# PS-09 Position Descriptions

NIST SP 800-53 control. Family: PS Personnel Security. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Incorporate security and privacy roles and responsibilities into organizational position descriptions.
Guidance: Specification of security and privacy roles in individual organizational position descriptions facilitates clarity in understanding the security or privacy responsibilities associated with the roles and the role-based security and privacy training requirements for the roles.

## Patterns that use it (1)
- Important (1): SP-018 Information Security Management System

## Clauses by framework (48 frameworks)
- iso_27001_2022: 5.3, A.5.2, A.6.2. OSA's own, not in NIST's crosswalk: 5.3, A.6.2
- iso_27002_2022: 5.2, 6.2
- cobit_2019: APO07
- nist_csf_2: GV.RR-02, GV.RR-04. OSA's own, not in NIST's crosswalk: GV.RR-02
- soc2_tsc: CC1.4, CC1.5
- iso_42001_2023: A.2.3, A.3.2
- nis2: Art. 21(2)(i)
- apra_cps_234: Para 16-17, Para 18
- mas_trm: 3
- bsi_grundschutz: OPS.1.1.2, ORP.2
- anssi: Hygiene.4, Hygiene.7, Hygiene.11, SecNumCloud.8.1
- osfi_b13: B-13.1.1
- finma_circular: IV.B.a(48), IV.B.d(60)
- gdpr: Art.29, Art.32(4), Art.37(1), Art.39(1)
- dora: Art.5(4)
- bio2: 5.2, 6.2
- rbi_csf: ITGRCA.8, ITGRCA.24
- fisc: FISC.O8
- lgpd_bcb: BCB.Art.17, BCB.Art.17-Supp, LGPD.Art.41, LGPD.Art.47
- hkma_tme1: TME1.2.1, TME1.2.4
- cbb_tm: TM-1
- cbuae: CR-1
- nca_ecc: 1-4, 1-9
- qatar_nia: GV, HR
- sama_csf: 1.1, 1.5, 1.7
- uae_ia: T1, T5
- bog_cisd: CISD-II, CISD-XV
- bom_ctrm: 1.1, 1.2
- cbe_csf: GOV-1, GOV-2
- cbn_csf: Part1.1, Part1.2
- popia: s55, s56
- sa_js2: JS2-4
- bot_cyber: Ch1.1, Ch7.2
- cpmi_pfmi: CG.GOV
- ecb_croe: CROE.2.1.2
- ffiec_is: II.C.7, II.C.7(a)
- iosco_cyber: GOV-4
- sebi_cscrf: GV.RR
- cmmc_2: PS
- fca_sysc_13: SYSC 13.6.1, SYSC 13.6.3, SYSC 13.G.1
- iso_27799: 6.1, 6.2
- lloyds_ms: CRM.1, GOV.1, MS8.1
- nhs_dspt: NDG-1.2
- pra_ss1_23: P2.4
- solvency_ii: Art.42, DR.258
- csa_ccm_v4: HRS-10
- csa_aicm: HRS-10
- mica: Art.34(1), Art.54(1)
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/PS-09
- Clauses only: /api/v1/controls/PS-09?fields=mappings
- Page for people: /controls/ps-09/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
