TechKnowSurge
NIST 800-53 PS-2 NIST 800-53 PS-3 NIST 800-53 PS-4 ISC2 CISSP 1.8 NIST 800-53 AC-5 NIST 800-53 AC-6 NIST CSF PR.AA-05 CompTIA Security+ 1.2
VideoSecurityFree

Personnel Management

Personnel management covers the full employee life cycle—from pre-hire screening and onboarding through active employment and eventual separation—with security playing a critical role at every stage. Understanding these phases helps security professionals protect organizational assets and reduce risk tied to human behavior.

Complete this video to capture a CTF flag worth 1 point.

About this video

Personnel management applies a structured life cycle model to employees, treating them as organizational assets that require deliberate management from the moment they are candidates through the day they leave the company. The life cycle consists of five phases—recruiting and hiring, onboarding, development, performance, and separation—and security teams have a defined role in each one. Before a candidate is hired, security helps set technical and role-based requirements and ensures that background checks are conducted to identify any history that could pose a risk relative to the responsibilities of the position being filled. Onboarding is widely recognized as the most consequential phase because the habits, awareness, and compliance behaviors established early tend to persist throughout employment. During this phase, accounts are provisioned according to least-privilege principles, equipment is issued and secured, and new employees receive training covering system usage, company policies and procedures, acceptable use, password standards, and broader security awareness. A structured development phase follows onboarding, during which the employee moves from partial proficiency to full performance readiness—a process that can take anywhere from a few weeks for less technical roles to a year or more for highly specialized ones. Many organizations use a formal probation period, often six months, to evaluate fit before an employee is considered fully integrated. Throughout the performance phase, security teams deliver ongoing and repeated training to account for evolving threats, updated policies, and the natural limits of human memory. Reinforcing security behaviors consistently is essential because a single lapse by one employee can expose the entire organization, regardless of how well everyone else is performing. Policies such as separation of duties, mandatory vacations, and job rotation serve both as operational controls and as deterrents against abuse or fraud. At separation, whether voluntary or involuntary, the priority is immediate de-provisioning of all accounts and access, recovery of company equipment, and an exit review to identify and close any residual vulnerabilities—steps that become especially urgent when a departure involves any degree of conflict or potential retaliation.

What you'll learn

What's covered

Personnel Management

Aligned to

NIST 800-53
PS-2 Position Risk Designation
PS-3 Personnel Screening
PS-4 Personnel Termination
AC-5 Separation of Duties
AC-6 Least Privilege
ISC2 CISSP
1.8 Contribute to and enforce personnel security policies and procedures
NIST CSF
PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
CompTIA Security+
1.2 Summarize fundamental security concepts.

Key terms

Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Separation of Duties
SoD
Separation of Duties is a security control principle requiring that critical or sensitive tasks be divided among multiple individuals to prevent fraud, collusion, and unauthorized actions by any single person.
Job Rotation
A personnel security control that moves employees between roles periodically to reduce the risk of fraud and uncover irregularities.
Mandatory Vacation
A policy requiring employees to take scheduled time away from their duties, allowing organizations to detect fraudulent or unauthorized activity in their absence.
Employee Lifecycle
The stages an employee progresses through within an organization, including candidate, onboarding, development, performance, and separation, each with associated security responsibilities.
Acceptable Use Policy
AUP
A documented policy that defines the rules and expectations for how employees and internal users may use organizational systems and resources. An AUP establishes the grounds for disciplinary or legal action if violated.
Role-Based Access Control
RBAC
An access control model that assigns permissions based on a user's role within an organization.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.

Topics

Personnel Security Employee Lifecycle Least Privilege Separation Of Duties Job Rotation Identity And Access Management Security Governance

Transcript

The employee life cycle

Just like any other asset, employees have a life cycle. There is a beginning part of their journey with the company, a middle part of the journey, and an end part of the journey. At the beginning you can see that we spend a lot of time starting out this journey with this employee, because it is the most critical part of the whole journey.

We are going to get into what our role is as security professionals in each part of this journey. There is a candidate phase, before the employee is even hired, where we want to set the stage to make sure that we are hiring the right employees. Then, once we hire them, we go through an onboarding process to bring them on board. But the development does not end at the end of that onboarding process; we want to continue investing a little more time and energy up front with these employees at the beginning, and that is the development phase. Once we pass the development phase we actually get some performance out of this employee, and this is where we get the true value out of the employee. Then at some point in time there is going to be a separation, where they move on from the company.

The employee life cycle is different from the account management life cycle. There are some differences between the two, although the two are really closely related. As part of the onboarding process we are going to be provisioning their account. We have to maintain and change manage the account that corresponds with them as an employee. And then there is the de-provisioning that correlates with the separation.

Recruiting and hiring

The first phase is the recruiting and hiring phase, where employees are not quite an employee yet but they are a candidate, and this is a critical part in choosing the right employee. We may want to have a say in what the technical and security requirements of these individuals are going to be, and then we use that as a guide and root out the ones that do not meet those requirements. This is also the point in time where we are going to carry out some sort of background check, to make sure that there is not a criminal history that might be a concern in regard to the position they are going to be holding within the company. So we want to have a say in this candidate process, to make sure that we are choosing the right candidates to move into being an actual employee.

Onboarding

Security and IT play a huge role in the onboarding process. We want to make sure that we are onboarding people correctly, and it has some benefits to it: improved retention, increased productivity, enhanced compliance, and stronger culture, by spending a lot of effort and time on this onboarding process. When I was a hiring manager, I made sure that the onboarding process was very smooth and very comprehensive to new employees, because it made a huge improvement in how the employee was going to perform for the extent of the time they were working for this company.

Some of what we want to focus on here is setting up the account and access management. I have a whole other module on account and access management, or identity and access management. We also want to be assigning and shipping equipment to them, making sure they have the right equipment and making sure it is secure. We are also going to be doing quite a bit of training and support during this process as well.

The onboarding training could consist of a lot of different things that we may want to add to make this employee successful. Some of the topics this might include are how to use the equipment we are giving them, certain systems that they are going to have access to, and how to access the help desk and other services. We are definitely going to want to train them on company policies, processes and procedures, and any other security topics that they need to be part of this company.

Development and performance

The development phase is after they have already been onboarded but they are still not 100% up to speed on what their job is and what they are going to be doing. The performance phase is where they are 100% up to speed on their role within the company and they are fully functioning, fully proficient in what they are doing.

There is a lot of effort in getting an employee up to speed in this development process. What I have found is that less technical positions might be a couple of weeks to a month, and more technical positions, if there is a lot to learn, might be a year or even a couple of years. That can get very expensive if it draws out for too long. So we have that development phase of getting them up to speed, and then the performance phase where they are actually doing their job.

In fact, a lot of companies will have a probation period. The probation period is from the point in time in which they get hired to the point in time where we feel like we have a well-developed employee, for the most part. A lot of companies will put a time frame of six months on this, so that you can make sure this is the right employee for that position. A lot of times there are limitations during this probation period, like they cannot take vacation time, or they are limited on how much vacation they can take. So a lot of companies will implement this probation period.

Ongoing training

So what do we do during these development and performance stages? We are going to have ongoing training, not just to get them up to speed, but because our brains are not perfect, so we want to make sure that we continually drive home security and that they understand what the security procedures, processes and standards are for the company. We do a lot of security awareness training, and there is going to be ongoing support during this time that we have to give them.

Some of this ongoing training is going to be new material, because things are constantly changing, security risks are constantly changing, and our policies and procedures are constantly changing, so we want to keep people up to speed on those. But in addition to that, we are going to repeat certain information, and this is really necessary because, number one, we start forgetting things, and number two, it also takes us a while to pick things up. By repeating certain topics and certain information we reinforce the things we are learning. What I have found is that certain employees are going to pick things up right away, or maybe even know them before they watch your training or go through some sort of training, while other employees are going to need to hear it again and again and again. So we need to make sure we keep up on training, and there are also other ways we can reinforce some of the behaviors to make sure that they are doing security correctly.

Really, a lot of this caters to the weakest link. A chain is as strong as its weakest link. That means you could have a whole chain of all of these links, but if you have one link that is really broken, that has a vulnerability to it, then that whole chain can fall apart, can come apart, can split at that weakest link. It is the same thing with security. Everybody could be doing their part, making sure they are maintaining secure access, making sure they are following policies and procedures, making sure they are being secure, but it just takes that one employee who leaves the gate open that allows that vulnerability for somebody to enter in and access things, and then all of us are vulnerable to just this one gate that is left open. That is why a lot of times we cater to this weakest link.

Policies and principles

One thing we want to update and make sure our employees are updated on is our policies. Some of those policies might include an acceptable use policy, AUP, the password policy, or an employee policy. These are dynamic documents that we want to update and change as things go, and we want to make sure that our employees are updated on these as well, that they understand what they are, and that they sign off on these different policies.

Here are some general principles and policies we may incorporate into our policies at our company. For instance, we could have a principle of least privilege. The idea behind this is that we limit access as much as we can, that we do not give access out to somebody unless they really need to have that access. And then on a similar, essentially access to certain information unless they need to know that information. We could also take the approach of separation of duties, where we separate out certain processes, so that having different people do different steps within the process can identify when there is some sort of abuse happening. Something that can help with that as well is mandatory vacations, and we could also practice something like job rotation.

Separation

Another critical part is the separation, where we need to make sure that the account is removed and access is removed, that we are getting equipment back, and perhaps even getting feedback so we can better our systems and services and continue to improve.

If an employee is exiting the company we call this a termination. I am not a big fan of this term, termination, but that is what the industry standard is, calling this a termination or separation. What we really need to do is make sure that as somebody is exiting we are closing all of the doors that they had access to, to make sure that there are not any ongoing security vulnerabilities when somebody leaves. This can be very critical, especially if somebody is leaving and they have some sort of grudge against the company or want to take some sort of retaliation against the company, so the exit part of this is pretty critical.

Although we have a role in each one of these steps, I will also say that a lot of times the security department or the IT department is in charge of pulling audits and pulling together information. There might be components within each one of these that we do not exactly have a first-hand role in, that we are not actually carrying out, that we are not actually having a say in. But what we do need is to pull audits for things like a SOC report. Maybe we are doing a SOC attestation, and so the security department might be leading this SOC attestation and need to pull together documents for this.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →