NIST 800-53 REV 5 • PERSONNEL SECURITY
PS-6(3) — Post-employment Requirements
Notify individuals of applicable, legally binding post-employment requirements for protection of organizational information; and Require individuals to sign an acknowledgment of these requirements, if applicable, as part of granting initial access to covered information.
CMMC Practice Mapping
No direct CMMC mapping
NIST 800-171 Mapping
No direct NIST 800-171 mapping
Related Controls
Supplemental Guidance
Organizations consult with the Office of the General Counsel regarding matters of post-employment requirements on terminated individuals.
Practitioner Notes
Nondisclosure and access agreements should include clauses that extend obligations beyond employment. When someone leaves, they must understand that their duty to protect information continues.
Example 1: Include post-employment nondisclosure clauses in all access agreements. During exit processing, conduct a debriefing that reminds departing personnel of their continuing obligations and have them sign a separation statement acknowledging those obligations.
Example 2: For personnel leaving positions with access to classified information, conduct a formal security debriefing using the SF-312 as the reference document. Remind them that the nondisclosure obligation is permanent and have them sign the debriefing acknowledgment. File it in their security record.