PS-7: External Personnel Security

NIST Baseline: Low 

DIR Required By:  01/20/2023 

Review Date:  07/31/2024 

  • It is the responsibility of the information resource owner, or designee, to: 
    • Establish and document personnel security requirements including security roles and responsibilities for third-party providers; 
    • Require third-party providers to comply with personnel security policies and procedures established by Tarleton State University (Tarleton); 
    • Require third-party providers to notify unit managers of any personnel transfers or terminations of third-party personnel who possess Tarleton credentials, or who have information resource privileges as soon as feasible; and 
    • Monitor provider compliance. 

References/Additional Resources

SP 800-35 

SP 800-63-3