Personnel Security Policy and Procedures (PS-1)

The university develops, disseminates, and periodically reviews/updates formal, documented procedures to facilitate the implementation of the Personnel Security policy and associated personnel security controls.

Position Risk Designation (PS-2)

The university identifies and classifies personnel positions based on risk category in order to determine the risk level associated with the position, thereby determining the controls that must be implemented for the position.

Personnel Screening (PS-3)

The university screens individuals, to authenticate identity, before authorizing access to university information resources.

Personnel Termination (PS-4)

In the event of termination of individual employment, the university terminates information resource access, retrieves all university information system-related property, and provides appropriate personnel with access to official records created by the terminated employee that are stored on university information resources.

Personnel Transfer (PS-5)

The university reviews information resource/facility access authorizations when personnel are reassigned or transferred to other positions within the university and initiates appropriate actions as identified by Human Resources.

Access Agreements (PS-6)

The university completes appropriate signed access agreements for individuals requiring access to university information and information resources before authorizing access.

Third Party Personnel Security (PS-7)

The university establishes personnel security requirements including security roles and responsibilities for third-party providers and monitors provider compliance.

Personnel Sanctions (PS-8)

The university employs a formal sanctions process for personnel failing to comply with established information security policies and procedures.