ATO Digital Service Provider (DSP) Operational Security Framework
Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

ATO Digital Service Provider (DSP) Operational Security Framework SEC.PERSONNEL: Personnel security for hiring, managing and terminating staff and contractors

DSPs have processes and procedures for hiring, managing and terminating employees, contractors and non-employees, particularly those with access to back-end software or data, to mitigate trusted-insider threats: for example identity proofing or pre-employment screening, previous employment checks, police checks, employee obligations and separation activities. Micro DSPs are exempt unless contractors or non-employees have access to source code or in-scope data (the web guidance defines micro as one or two employees, the September 2025 questionnaire as up to three).

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ISM-0430 Same-day removal of access
  • ISM-0434 Screening and clearances before access

ISO 27002:2022 · 2 controls

  • 6.1 Screening
  • 6.5 Responsibilities after termination or change of employment

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.