Quick-reference card
| Field | Value |
|---|---|
| Control ID | PS-05 |
| Control Name | Personnel Transfer |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Personnel Security |
| Baselines | LOW MODERATE HIGH |
| Relevance | Organization (First Party and Third Party) |
| Risk Severity | High |
What this control requires
PS-05 requires organizations to review and adjust every logical and physical access authorization when someone moves to a new role internally. Most NIST SP 800-53 controls focus on the edges of employment, hiring and termination, but PS-05 addresses the often-overlooked middle: what happens to access when people change jobs within the same organization.
In practice, this control means you can’t treat an internal transfer like a name change on an org chart. You need to confirm that the person’s current access still matches their new responsibilities, revoke anything that doesn’t, and provision whatever the new role requires. This review covers both system accounts and physical facility access.
The reason PS-05 exists is that access tends to accumulate. An analyst who moves from finance to marketing rarely loses their finance system privileges unless someone explicitly removes them. Over time, this privilege creep creates exactly the kind of excessive access that auditors flag and attackers exploit.
Why it matters
Unmanaged personnel transfers are one of the most reliable sources of excessive privilege in any organization. Unlike terminated employees, transferred personnel remain active in your systems, which means their outdated access often flies under the radar during routine reviews.
The compliance risk here is direct. Auditors evaluating your personnel security controls will look for documented evidence that access was reviewed at the time of transfer, not months later during a periodic review cycle. Failure to maintain this control introduces audit findings and may result in certification withdrawal or regulatory action.
Beyond audit risk, privilege accumulation from unmanaged transfers undermines your entire access control posture. Every access authorization that persists beyond its operational need violates the principle of least privilege, and every violation is a potential pathway for misuse, whether intentional or accidental.
What attackers exploit
- Accumulated privileges across roles. Transferred employees who retain access from previous positions create accounts with broader permissions than any single role should have.
- Stale physical access authorizations. Building passes and facility access tied to a previous role often persist because physical access reviews happen less frequently than logical access reviews.
- Gaps between HR action and IT execution. When the formal transfer happens in HR systems but access changes lag by days or weeks, the window for unauthorized access opens.
- Lack of notification to security teams. If security and IT operations aren’t notified of transfers in a defined timeframe, they can’t act on access changes they don’t know about.
How to implement
The most common failure with PS-05 isn’t missing the control entirely. It’s treating internal transfers with less rigor than terminations. Organizations that have robust offboarding processes often have no equivalent workflow for role changes, leaving transferred employees with a union of their old and new permissions.
For your organization
Start by establishing a formal trigger in your HR system that initiates an access review whenever a transfer or reassignment is processed. This trigger should generate a review task for the employee’s new manager and the IT or identity team.
Build a documented transfer checklist that covers both logical and physical access. Logical access includes system accounts, application roles, shared drive permissions, VPN group memberships, and privileged access. Physical access includes badge access to buildings, floors, secure areas, and any key or token issuance. Your account management processes should integrate directly with this checklist so that account modifications during transfers follow the same approval workflows as new account provisioning.
Define a specific timeframe for completing transfer actions after the formal HR action. NIST expects you to set this parameter yourself. Most organizations target completion within five business days of the effective transfer date.
Ensure you notify the right people. Your procedure should name the roles that receive transfer notifications: the previous manager, the new manager, the IT security team, and the physical security team at minimum.
Document everything. Retain records showing what access was reviewed, what was revoked, what was added, and who approved each change. These records are your primary evidence during an audit.
Common mistakes to avoid:
- Relying on the employee to self-report what access they no longer need
- Treating all transfers identically regardless of the sensitivity change between roles
- Failing to update physical access when only logical access is reviewed
- Not defining a specific timeframe for completing transfer actions
For your vendors
When assessing a vendor’s PS-05 compliance, your goal is to verify that they have a repeatable, documented process for managing access during internal role changes.
Questionnaire questions to include:
- Do you have a documented procedure for reviewing and modifying access authorizations when employees transfer between roles?
- What is your defined timeframe for completing access changes after a transfer?
- How do you ensure both logical and physical access are reviewed during transfers?
- Who is notified when a personnel transfer occurs, and within what timeframe?
Evidence to request:
- Personnel transfer policy or the relevant section of the personnel security policy
- A sample of completed transfer checklists (redacted) showing access review and modification
- Documentation of the notification process and defined roles
- System logs or identity management records showing access modifications aligned with transfer dates
Red flags to watch for:
- No defined procedure separate from termination procedures
- Transfer checklists that address only logical access or only physical access, not both
- No defined timeframe for completing transfer actions
- Evidence that access changes consistently lag behind formal transfer dates by weeks or more
Verification approach:
Request a sample of three to five recent transfers and compare the formal transfer date against the date access was actually modified. Look for consistency between the stated timeframe in policy and the actual execution timeline. Confirm that both logical and physical access appear in the review documentation.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Personnel security policy | Personnel security policy defining transfer procedures, access review requirements, and notification timelines |
| Transfer procedures | Documented workflow for initiating and completing access reviews upon reassignment, including checklists for logical and physical access |
| Transfer action records | Completed transfer forms showing access reviewed, revoked, and provisioned for each transferred employee, with timestamps and approvals |
| Access authorization inventory | Current list of system and facility access authorizations by employee, used to verify post-transfer modifications |
| Notification records | Email or ticketing system records confirming that defined personnel or roles were notified within the required timeframe |
| System security plan | Relevant sections of the system security plan describing how PS-05 is implemented, including defined parameters for timeframes and notification roles |
Cross-framework mapping
| Framework | Control | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.11 Return of assets | Partial |
| ISO 27001:2022 | 6.5 Responsibilities after termination or change of employment | Partial |
| NIST SP 800-171 Rev 3 | 03.09.02 Personnel Termination and Transfer | Partial |
Related controls
The following controls within NIST SP 800-53 address related aspects of access management and personnel security.
- AC-02 — Account Management: Governs the lifecycle of system accounts, including creation, modification, and removal, which directly supports the access changes required during personnel transfers.
- IA-04 — Identifier Management: Covers the management of user identifiers, which may need to be updated or reissued when personnel change roles.
- PE-02 — Physical Access Authorizations: Addresses the authorization of physical facility access, a key component of the transfer review process.
- PM-12 — Insider Threat Program: Supports detection of access misuse that can result from improperly managed transfers and accumulated privileges.
- PS-04 — Personnel Termination: Covers access revocation when employees leave the organization entirely, representing the complementary control to PS-05’s transfer focus.
- PS-07 — External Personnel Security: Extends personnel security requirements to external service providers, whose staff transfers also require access review.
Frequently asked questions
What is NIST SP 800-53 PS-05
PS-05 requires organizations to review and modify all logical and physical access authorizations whenever an employee is reassigned or transferred to a different position. This control ensures that access permissions match the person’s new operational need rather than accumulating across roles. It covers system accounts, facility access, identification cards, and building passes. Organizations must define specific timeframes for completing transfer actions and notifying relevant personnel.
What happens if PS-05 is not implemented
Failing to implement PS-05 results in privilege accumulation, where transferred employees retain access authorizations from previous roles that no longer align with their current responsibilities. Auditors will flag the absence of documented transfer procedures and access modification records as a control deficiency. For organizations pursuing or maintaining FedRAMP, FISMA, or NIST SP 800-53 compliance, this deficiency can lead to plan of action and milestones entries, conditional authorizations, or delays in authorization to operate decisions. The compounding effect of unmanaged transfers also degrades the effectiveness of your broader account management controls.
How do you audit PS-05
Auditing PS-05 starts with reviewing the personnel security policy and transfer procedures for defined timeframes and notification roles. Pull a sample of recent personnel transfers from HR records and compare each formal transfer date against the date that access modifications were completed in identity management systems. Verify that the access authorization inventory reflects the transferred employee’s current role, not a combination of old and new permissions. Confirm that notification records show the defined personnel or roles were informed within the required timeframe.
What is the difference between PS-04 and PS-05
PS-04 covers personnel termination, where the goal is to revoke all access immediately when someone leaves the organization. PS-05 covers personnel transfers, where access isn’t fully revoked but must be reviewed, modified, and realigned to a new set of responsibilities. The key distinction is that PS-05 requires a nuanced access review rather than a blanket revocation, because the transferred employee still needs some level of system and facility access. Both controls share a dependency on timely notification to security teams and documented records of access changes.