Cyber Resilience

NIST 800-53 r5 · Controls catalogue · Family PS

PS-4Personnel Termination

Upon termination of individual employment: Disable system access within {{ insert: param, ps-04_odp.01 }}; Terminate or revoke any authenticators and credentials associated with the individual; Conduct exit interviews that include a discussion of {{ insert: param, ps-04_odp.02 }}; Retrieve all security-related organizational system-related property; and Retain access to organizational information and systems formerly controlled by terminated individual.

Last updated: 22 August 2026 07:11 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (0)

Weaknesses this control addresses (6)AI-assisted

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control6,900+Disabling all system access and revoking credentials upon termination directly prevents improper access control by former personnel.
CWE-287Improper Authentication5,200+Revoking authenticators and credentials eliminates the ability of terminated individuals to authenticate using prior mechanisms.
CWE-269Improper Privilege Management3,400+Explicit revocation of privileges and access rights addresses improper privilege management after employment ends.
CWE-522Insufficiently Protected Credentials1,600+Terminating or revoking credentials stops use of insufficiently protected or lingering credentials post-termination.
CWE-285Improper Authorization1,500+Terminating authorizations and privileges ensures that access rights no longer apply to the individual, reducing improper authorization risks.
CWE-250Execution with Unnecessary Privileges300+Disabling access and retrieving security-related property prevents continued execution with unnecessary privileges by ex-employees.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2023-26689 7.49.80.0062partial
CVE-2025-647257.29.80.0035partial
CVE-2025-7972 6.99.10.0050partial
CVE-2026-356386.48.80.0029partial
CVE-2024-48853 6.39.00.0037partial
CVE-2026-564286.08.10.0028partial
CVE-2024-28020 5.68.00.0037partial
CVE-2024-58105 5.37.30.0016partial
CVE-2024-27269 5.16.80.0043partial
CVE-2025-635635.06.50.0025partial
CVE-2026-601354.96.50.0021partial
CVE-2024-46671 4.86.20.0042partial
CVE-2024-29296 4.75.30.0124partial
CVE-2024-45425 3.94.90.0031partial
CVE-2023-51750 3.74.60.0029partial
CVE-2024-52359 3.64.30.0030partial
CVE-2024-13041 3.54.20.0028partial
CVE-2024-6356 3.34.40.0019partial
CVE-2024-9312 5.27.50.0028partial
CVE-2022-35503 5.77.50.0054partial

Other controls in family PS

PS-1 PS-2 PS-3 PS-5 PS-6 PS-7 PS-8 PS-9