NIST Cybersecurity Framework 2.0
GV - Govern

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RR-04: Cybersecurity is included in human resources practices

Cybersecurity is included in human resources practices. Control from NIST Cybersecurity Framework 2.0 framework, domain: GV - Govern.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 101 controls across 35 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

ISO 27001:2022 · 7 controls

  • 5.11 Return of assets
  • 6.1 Screening
  • 6.2 Terms and conditions of employment
  • 6.3 Information security awareness, education and training
  • 6.4 Disciplinary process
  • 6.5 Responsibilities after termination or change of employment
  • 6.6 Confidentiality or non-disclosure agreements

C5 (Germany) · 6 controls

  • C5-AM-05 Commitment to Permissible Use, Safe Handling and Return of Assets
  • C5-HR-01 Verification of qualification and trustworthiness
  • C5-HR-02 Employment terms and conditions
  • C5-HR-04 Disciplinary measures
  • C5-HR-05 Responsibilities in the event of termination or change of employment
  • C5-HR-06 Confidentiality agreements

ISO 27002:2022 · 6 controls

  • 5.11 Return of assets
  • 6.1 Screening
  • 6.2 Terms and conditions of employment
  • 6.4 Disciplinary process
  • 6.5 Responsibilities after termination or change of employment
  • 6.6 Confidentiality or non-disclosure agreements

FedRAMP High · 5 controls

  • PS-1 Policy and Procedures
  • PS-2 Position Risk Designation
  • PS-3 Personnel Screening
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer

FedRAMP Moderate · 5 controls

  • PS-1 Policy and Procedures
  • PS-2 Position Risk Designation
  • PS-3 Personnel Screening
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer

HIPAA Security Rule · 4 controls

ISO 27701:2019 · 4 controls

  • 6.4 Human resource security
  • 6.4.1 Prior to employment
  • 6.4.2 During employment
  • 6.4.3 Termination and change of employment

NIST SP 800-66 Rev 2 · 4 controls

PCI DSS 4.0 · 4 controls

  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 12.7.1 12.7.1 Pre-hire screening of personnel with CDE access
  • 8.2.5 8.2.5 Terminated users' access revoked immediately
  • 9.3.1.1 9.3.1.1 Personnel access to sensitive areas controlled

SOC 2 · 4 controls

  • SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
  • SOC2-CC1.5 CC1.5 Accountability for internal control responsibilities (COSO principle 5)
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • ISM-0430 Same-day removal of access
  • ISM-0434 Screening and clearances before access
  • ISM-2003 Awareness of cyber workforce and skills gaps

CIS Controls v8 · 3 controls

  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-171 Rev 3 · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-P30 Independence and Skill of Testing Personnel
  • CPS234-P33 Skill of Personnel Providing Control Assurance

CMMC 2.0 · 2 controls

NIS2 Directive · 2 controls

  • Art.20.2 Train the management body, and offer equivalent training to staff on a regular basis
  • Art.21.2.i Human resources security, access control policies and asset management

NIST SP 800-172 · 2 controls

  • 3.9.1e Enhanced Personnel Screening
  • 3.9.2e Insider Threat Program

NIST SP 800-181 · 2 controls

  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures

APPI · 1 control

  • ASD37-37 Personnel management (Very Good)
  • AUCDR-IS-6 Information security training and awareness program
  • ITSG33-PS Personnel Security (PS)

ISO 22301:2019 · 1 control

ISO/IEC 42001:2023 · 1 control

  • PR.IP-11 PR.IP-11: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening)
  • PR.IP-11 PR.IP-11: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GV - Govern

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-GV.RR-04 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 101 it maps to, and the evidence behind each claim, over MCP and REST.