PS.L2-3.9.2[c] – Determine if actions for personnel termination or transfer are implemented.
This objective confirms that your organization is not only documenting the steps for terminating or transferring personnel — but that those steps are actually followed and enforced when individuals with access to Controlled Unclassified Information (CUI) leave or change roles.
PS.L2-3.9.2[b] – Examine documentation to confirm actions for personnel termination or transfer are identified.
This objective ensures that your organization has documented procedures for managing user access and asset recovery during personnel termination or job role changes—especially for individuals with access to systems that handle Controlled Unclassified Information (CUI).
PS.L2-3.9.1 – Screen individuals prior to authorizing access to organizational systems containing CUI.
This control requires your organization to screen personnel before allowing them to access systems that store, process, or transmit Controlled Unclassified Information (CUI). This applies to employees, contractors, and any third parties who will interact with sensitive environments.
PS.L2-3.9.2[a] – Identify actions for personnel termination or transfer.
This objective requires your organization to define and document the actions to take when personnel are terminated or transferred, especially those who had access to systems containing Controlled Unclassified Information (CUI). These actions must be part of a structured process to prevent unauthorized retention of access or data.
3.9.2 – Ensure that CUI is protected during personnel actions such as terminations and transfers
This control requires organizations to safeguard Controlled Unclassified Information (CUI) during employee terminations, transfers, or role changes. You must ensure that access is revoked or adjusted immediately to prevent unauthorized access to sensitive information. Read the full blog breakdown of 3.9.2
3.9.1 – Screen individuals prior to authorizing access to organizational systems containing CUI
This control requires organizations to conduct background screening for individuals before granting them access to systems that handle Controlled Unclassified Information (CUI). This applies to both employees and contractors. Read the full blog breakdown of 3.9.1