PS-05 Personnel Transfer

Control: The organization reviews information systems/facilities access authorizations when personnel are reassigned or transferred to other positions within the organization and initiates appropriate actions.

Supplemental Guidance: Appropriate actions that may be required include: (i) returning old and issuing new keys, identification cards, building passes; (ii) closing old accounts and establishing new accounts; (iii) changing system access authorizations; and (iv) providing for access to official records created or controlled by the employee at the old work location and in the old accounts.

Control Enhancements: (0) None.

Baseline: LOW PS-5 MOD PS-5 HIGH PS-5

Family: Personnel Security

Class: Operational

ISO 17799 mapping: 8.3.1, 8.3.3, 11.2.1

COBIT 4.1 mapping: PO7.8

PCI-DSS v2 mapping: 7.1.1