- Build a termination checklist executed the day of separation: disable accounts, revoke tokens and sessions, recover devices and badges, and handle mail forwarding deliberately.
- Treat transfers as seriously as terminations — access accumulated across role changes is the quieter failure, and only a role-based review catches it.
- Make the HR-to-IT trigger reliable — an integration or a named handoff with a deadline. This requirement fails at the handoff far more often than at the disablement.
3.9.2 — Personnel action safeguards
3.9 Personnel Security · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.
Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.
NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A — Assessing Security Requirements for CUI ↗What this requirement is after
Departures and role changes are the moments access is most likely to be wrong. Terminations must disable accounts, cut active sessions, and recover credentials and equipment promptly; transfers must reshape access to the new role instead of letting it accumulate across careers.
Carried into Rev. 3 as 03.09.02 Personnel Termination and Transfer, which enumerates the actions — disabling system access within an organization-defined period, terminating authenticators, and retrieving security-related property.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- Completed termination checklists sampled against the HR separation list
- Directory records showing disablement timestamps relative to separation dates
- Access-review records confirming transferred personnel lost their prior roles' access
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this lands in Rev. 3
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |