CMMC 2.0 • LEVEL 2 • PERSONNEL SECURITY

PS.L2-3.9.2Personnel Termination and Transfer

When individual employment is terminated: Disable system access within exit interview covering CUI obligations and NDA; retrieval of all credentials and property at separation; acknowledgment that CUI confidentiality obligations survive employment (minimum 2 years post-employment)CMMC/STIG, Terminate or revoke authenticators and credentials associated with the individual, and Retrieve security-related system property. When individuals are reassigned or transferred to other positions in the organization: Review and confirm the ongoing operational need for current logical and physical access authorizations to the system and facility, and Modify access authorization to correspond with any changes in operational need.

NIST 800-171 Mapping

NIST 800-53 Controls

Assessment Objectives

  • upon termination of individual employment, system access is disabled within exit interview covering CUI obligations and NDA; retrieval of all credentials and property at separation; acknowledgment that CUI confidentiality obligations survive employment (minimum 2 years post-employment)CMMC/STIG.
  • upon termination of individual employment, authenticators associated with the individual are terminated or revoked.
  • upon termination of individual employment, credentials associated with the individual are terminated or revoked.
  • upon termination of individual employment, security-related system property is retrieved.
  • upon individual reassignment or transfer to other positions in the organization, access authorization is modified to correspond with any changes in operational need.
  • upon individual reassignment or transfer to other positions in the organization, the ongoing operational need for current logical and physical access authorizations to the system and facility is reviewed.
  • upon individual reassignment or transfer to other positions in the organization, the ongoing operational need for current logical and physical access authorizations to the system and facility is confirmed.

Practitioner Notes

Practitioner commentary coming soon.