Quick-reference card
| Field | Value |
|---|---|
| Control ID | PS-07 |
| Control Name | External Personnel Security |
| Framework | NIST SP 800-53 Revision 5 |
| Control Family | Personnel Security |
| Baselines | LOW MODERATE HIGH |
| Relevance | Organization (Third Party) |
| Risk Severity | High |
What this control requires
PS-07 requires your organization to define, enforce, and monitor personnel security requirements for every external provider that accesses your systems, facilities, or data. That means contractors, managed service providers, testing firms, outsourced IT teams, and any other third party whose people touch your environment.
In practice, you need to do five things. First, establish personnel security roles and responsibilities that apply to external providers. Second, require those providers to follow your personnel security policies. Third, document all of these requirements in your acquisition and contracting materials. Fourth, require providers to notify designated personnel when their staff who hold your credentials, badges, or system privileges transfer roles or leave the provider. Fifth, actively monitor whether providers are meeting these obligations over time.
The underlying problem PS-07 addresses is that organizations can’t control hiring, screening, or offboarding decisions made by their vendors. Without documented requirements and ongoing monitoring, a terminated contractor could retain active credentials to your systems for weeks or months after their last day. PS-07 closes that gap by making external personnel security an explicit, enforceable contract term rather than an assumed best practice.
Why it matters
Most organizations invest heavily in screening and managing their own employees but extend almost no equivalent rigor to the external personnel working inside their environments. Contractors, consultants, and outsourced teams often operate with the same access as full-time staff, yet their hiring, screening, and termination processes are controlled by a different organization with different standards.
That asymmetry creates real compliance exposure. Auditors evaluating your NIST SP 800-53 posture will look for documented evidence that you’ve extended personnel security requirements to external providers. If you can’t produce acquisition documents, service-level agreements, or compliance monitoring records that address third-party personnel, you’ll receive a finding regardless of how strong your internal HR processes are.
The risk goes beyond audit findings. When a vendor’s employee leaves and the vendor doesn’t notify you within a defined timeframe, that individual may retain active credentials, physical badges, or system privileges. Your internal termination workflows don’t fire because the person was never in your HR system. The access persists until someone notices, and in many organizations, no one is watching.
Organizations that manage large vendor portfolios face this challenge at scale. Each provider relationship introduces personnel you didn’t hire, didn’t screen, and won’t be told about when they leave. Third-party risk requirements under NIST 800-161 reinforce the need for structured controls over supply chain personnel, and PS-07 is the personnel-specific anchor for that effort.
What attackers exploit
- Lingering credentials from unreported terminations. When a vendor’s employee departs but the vendor never notifies the contracting organization, the former contractor’s credentials remain active and exploitable.
- Inconsistent screening standards across providers. Organizations that don’t impose their own personnel security requirements on vendors inherit whatever screening the vendor chose to perform, which may be minimal.
- Undocumented access granted during onboarding. External personnel who receive ad hoc system privileges or physical badges outside formal processes create access that no one tracks or revokes.
- Gaps in compliance monitoring. Without ongoing verification, vendors may comply with personnel security requirements during initial onboarding but drift over time as staff turnover increases.
How to implement
The most common failure mode for PS-07 is treating it as a one-time contracting exercise. Organizations add personnel security language to their master service agreements, then never verify whether vendors actually follow through on notification timelines or screening requirements.
For your vendors
Start by defining the personnel security requirements you’ll impose on every external provider. These requirements should address background screening standards, security awareness training obligations, acceptable timeframes for notifying your team about personnel transfers or terminations, and the process for returning credentials and badges. Document these requirements in a standalone personnel security addendum or embed them directly in your acquisition documents and service-level agreements.
When evaluating a vendor’s compliance, your security questionnaires should include specific questions about their personnel security practices. Ask whether the vendor conducts background checks on all personnel who will access your systems. Ask how quickly the vendor will notify your designated contact when someone with access to your environment leaves or changes roles. Ask whether the vendor provides security awareness training and how frequently. Request copies of their personnel security policy and any termination notification procedures.
Evidence you should request goes beyond policy documents. Ask for redacted examples of completed background checks to confirm the vendor’s screening process is active. Request logs or records showing past termination notifications to verify the vendor has an operational process, not just a policy. If the vendor provides personnel who access your physical facilities, ask for their badge management procedures and credential return records.
Red flags include vendors who can’t produce a written personnel security policy, vendors who report that termination notifications happen “as needed” without a defined timeframe, and vendors who don’t distinguish between personnel with and without access to your environment. If a vendor can’t articulate who in their organization is responsible for sending termination notifications, their process likely doesn’t exist.
To verify beyond self-attestation, consider periodic access reviews that cross-reference your active external user accounts against the vendor’s current personnel roster. The Vendor Risk product from UpGuard helps automate ongoing monitoring of vendor security practices, including personnel security posture, so you aren’t relying solely on annual questionnaire responses. Continuous monitoring catches gaps between what vendors promise and what they deliver.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Personnel security policy | Policy document defining personnel security requirements for external providers, including screening standards, access approval workflows, and notification obligations |
| Acquisition and contracting documents | Master service agreements, statements of work, or procurement contracts containing personnel security clauses and defined notification timeframes |
| Service-level agreements | SLAs specifying vendor obligations for termination and transfer notification timelines, credential return procedures, and screening compliance |
| Personnel security requirements list | Documented list of security roles, responsibilities, and screening criteria applied to external provider personnel |
| Notification records | Logs or correspondence showing vendor notifications of personnel transfers or terminations within the required timeframe |
| Compliance monitoring records | Results of periodic reviews, access audits, or assessments verifying that external providers are meeting personnel security requirements |
| System security plan | SSP sections addressing external personnel security controls, roles, and responsibilities |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 5.2 Information security roles and responsibilities | Partial |
| ISO 27001:2022 | 5.4 Management responsibilities | Partial |
Related controls
- PS-02 — Position Risk Designation: Assigns risk categories to positions, which feeds into the screening and access requirements PS-07 extends to external provider personnel.
- PS-03 — Personnel Screening: Defines screening procedures for individuals before granting access, providing the baseline that external providers must meet or exceed under PS-07.
- PS-04 — Personnel Termination: Covers access revocation when personnel leave, directly relevant to the notification requirements PS-07 imposes on external providers.
- PS-05 — Personnel Transfer: Addresses access changes during role reassignment, complementing PS-07’s requirement that vendors report transfers of credentialed personnel.
- PS-06 — Access Agreements: Establishes the agreements personnel must sign before receiving access, which PS-07 requires organizations to extend to external provider staff.
- AT-02 — Literacy Training and Awareness: Provides the security awareness training that organizations may require external providers to deliver to their personnel under PS-07.
- AT-03 — Role-based Training: Specifies training aligned to security functions, relevant when external personnel fill roles with specific security responsibilities.
- MA-05 — Maintenance Personnel: Controls access for external maintenance workers, a specific subset of external personnel addressed by PS-07’s broader requirements.
- PE-03 — Physical Access Control: Manages facility access and badge issuance, directly tied to PS-07’s requirements for credential return and termination notification.
- SA-05 — System Documentation: Ensures external providers have the documentation they need to fulfill security responsibilities defined under PS-07.
Frequently asked questions
What is NIST SP 800-53 PS-07?
PS-07 is the NIST SP 800-53 control that requires organizations to establish, document, and monitor personnel security requirements for external providers such as contractors, service bureaus, and outsourced IT teams. It covers everything from defining security roles and responsibilities to requiring timely notification when external personnel with organizational credentials or system privileges transfer or leave. The control applies across LOW, MODERATE, and HIGH baselines, making it a foundational requirement for any organization that relies on third-party personnel.
What happens if PS-07 is not implemented
Without PS-07, your organization has no formal mechanism to ensure that external providers follow your personnel security policies or notify you when credentialed staff depart. Terminated contractor accounts may remain active indefinitely because your internal offboarding process doesn’t cover personnel managed by a different organization. Auditors reviewing your compliance posture will flag the absence of documented personnel security requirements in acquisition documents and service-level agreements. The result is both a compliance gap and a practical security risk from unmonitored third-party access.
How do you audit PS-07
Auditing PS-07 starts with verifying that personnel security requirements are documented and included in acquisition documents and service-level agreements with external providers. Assessors will review your compliance monitoring process to confirm that you’re actively verifying provider adherence, not just collecting initial attestations. They’ll also check for evidence that external providers have notified designated personnel of transfers and terminations within the defined timeframe, using notification records or logs as proof. A complete audit trail includes the personnel security policy, the list of personnel security requirements, and records showing ongoing oversight of each provider relationship.
Does PS-07 apply to cloud service providers
Yes. Cloud service providers are a category of external provider under PS-07, and their personnel may hold credentials or system privileges within your environment. You should include personnel security requirements in your cloud service agreements, specifying notification timelines for staff changes and screening expectations for personnel with access to your data or infrastructure. The Personnel Security family provides additional controls that work alongside PS-07 to address screening, termination, and access agreement requirements for all external personnel, including cloud provider staff.