Personnel Security (PS) Guide for CMMC Level 2.0 Compliance

HR, nist-800-171

Welcome to our comprehensive Personnel Security (PS) Guide for CMMC Level 2.0 Compliance. This guide is designed specifically to support small and medium-sized businesses, as well as DoD contractors, in achieving Personnel Security compliance & gathering evidence for CMMC Level 2.

In this guide, we provide a clear and practical approach to navigating the personnel security requirements set out in CMMC Level 2.0. From personnel screening processes to updating your System Security Plan (SSP), we’ll guide you through each essential control with actionable steps and evidence-gathering tips to meet compliance with confidence.

To ensure your team is fully prepared for certification, we offer expert consultations designed to simplify complex requirements and expedite your path to compliance. Schedule your free Consultation Now!

Trusted companies rely on Adelia Risk for CMMC Level 2 personnel security and compliance

PS.L2-3.9.1 – SCREEN INDIVIDUALS FOR PERSONNEL SECURITY

“Screen individuals prior to authorizing access to information systems containing CUI.”

Level Of Effort: Low

This control means that businesses have to check how trustworthy people are before letting them use systems with Controlled Unclassified Information (CUI).

Recommendations:

  • Conduct criminal background checks: The usual way companies handle this is by doing criminal background checks on new employees or current employees who haven’t been checked before.

Evidence:

  • For conducting background checks: Keep records of these background checks. Also, update your System Security Plan (SSP) to show that you’re keeping track of who’s been checked and that you’re following this screening process.

What our clients say

Client testimonial praising Adelia Risk for closing cybersecurity gaps and ensuring CMMC Level 2 compliance

PS.L2-3.9.2 – PERSONNEL ACTIONS

“Ensure that CUI and information systems containing CUI are protected during and after personnel actions such as terminations and transfers.”

Level Of Effort: Low

This control makes sure that systems with CUI stay safe when people change jobs or leave the company. It requires a plan for turning off their system access. Follow this plan carefully whenever there’s a change in personnel.

Recommendations:

  • Checklists for new and leaving employees: Make lists that help you keep track of important steps. When new people or contractors come in, you need to check their backgrounds. It’s also important to carefully decide who gets to access your systems and the CUI. And don’t forget, they need the right training too.

Evidence:

  • Using checklists: Keep these checklists and update your SSP with this info. This shows you’re paying attention to these important steps.

A quick tip: You can find examples of Termination Checklists here. You can change them a bit to fit what your company needs. They’re a good starting point to make sure you’re doing everything right when someone leaves the company.

Trusted companies rely on Adelia Risk for CMMC Level 2 personnel security and compliance

Need Help With Other CMMC Controls? 

Table of Contents

Tag(s):
Picture of Josh Ablett

Josh Ablett

Josh Ablett, CISSP, has been meeting regulations and stopping hackers for 20 years. He has rolled out cybersecurity programs that have successfully passed rigorous audits by the SEC, the FDIC, the OCC, HHS, and scores of customer auditors. He has also built programs that comply with a wide range of privacy and security regulations such as CMMC, HIPAA, GLBA, SEC/FINRA, and state privacy laws. He has worked with companies ranging from 5 people to 55,000 people.

Share

Related Posts

HIPAA Compliant Email is at the heart of modern medical practices. It makes administrative processes more

When working with clients on cybersecurity tasks, or addressing security vulnerabilities, they sometimes ask, “how do

Though Gmail is not HIPAA compliant by default, it can be configured to meet HIPAA standards

Do you think we might be a good match?