CISSP - Security and Risk Management (16% of the exam) - Section 1.8

Contribute to and enforce personnel security policies and procedures across the employment lifecycle and with vendors and contractors.

Describe personnel security controls across the full employment lifecycle - from candidate screening and onboarding through to termination - and extend these requirements to vendor agreements and contractor compliance policies. Recognise the security risks introduced at each lifecycle stage and the corresponding mitigation.

candidate screeningonboardingterminationvendor agreementscompliance policy

Practice question for this objective

Free sampleSecurity and Risk Managementmedium

A manufacturing company is preparing to sign a master services agreement with a third-party support vendor whose engineers will hold remote administrative access to production control systems. The procurement lead asks the security manager which clause matters MOST to include in the vendor contract from a personnel security perspective.

  • AA requirement that the vendor carry cyber liability insurance with a minimum coverage limit, to compensate the company if a vendor employee causes a breach.
  • BA clause obliging the vendor to apply background screening, onboarding, and offboarding controls to its assigned personnel that are equivalent to the company's own internal policy, with notification when assigned staff leave. Correct
  • CA right-to-audit clause permitting the company to inspect the vendor's premises and systems on reasonable notice once per year.
  • DA confidentiality clause requiring each vendor engineer to sign a non-disclosure agreement before being assigned to the account.
Flow personnel security requirements - screening, onboarding, and offboarding - into vendor contracts so that third-party staff meet the same baseline as employees. When a vendor's staff hold the same access as employees, the personnel security baseline must travel with the contract. Insurance, audits, and confidentiality clauses each have a role, but the primary risk reducer is the obligation to screen, onboard, and offboard assigned personnel to a defined standard and to notify the buyer when those personnel leave so that access reviews can keep pace. This is what closes the silent-leaver problem that audits and insurance alone cannot.

Why A is wrong: Insurance transfers some financial loss after the fact but does not reduce the probability of a personnel incident. It is a useful contract term but it is downstream of the actual controls on who the vendor allows near the production systems.

Why B is correct: This flows the personnel security baseline through the supply chain. It sets a measurable standard the vendor must meet for any individual touching the production systems, and the leaver notification clause closes the gap where the vendor's offboarding never reaches the company's access reviews. It is the manager-level control on which the other clauses depend.

Why C is wrong: Annual audits are a deterrent and a verification mechanism, but on their own they do not specify what good looks like. Without a separately defined standard for vendor personnel, an auditor walks in with nothing concrete to test against.

Why D is wrong: Non-disclosure agreements address what an engineer is permitted to say about what they see, not who the vendor is permitted to send. They are necessary, easy to obtain, and commonly already present, but they leave the screening and offboarding gaps untouched.

See more CISSP practice questions, answers explained.

Exam traps in Security and Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • Issuing the laptop, smart card, and physical site badge that the new hire needs to begin working on the segregated network.

    Why it is wrong: Provisioning the tools makes the person productive but does not by itself establish the legal and policy basis for handling classified material. Equipment without an accepted obligation creates capability without accountability.

  • Allow the start date to proceed and have the line manager supervise the new hire informally until the background check completes.

    Why it is wrong: Informal supervision is not a control: it is not documented, not measurable, and does not restrict the privileged access the role requires. It substitutes manager goodwill for an authorisation decision and is likely to be quietly dropped under workload pressure.

  • Document the situation as a formal risk acceptance, signed at the board level, and continue monitoring the threat landscape for active exploitation.

    Why it is wrong: Risk acceptance can be a valid response, but it is only defensible after the residual exposure has been quantified against the organisation's risk appetite and alternative treatments have been weighed. Recommending acceptance without that analysis pre-empts the very decision the board has asked the CISO to inform.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.