ASD Strategies to Mitigate Cyber Security Incidents
Preventing Malicious Insiders

ASD Strategies to Mitigate Cyber Security Incidents ASD37-37: Personnel management (Very Good)

Personnel management including pre-employment checks, ongoing security awareness training, and management of disgruntled employees and departing personnel.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 103 controls across 47 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CMMC 2.0 · 5 controls

ISO 27002:2022 · 5 controls

  • 5.11 Return of assets
  • 6.1 Screening
  • 6.3 Information security awareness, education and training
  • 6.4 Disciplinary process
  • 6.5 Responsibilities after termination or change of employment

FedRAMP High · 4 controls

  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • PS-3 Personnel Screening
  • PS-4 Personnel Termination

FedRAMP Moderate · 4 controls

  • AT-2 Literacy Training and Awareness
  • AT-2(2) Insider Threat
  • PS-3 Personnel Screening
  • PS-4 Personnel Termination

HIPAA Security Rule · 4 controls

ISO 27001:2022 · 4 controls

  • 5.11 Return of assets
  • 6.1 Screening
  • 6.3 Information security awareness, education and training
  • 6.5 Responsibilities after termination or change of employment
  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

NIST SP 800-53 Rev 5 · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

PCI DSS 4.0 · 4 controls

  • 12.6.1 12.6.1 Formal security awareness program
  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 12.7.1 12.7.1 Pre-hire screening of personnel with CDE access
  • 8.2.5 8.2.5 Terminated users' access revoked immediately

C5 (Germany) · 3 controls

  • C5-HR-01 Verification of qualification and trustworthiness
  • C5-HR-03 Security training and awareness programme
  • C5-HR-04 Disciplinary measures

CIS Controls v8 · 3 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-14.9 Conduct Role-Specific Security Awareness and Skills Training
  • CIS-6.2 Establish an Access Revoking Process

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

UK Cyber Essentials · 3 controls

  • CE-AC.1 User Account Approval Process
  • CE-AC.3 Remove or Disable Accounts When No Longer Required
  • CE-SC.7 Educate Users on Strong Passwords
  • ANSSI-HYG-02 Raise User Awareness of Basic Security Practice
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures

SOC 2 · 2 controls

  • SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication
  • PA-3 Manage lifecycle of identities and entitlements
  • CJIS-2 Security Awareness Training

FDA 21 CFR Part 11 · 1 control

  • Part11.10 Controls for closed systems (21 CFR §11.10)
  • CAT-D1-4 Training and culture
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
  • HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media

ISO 27799:2025 · 1 control

  • ISO27799-09 Security awareness and training program
  • ISO28001-PI-02 Security Awareness and Training

ISO/IEC 27011:2024 · 1 control

  • 27011-6.3 Awareness and Training

MARS-E · 1 control

  • MDS2-Roadmap-Third-Party-RDMP-Security-Guidance-SGUD-SBOM-Vulnerability-Disclosure-Programme MDS2 Roadmap + RDMP + Third Party + Security Guidance + SGUD + SBOM + Vulnerability Disclosure + Coordinated
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-66 · 1 control

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • DSOMM-1 Culture, Organization, Education, and Governance
  • OMANCS-8 Third-Party + Supply Chain Risk, Awareness Training, Physical Security, Compliance Audit
  • PASONE-3 Personnel Security, Vetting, Awareness, and Training
  • UKGAMBLE-4 Resilience and Incident Response

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done?

ASD Strategies to Mitigate Cyber Security Incidents ASD37-37 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 103 it maps to, and the evidence behind each claim, over MCP and REST.