PS-1: Personnel Security – Policy and Procedures
NIST Baseline: Low
DIR Required By: 07/20/2023
Review Date: 07/31/2024
Purpose –
The Personnel Security Policy and associated controls document the requirements for managing risks associated with personnel including hiring, termination, transfer, third-party personnel, and disciplinary action.
Scope and Roles –
This policy applies to information resources owned or managed by Tarleton State University (Tarleton). The intended audience includes all involved in hiring and personnel management, the Tarleton Chief Information Officer (CIO), Chief Information Security Officer (CISO), and information resource owners and custodians.
Compliance –
Personnel Security controls are implemented to ensure compliance with the Texas Department of Information Resources (DIR) Security Control Standards Catalog as required by Title 1 Texas Administrative Code §202.76 and Texas A&M University System (TAMUS) Regulation 29.01.03, Information Security.
Implementation –
- The Tarleton CISO, in coordination with information resource owners and custodians, shall develop, document, and disseminate a set of controls that addresses the Personnel Security for information resources. These controls should:
- Address purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
- Be consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
- Information resource owners and custodians are responsible for any procedures to facilitate the implementation of the Personnel Security controls in order to ensure proper security protocols regarding personnel;
- The Tarleton CISO, or their designee, shall review and update the Personnel Security controls as necessary.