The organisation sets personnel security requirements and roles for external providers, requires them to follow its personnel security policies, documents the requirements, requires providers to report transfers or terminations of their staff holding credentials, badges or privileges within a set time, and monitors compliance; it also screens private-sector organisations and individuals with access to Protected and Classified information, assets and facilities under the TBS Standard on Security Screening and defines government oversight and end-user roles for third-party services under the TBS mandatory procedures for security in contracts. No enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.