Under active development Content is continuously updated and improved

PS-3(1)Personnel Screening | Classified Information

IL6

>Control Description

Verify that individuals accessing a system processing, storing, or transmitting classified information are cleared and indoctrinated to the highest classification level of the information to which they have access on the system.

>DoD Impact Level Requirements

No specific parameter values or requirements for this impact level.

>Discussion

Classified information is the most sensitive information that the Federal Government processes, stores, or transmits. It is imperative that individuals have the requisite security clearances and system access authorizations prior to gaining access to such information. Access authorizations are enforced by system access controls (see AC-3) and flow controls (see AC-4).

>Related Controls

>Assessment Interview Topics

Questions assessors commonly ask

Process & Governance:

  • What policies govern classified information for organizational personnel?
  • Who is responsible for implementing and overseeing classified information controls?
  • How does the organization coordinate classified information with HR and legal teams?
  • What is the process for handling exceptions to classified information requirements?
  • What governance exists for ensuring consistent application of classified information across the organization?

Technical Implementation:

  • What systems or tools technically implement classified information?
  • How are classified information activities integrated with HR and identity management systems?
  • What automation supports classified information enforcement and tracking?
  • What audit capabilities exist for classified information?
  • How are classified information requirements technically enforced in access control systems?

Evidence & Documentation:

  • Provide documented policies and procedures for classified information.
  • Provide personnel records demonstrating classified information implementation.
  • Provide evidence of classified information for all personnel with system access.
  • Provide records of classified information reviews and updates.
  • Provide documentation of coordination between classified information and HR processes.

Ask AI

Configure your API key to use AI features.