Chapter 4 establishes preventive security measures starting with access control + personnel security. 4.1 Measures Relating to Access Control - each State shall establish + implement measures to prevent unauthorised persons + vehicles + items from gaining access to airside areas + security restricted areas (SRAs); identification of persons authorised to access airside + SRAs through aviation security identification card (ASIC) or equivalent + photo + name + employer + access privilege + expiry + revocation; biometric or PIN access controls for SRAs; vehicle access controls + screening + escort; access boundary protection + perimeter fencing + gates + lighting + CCTV + monitoring + intrusion detection; ramp + boarding bridge + jet bridge + tarmac. 4.2 Measures Relating to Personnel - each State shall ensure that persons implementing security controls are subject to background check before being authorised to access airside or SRAs without escort; background check covers identity + criminal history + employment + financial + reference + residence + intelligence vetting (per national programme); periodic re-investigation + adverse event tracking + insider threat detection + behavioural observation + continuous evaluation; identity verification + ASIC issuance + revocation; visitor + contractor + service supplier escort; cleaner + catering + ground handler + fuel handler personnel access; foreign worker considerations. Coordinates with ICAO Doc 8973 + national intelligence + national vetting authority + EU Reg 2015/1998 + FAA Aviation Worker Vetting + IATA Insider Threat + GASeP PO5 Insider Threat. ICAO Annex 17 Chap 4 + Access Control + Airside + SRA + Personnel + Background + Insider Threat applies.
This control maps to 37 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.