A.6.1 People
Screening
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PS-3mostlyaligns with — Both controls require background screening of personnel before granting access to organizational systems or sensitive information, with the depth of checks scaled to role criticality.
- PS-2partialaligns with — The ISO guidance to perform more detailed verifications for critical roles is consistent with the risk-based assignment of position risk designations that drive screening rigor.
- PS-4partialaligns with — The ISO control’s provisions for delayed onboarding, reduced access, or termination when screening is incomplete or unsatisfactory directly support the personnel termination and access revocation objectives of PS-4.
- PS-7partialaligns with — The ISO requirement to embed screening obligations in supplier contracts when personnel are obtained through external providers maps to the external personnel security expectations of PS-7.
- PS-9partialaligns with — Screening criteria and role-specific competence and trustworthiness requirements in the ISO control align with the need to define position descriptions that establish the security responsibilities and qualifications for each role.
Aligned NIST CSF 2.0 outcomes (9)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.RR-04fullcovers — The ISO control establishes pre-employment screening, competence verification, and periodic re-checks as part of HR practices to ensure personnel trustworthiness and suitability for security roles.
- GV.RR-02mostlyaligns with — By defining who performs screening, when it occurs, and the criteria used, the control operationalizes the assignment and communication of cybersecurity-related HR responsibilities.
- GV.SC-05mostlyaligns with — The control requires that screening obligations for supplier-provided personnel be written into contracts, thereby embedding personnel-risk controls into third-party agreements.
- ID.RA-10partialaligns with — Screening of candidates for critical roles and supplier staff contributes to the pre-acquisition assessment of critical suppliers by validating the trustworthiness of the people who will deliver services.
- PR.AA-01partialaligns with — Verifying identity and confirming suitability before granting access supports the management of identities and credentials for authorized personnel.
Mitigated MITRE ATT&CK techniques (3)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1078partialprevents — Screening and periodic re-verification of personnel lowers the chance that an attacker can obtain or maintain access through a trusted insider account.
- T1556partialmitigates — Verifying the trustworthiness and competence of candidates for security-critical roles makes it harder for an adversary to insert personnel who could later weaken authentication processes.
- T1589nonemitigates — Pre-employment identity and background verification reduces the likelihood that an adversary can place an insider with valid credentials into the organization.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.