CISSP - Security and Risk Management - Section 1.8

Contribute to and enforce personnel security policies and procedures across the employment lifecycle and with vendors and contractors.

Describe personnel security controls across the full employment lifecycle - from candidate screening and onboarding through to termination - and extend these requirements to vendor agreements and contractor compliance policies. Recognise the security risks introduced at each lifecycle stage and the corresponding mitigation.

candidate screeningonboardingterminationvendor agreementscompliance policy

Practice question for this objective

Free sampleSecurity and Risk Managementmedium

A manufacturing company is preparing to sign a master services agreement with a third-party support vendor whose engineers will hold remote administrative access to production control systems. The procurement lead asks the security manager which clause matters MOST to include in the vendor contract from a personnel security perspective.

  • AA requirement that the vendor carry cyber liability insurance with a minimum coverage limit, to compensate the company if a vendor employee causes a breach.
  • BA clause obliging the vendor to apply background screening, onboarding, and offboarding controls to its assigned personnel that are equivalent to the company's own internal policy, with notification when assigned staff leave. Correct
  • CA right-to-audit clause permitting the company to inspect the vendor's premises and systems on reasonable notice once per year.
  • DA confidentiality clause requiring each vendor engineer to sign a non-disclosure agreement before being assigned to the account.
Flow personnel security requirements - screening, onboarding, and offboarding - into vendor contracts so that third-party staff meet the same baseline as employees. When a vendor's staff hold the same access as employees, the personnel security baseline must travel with the contract. Insurance, audits, and confidentiality clauses each have a role, but the primary risk reducer is the obligation to screen, onboard, and offboard assigned personnel to a defined standard and to notify the buyer when those personnel leave so that access reviews can keep pace. This is what closes the silent-leaver problem that audits and insurance alone cannot.

Why A is wrong: Insurance transfers some financial loss after the fact but does not reduce the probability of a personnel incident. It is a useful contract term but it is downstream of the actual controls on who the vendor allows near the production systems.

Why B is correct: This flows the personnel security baseline through the supply chain. It sets a measurable standard the vendor must meet for any individual touching the production systems, and the leaver notification clause closes the gap where the vendor's offboarding never reaches the company's access reviews. It is the manager-level control on which the other clauses depend.

Why C is wrong: Annual audits are a deterrent and a verification mechanism, but on their own they do not specify what good looks like. Without a separately defined standard for vendor personnel, an auditor walks in with nothing concrete to test against.

Why D is wrong: Non-disclosure agreements address what an engineer is permitted to say about what they see, not who the vendor is permitted to send. They are necessary, easy to obtain, and commonly already present, but they leave the screening and offboarding gaps untouched.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security and Risk Management objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.