A.6.1 People
Screening
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (14)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-3mostlyaligns with — Both controls require background screening of personnel before granting access to organizational systems or sensitive information, with the depth of checks scaled to role criticality.
- PS-2partialaligns with — The ISO guidance to perform more detailed verifications for critical roles is consistent with the risk-based assignment of position risk designations that drive screening rigor.
- PS-4partialaligns with — The ISO control’s provisions for delayed onboarding, reduced access, or termination when screening is incomplete or unsatisfactory directly support the personnel termination and access revocation objectives of PS-4.
- PS-7partialaligns with — The ISO requirement to embed screening obligations in supplier contracts when personnel are obtained through external providers maps to the external personnel security expectations of PS-7.
- PS-7partialcovers — A.6.1 screening of personnel for eligibility/suitability addresses a slice of PS-7's broader external-provider personnel-security requirements (roles, compliance, documentation, notifications), but leaves the bulk of the target's external-provider obligations uncovered.
- PS-9partialaligns with — Screening criteria and role-specific competence and trustworthiness requirements in the ISO control align with the need to define position descriptions that establish the security responsibilities and qualifications for each role.
- PS-2governs — A.6.1's screening policy directly mandates the personnel-risk domain that PS-2's position-risk designation and screening-criteria requirements operationalize
- PS-3governs — A.6.1 directly names and requires personnel screening to ensure eligibility and suitability before and during employment, which is exactly the subject and requirement stated in PS-3.
- PS-9governs — A.6.1's screening policy explicitly governs the personnel domain that position descriptions (including security/privacy roles) sit inside; the target is reached by subject membership rather than explicit citation.
Aligned NIST CSF 2.0 outcomes (15)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.RR-04fullcovers — The ISO control establishes pre-employment screening, competence verification, and periodic re-checks as part of HR practices to ensure personnel trustworthiness and suitability for security roles.
- GV.RR-02mostlyaligns with — By defining who performs screening, when it occurs, and the criteria used, the control operationalizes the assignment and communication of cybersecurity-related HR responsibilities.
- GV.SC-05mostlyaligns with — The control requires that screening obligations for supplier-provided personnel be written into contracts, thereby embedding personnel-risk controls into third-party agreements.
- ID.RA-10partialaligns with — Screening of candidates for critical roles and supplier staff contributes to the pre-acquisition assessment of critical suppliers by validating the trustworthiness of the people who will deliver services.
- PR.AA-01partialaligns with — Verifying identity and confirming suitability before granting access supports the management of identities and credentials for authorized personnel.
- GV.RR-02covers — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- GV.SC-05covers — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.RA-10governs — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.RA-10implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-01covers — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Mitigated MITRE ATT&CK techniques (51)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.