NIST SP 800-53 Revision 5.1 HIGH PS-3: Personnel Screening
Screen individuals prior to authorizing access; rescreen at FedRAMP frequency per position risk; US citizenship may apply.
What else in your programme already covers this
This control maps to 25 controls across 20 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST800-SA-21 Developer Screening. Require that the developer of [organization-defined]: Has appropriate access authorizations as determined by assigned [organization-defined] ; and Satisfies the following additional personnel screening criteria: [organization-defined]