DSPs have processes and procedures for hiring, managing and terminating employees, contractors and non-employees, particularly those with access to back-end software or data, to mitigate trusted-insider threats: for example identity proofing or pre-employment screening, previous employment checks, police checks, employee obligations and separation activities. Micro DSPs are exempt unless contractors or non-employees have access to source code or in-scope data (the web guidance defines micro as one or two employees, the September 2025 questionnaire as up to three).
This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.