Answer
CPCSC requires comprehensive personnel security including screening, training, access management, monitoring, and termination procedures to ensure trustworthy handling of specified information.
Why Personnel Security Matters
Most security incidents involve human factors whether through malicious intent, negligence, or manipulation by adversaries. Malicious insiders with legitimate access can steal specified information, sabotage systems, or provide access to external attackers—notable breaches like Snowden, Manning, and countless corporate espionage cases demonstrate this threat.
Negligent or untrained employees might inadvertently mishandle specified information, fall for phishing attacks, misconfigure systems, or violate security policies without understanding consequences. Compromised personnel can be blackmailed, coerced, or manipulated by foreign intelligence services or criminal organizations into betraying their employers.
Social engineering attacks exploit human psychology to convince employees to bypass security controls, reveal credentials, or install malware. For defense contractors handling specified information, personnel security threats are elevated because foreign adversaries specifically target employees through recruitment, blackmail, or manipulation.
Strong personnel security controls reduce these risks through screening, training, monitoring, and accountability.
ITSP.10.171 Personnel Security Requirements
The Personnel Security family in ITSP.10.171 includes multiple requirements:
- Organizations must screen individuals for positions based on criteria including requiring formal screening commensurate with risk level and determining whether position requires specific security eligibility or clearance
- Ensure positions are filled by individuals meeting screening criteria
- Require individuals to sign acknowledgments of responsibilities for handling specified information before granting access
- Establish terms and conditions for third-party providers regarding personnel screening, including requiring providers to comply with personnel security policies and procedures
- Notify of any changes in personnel or employment status, and comply with consequences for failure to meet personnel security requirements
- Review and update personnel screening criteria and procedures at defined frequency
- Require personnel to report travel to countries of concern, contacts with individuals from countries of concern, or other activities that might indicate counterintelligence or security concerns
- Upon employment termination, disable information system access within defined timeframe, conduct exit interviews including return of organizational property and discussion of post-employment responsibilities
- Retrieve all security-related organizational property
- Require personnel with duties related to system security to demonstrate security competence through appropriate training and experience
Personnel Screening and Background Checks
Background checks verify personnel trustworthiness before granting access to specified information. The following types of verification are commonly conducted:
- Identity verification confirms individual is who they claim through government-issued identification
- Employment history verification contacts previous employers to confirm employment dates, positions, and departures
- Education verification confirms claimed degrees and credentials from issuing institutions
- Criminal history checks through police records identify convictions or pending charges
- Credit history checks identify financial problems that might make individuals vulnerable to bribery or blackmail
- Reference checks contact personal or professional references to gather information about character and suitability
- Citizenship and immigration status verification confirms legal right to work in Canada and citizenship for positions requiring it
Screening depth should be proportional to risk—personnel accessing highly sensitive specified information require more thorough checks than those with supervised limited access. For defense contracts involving classified information in addition to specified information, formal security clearances through government security processes are required.
Organizations should document screening requirements for different position categories, implement screening before granting access, and conduct periodic re-screening (every 5-10 years depending on risk level) to identify changes in circumstances.
Personnel Security Training
Training ensures personnel understand security responsibilities and recognize threats. Initial security training before granting access to specified information covers the following areas:
- Security policies and procedures
- Acceptable use of systems
- Data classification and handling requirements
- Physical security obligations
- Incident reporting procedures
- Consequences of security violations
Role-based training for personnel with security responsibilities provides specialized training appropriate to their roles—system administrators need technical security training, managers need security management training, security personnel need advanced threat and response training.
Annual refresher training maintains awareness and updates personnel on new threats, policy changes, and lessons learned from incidents. Specialized training for handling specified information covers classification levels, marking requirements, storage and transmission procedures, and authorized disclosure rules.
Insider threat awareness trains personnel to recognize indicators of concerning behavior in colleagues and reporting procedures. Social engineering and phishing awareness prepares personnel to recognize manipulation attempts and respond appropriately.
Training should be documented with completion certificates, and access to specified information should be contingent on completing required training. Training effectiveness should be measured through testing, phishing simulations, and incident analysis.
Personnel Access Management
Managing personnel access throughout employment lifecycle is critical. The following principles and practices apply:
- Access provisioning follows formal request and approval process verifying need-to-know and authorization before granting access
- Least privilege principle provides only access necessary for job duties, not broad access "just in case"
- Role-based access groups personnel into roles with standardized access rather than individually customizing each person's access
- Access reviews periodically (quarterly or semi-annually) verify personnel still require their access and remove unnecessary permissions
- Privileged access for administrative or security-sensitive roles receives heightened oversight, monitoring, and restrictions
- Segregation of duties prevents single individuals from having access to perform high-risk activities alone—for example, personnel who approve transactions shouldn't also process them
- Need-to-know principle restricts access to specified information to personnel with legitimate business need, not merely job title or department
- Access changes when roles change require updating access to match new responsibilities and removing old access
Organizations should implement identity and access management systems that centralize access control and provide audit trails of access grants, changes, and revocations.
Monitoring and Insider Threat Detection
Organizations must monitor personnel for security concerns and potential insider threats. The following monitoring mechanisms are commonly implemented:
- User activity monitoring tracks what personnel do with specified information including what files are accessed, what actions are taken, what data is downloaded or transferred, and unusual access patterns
- Behavioral analytics establish baseline behavior for each user and alert on anomalies such as accessing unusual information, working at unusual times, downloading excessive data, or accessing systems shortly before resignation
- Physical security monitoring through badge access logs tracks personnel facility access including unauthorized area access attempts, unusual access times, or tailgating
- Security incident correlation connects personnel to security events for investigation
- Privileged user monitoring intensely logs and reviews actions by administrators and others with elevated access
- Peer reporting programs encourage personnel to report concerning behavior by colleagues, with protection for reporters
Organizations should document monitoring scope and purposes, inform personnel that monitoring occurs (reducing expectation of privacy), and use monitoring to detect threats early rather than assuming all personnel remain trustworthy indefinitely.
Monitoring should be proportional to risk and respect privacy appropriately—the goal is security, not surveillance.
Insider Threat Programs
Formal insider threat programs systematically address malicious or negligent insider risks. Key components include:
- Multi-disciplinary teams combine personnel from security, IT, HR, legal, and management to assess potential threats holistically
- Indicator identification defines concerning behaviors such as financial problems, workplace conflicts, policy violations, foreign contacts, attempts to access unauthorized information, or concerning statements
- Detection mechanisms including user activity monitoring, HR reports, manager observations, peer reports, and security tool alerts identify potential insider threats
- Risk assessment evaluates whether identified behaviors constitute actual threats requiring response or benign situations requiring no action
- Response procedures define how to investigate concerns, what interventions are appropriate (counseling, access restrictions, termination, law enforcement involvement), and documentation requirements
- Balance of security and privacy recognizing monitoring and assessment must be conducted ethically and legally
- Protection of sources ensures personnel reporting concerns aren't retaliated against
Organizations handling specified information should consider developing formal insider threat programs proportional to their size—even small programs demonstrate security maturity and reduce risk from trusted insiders who betray that trust.
Personnel Transfer and Termination
Access management during personnel changes is critical security control. Transfer processes when personnel change roles include the following:
- Review and adjustment of access to match new responsibilities
- Removal of old access no longer needed
- Re-training if new role has different security requirements
- Update of security records
Termination processes require the following actions:
- Immediate access revocation across all systems ideally within minutes of notification to prevent malicious acts during notice period
- Property return including issued devices, security badges, keys, documents containing specified information, and any organizational property
- Exit interviews discuss post-employment security obligations including continued confidentiality obligations, prohibition on retaining specified information, and consequences of violations
- Account deactivation across all systems, applications, VPNs, physical access, and third-party services
- Notification to relevant parties including IT, security, facilities, and managers of personnel with whom terminated individual worked
- Monitoring after termination for attempted access using old credentials or social engineering attempts
For high-risk terminations involving personnel with extensive access or terminated under adverse circumstances, organizations might implement enhanced monitoring, accelerate password resets, or conduct security reviews of areas terminated individual accessed.
Prompt and comprehensive termination procedures prevent common security incidents involving former employees accessing systems after departure.
Third-Party Personnel Security
Third-party contractors, subcontractors, and vendors with access to specified information require personnel security measures comparable to employees. Key requirements include:
- Contractual requirements flow personnel security obligations to third parties including screening requirements, training requirements, acceptable use policies, incident reporting obligations, and access revocation procedures
- Verification that third parties actually implement required measures through attestations, audits, or reviews
- Segregation of third-party access limits third-party personnel to systems and information necessary for their work, separate from employee access domains
- Monitoring of third-party personnel activity for security concerns and policy compliance
- Notification requirements obligate third parties to inform you of personnel changes, security incidents, or concerning behavior by their personnel with your access
- Termination coordination ensures when third-party personnel separate from vendor or complete assignments, your systems access is revoked
Organizations shouldn't assume third parties implement personnel security equivalent to yours—verify through contracts and oversight that third-party personnel meet security standards appropriate to specified information.
Personnel Security Documentation
Organizations must maintain comprehensive personnel security records. Required documentation includes:
- Screening documentation includes background check results, security clearances or eligibilities, screening approval decisions, and basis for approval
- Training records document what training was completed, when, and by whom—compliance depends on demonstrating required training occurred
- Access authorization records show what access was granted, when, based on what approval, and business justification
- Non-disclosure agreements signed by personnel
- Incident records involving personnel security concerns
- Termination records documenting access revocation, property return, and exit interviews
These records support compliance demonstration during CPCSC assessments, provide audit trails for investigation, and evidence that personnel security requirements are implemented.
Records containing personal information must be protected appropriately and retained according to privacy law requirements (typically at least two years after personnel separation). Organizations should implement systematic recordkeeping rather than ad-hoc files—identity management systems, HR systems, and training platforms can provide structured record management.
Personnel Security Challenges
Organizations face practical challenges implementing personnel security:
- Privacy laws and employment standards limit what screening can be conducted, how information can be used, and what employment decisions can be based on personal information—legal compliance is essential
- Costs of thorough background checks, particularly for small organizations or large workforces, can be substantial—risk-based approaches prioritize screening for highest-risk positions
- Time required for comprehensive screening can slow hiring when business needs are urgent—balancing security and agility requires planning ahead and potentially provisional access with supervision while screening completes
- Resistance from personnel to monitoring, screening, or restrictions based on privacy concerns or cultural sensitivities—communication emphasizing protection of specified information and national security can help
- Legacy employees hired before formal personnel security programs might not have been screened to current standards—retroactive screening or periodic re-screening addresses this
Organizations should develop personnel security programs appropriate to their size and risk while satisfying ITSP.10.171 requirements—programs can start small and mature over time.
Learn More
Additional resources on personnel security under CPCSC: