your own standards.

During vendor assessments, ask these questions:

  • Do you conduct background investigations on all personnel who will access our systems or data?
  • What screening criteria do you apply, and how do they vary by role sensitivity?
  • What is your rescreening policy, including trigger conditions and frequency?
  • How do you handle personnel who fail a screening or rescreening check?
  • Can you provide evidence of completed screenings for individuals assigned to our account?

Request specific artifacts as evidence. A vendor’s personnel screening policy alone isn’t sufficient. Ask for redacted screening completion records, the rescreening schedule with documented trigger conditions, and the procedure for revoking access when screening issues arise.

Red flags to watch for include vendors who can’t produce a written screening policy, those who screen only at hire with no rescreening program, and providers who grant system access before screening is complete. Any vendor claiming that all screening is handled by a staffing agency should still demonstrate oversight and accountability for the screening outcomes.

Verify that the vendor’s screening standards align with the risk level of the data or systems they access on your behalf. A vendor handling low-sensitivity support tickets doesn’t need the same screening depth as one administering your cloud infrastructure.

Evidence examples

Evidence typeExample artifact
Personnel screening policyPersonnel Security Policy defining screening criteria by position risk level, rescreening triggers, and approval authority for access provisioning
Screening proceduresStandard operating procedure documenting background investigation steps, identity verification methods, and screening completion workflow
Screening completion recordsRedacted background investigation reports confirming screening was completed prior to system access for each individual
Rescreening scheduleDocumented rescreening calendar showing trigger conditions, frequency by risk tier, and dates of completed rescreenings
System security planSSP section describing how PS-03 is implemented, including screening gates in the access provisioning process
Access provisioning recordsAudit trail showing system access was granted only after screening completion, with timestamps and approver names

Cross-framework mapping

Organizations mapping their NIST SP 800-53 controls to other frameworks will find partial overlap with personnel screening requirements. For a deeper look at how NIST SP 800-171 addresses personnel security, the 03.09 family covers similar ground for controlled unclassified information environments.

FrameworkControl(s)Coverage
ISO 27001:20226.1 ScreeningPartial
NIST SP 800-171 Rev 303.09.01 Personnel ScreeningPartial
  • AC-02 — Account Management: account provisioning workflows should verify that personnel screening is complete before creating or enabling system accounts.
  • IA-04 — Identifier Management: identifier assignment depends on confirmed screening status to prevent unvetted individuals from receiving system credentials.
  • MA-05 — Maintenance Personnel: maintenance staff require screening commensurate with the access their maintenance activities demand.
  • PE-02 — Physical Access Authorizations: physical access decisions should factor in the same screening results used for logical access under PS-03.
  • PM-12 — Insider Threat Program: screening and rescreening feed the indicators that insider threat programs use to detect changes in personnel risk.
  • PS-02 — Position Risk Designation: PS-02 establishes the risk categories that determine the depth of screening PS-03 requires.
  • PS-06 — Access Agreements: signed access agreements formalize the terms that screened personnel must follow when using organizational systems.
  • PS-07 — External Personnel Security: extends screening requirements to external service providers, contractors, and other non-employees.
  • SA-21 — Developer Screening: applies additional screening requirements to individuals involved in system development and integration.

Frequently asked questions

What is NIST SP 800-53 PS-03?

PS-03 is the NIST SP 800-53 control that requires organizations to screen individuals before authorizing system access and rescreen them at defined intervals based on position risk designation. It applies across all three baselines (LOW, MODERATE, HIGH), making it a universal requirement for federal systems and any organization using the NIST SP 800-53 framework. The control ensures that access decisions are grounded in verified background information rather than assumed trust.

What happens if PS-03 is not implemented?

Without PS-03, organizations have no documented assurance that individuals accessing their systems have undergone background investigations appropriate to their role’s risk level. Auditors reviewing FISMA compliance will flag the absence of screening completion records and rescreening schedules as a finding. The gap may delay or prevent an authorization to operate and can trigger corrective action plans that consume significant security team resources.

How do you audit PS-03?

Auditors verify PS-03 by reviewing personnel screening completion records against the list of individuals with active system access, confirming that every authorized user was screened before provisioning. They also examine the documented rescreening trigger conditions and frequency, then sample rescreening records to verify the schedule is being followed. The system security plan should describe the screening gates in the access provisioning workflow, and auditors will test whether those gates function as documented.

How often should personnel rescreening occur?

Rescreening frequency under PS-03 is organization-defined, meaning you set the intervals based on your risk assessment and the sensitivity of each position. Many organizations rescreen high-risk positions every one to two years and moderate-risk positions every five years, while also defining event-driven triggers like role changes or adverse information. The key requirement is that you document both the conditions requiring rescreening and the specific frequency, then maintain records showing you follow the schedule.

Experience superior visibility and a simpler approach to cyber risk management