TechKnowSurge
NIST 800-53 PS-3 NIST 800-53 PM-12 NIST CSF GV.RR-04 ISC2 CISSP 1.8 NIST 800-53 AC-2 NIST 800-53 PS-4 NIST 800-53 PL-4 NIST CSF PR.AA-01
VideoSecurityFree

Personnel Management

Effective cybersecurity programs extend beyond technology into personnel management, influencing hiring practices to reduce insider threats and ensure trustworthy staff are placed in the right roles. This coverage examines how security teams contribute to onboarding, offboarding, background checks, and audit processes across an organization.

Complete this video to capture a CTF flag worth 1 point.

About this video

Staffing decisions are among the most consequential factors in an organization's security posture. No amount of awareness training or policy enforcement can fully compensate for individuals who consistently exhibit poor security habits or remain susceptible to social engineering — and those individuals represent a real and ongoing risk regardless of the resources directed at them. This makes personnel management a legitimate domain of cybersecurity responsibility, not just a function owned entirely by HR. Although cybersecurity teams rarely have final authority over hiring decisions in other departments, a well-structured security program secures meaningful influence over the process. This includes ensuring that candidate evaluations incorporate trustworthiness assessments and that background checks are treated as a security control rather than a formality. Insider threats are a recognized and serious risk category, and the hiring pipeline is one of the earliest opportunities to address that risk before it enters the organization. Cybersecurity's role in personnel management also extends to the full employee lifecycle. Onboarding and offboarding procedures intersect directly with security obligations — acceptable use policy acknowledgment, account provisioning, and access revocation all fall within the scope of a cybersecurity program. Beyond these operational touchpoints, security professionals frequently serve as internal auditors of HR-managed hiring processes, reviewing documentation trails and validating that established procedures are being followed consistently. That documentation is then made available to compliance evaluators and external auditors assessing the organization's overall security practices.

What you'll learn

What's covered

Personnel Management in Security

Aligned to

NIST 800-53
PS-3 Personnel Screening
PM-12 Insider Threat Program
AC-2 Account Management
PS-4 Personnel Termination
PL-4 Rules of Behavior
NIST CSF
GV.RR-04 Cybersecurity is included in human resources practices.
PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization.
ISC2 CISSP
1.8 Contribute to and enforce personnel security policies and procedures

Key terms

Acceptable Use Policy
AUP
A documented policy that defines the rules and expectations for how employees and internal users may use organizational systems and resources. An AUP establishes the grounds for disciplinary or legal action if violated.
Insider Threat
A security risk that originates from individuals who have authorized access to an organization's systems — such as employees, contractors, or partners — and misuse that access either maliciously or through negligence.
Identity and Access Management
IAM
A framework of policies and technologies that ensures the right users have appropriate access to resources.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Role-Based Access Control
RBAC
An access control model that assigns permissions based on a user's role within an organization.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.

Topics

Insider Threat Personnel Security Background Checks User Account Management Acceptable Use Policy Cybersecurity Governance

Transcript

One of the most important things that an organization can do to contribute to its success is hiring the right people and putting them in the right spot, and that is no different when it comes to security. It is really important that you find the right people and put them into the right spot. I have seen certain individuals within a company that have opened up the company for the most risk, that is, no matter what awareness and training that you put in front of them and how many times you talk to them, they still have bad practices when it comes to cyber security and fall for the same scams.

Usually there is not a say on who gets hired for other departments. However, it is critical that a proper cyber security program at least has some input and some control over the hiring process.

Roles In Personnel Management

Here are some of the roles that the cyber security program may have in personnel management. For one, the onboarding and offboarding process. One of the things that gets signed is an acceptable use policy, and usually that falls under IT or a cyber security program. There is also this account management aspect of it, and the cyber security awareness and training.

What I have found is that during this hiring process there is an evaluation of the person and usually some sort of background check. So that is part of the aspect of a cyber security program: it needs to make sure that there are components that are looking at that person's trustworthiness within the company. Insider threats can be a real problem, so making sure that there is an amount of security with hiring the right people.

Auditing The Hiring Process

Also, what I have had to do is be an auditor for that hiring process. HR really has the primary control over that hiring process. However, I have come in with the SOC attestations and said, okay, what have we been doing, where is the documentation for this? And then I turn this over to the evaluators, to the auditors, so they can evaluate our processes. So that is the role that I have played in personnel management when it comes to other departments and hiring in general.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →