# PS-03 Personnel Screening

NIST SP 800-53 control. Family: PS Personnel Security. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Screen individuals prior to authorizing access to the system; and b. Rescreen individuals in accordance with [Assignment: organization-defined conditions requiring rescreening and, where rescreening is so indicated, the frequency of rescreening].
Guidance: Personnel screening and rescreening activities reflect applicable laws, executive orders, directives, regulations, policies, standards, guidelines, and specific criteria established for the risk designations of assigned positions. Examples of personnel screening include background investigations and agency checks. Organizations may define different rescreening conditions and frequencies for personnel accessing systems based on types of information processed, stored, or transmitted by the systems.

## Enhancements (4)
- PS-03(01) Classified Information
- PS-03(02) Formal Indoctrination
- PS-03(03) Information Requiring Special Protective Measures
- PS-03(04) Citizenship Requirements
Each enhancement's statement: /api/v1/controls/PS-03?fields=enhancements

## Patterns that use it (2)
- Important (1): SP-014 Awareness and Training Pattern
- Standard (1): SP-026 PCI Full Environment

## Clauses by framework (60 frameworks)
- iso_27001_2022: A.6.1
- iso_27002_2022: 6.1
- cobit_2019: APO07
- pci_dss_v4: 12.7
- nist_csf_2: GV.RR-04. OSA's own, not in NIST's crosswalk: GV.RR-04
- iso_42001_2023: A.4.6
- nis2: Art. 21(2)(i)
- bsi_grundschutz: ORP.2
- anssi: Hygiene.7, SecNumCloud.8.1
- osfi_b13: B-13.1.1
- finma_circular: IV.B.a(48), IV.F(100)
- gdpr: Art.28(3)(b), Art.32(4)
- dora: Art.5(4)
- bio2: 6.1
- rbi_csf: Annex1.8
- fisc: FISC.O8
- lgpd_bcb: LGPD.Art.47
- mlps_2: 8.1.8.1
- dnb_good_practice: DNB.8.1, DNB.8.4
- swift_cscf: SWIFT.5.3A
- nca_ecc: 1-9
- qatar_nia: HR
- sama_csf: 1.7
- uae_ia: T5
- bog_cisd: CISD-XV
- bom_ctrm: 3.8
- cbe_csf: CD-1, GOV-2
- cbn_csf: Part1.2, Part9
- popia: s19
- sa_js2: JS2-8.6
- bot_cyber: Ch7.2
- cpmi_pfmi: CG.GOV
- ecb_croe: CROE.2.1.2, CROE.2.3.2
- ffiec_is: II.C.7, II.C.7(a)
- hipaa_sr: §164.308(a)(3)(i), §164.308(a)(3)(ii)(A), §164.308(a)(3)(ii)(B)
- iosco_cyber: GOV-4
- nydfs_500: 500.10
- sebi_cscrf: GV.RR
- cmmc_2: PS
- nerc_cip: CIP-004-7
- nrc_73_54: RG5.71-C-PS
- doe_c2m2: WORKFORCE
- api_1164: Sec 13
- awia: AWWA Sec 8
- iaea_nss: Sec 9
- pci_pts: H
- cbest: CBEST.8
- fca_sysc_13: SYSC 13.6.4
- fda_21_cfr_11: §11.10(i), §11.100(b)
- hitrust_csf: 02.a
- iso_27799: 7.1, 9.3
- naic_ds: 4-personnel, 4B
- pra_ss1_23: P2.4
- solvency_ii: Art.42
- csa_ccm_v4: HRS-01
- csa_aicm: HRS-01
- ccss_v9: 1.04.4
- basel_sco60: SCO60.55, SCO60.62
- bssc: GSP-04
- sec_custody_digital: SEC-CD-16
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PS-03
- Clauses only: /api/v1/controls/PS-03?fields=mappings
- Page for people: /controls/ps-03/
