GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

HRS-001 Personnel Security Policy

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented personnel security policy exists, covering pre-employment screening, terms and conditions of employment, information security obligations during employment, and requirements on termination. The policy is communicated to all personnel and reviewed at defined intervals.

Rationale

People are both a critical control and a primary risk vector. A documented policy establishes the expected security behaviours and obligations throughout the employment lifecycle, providing the baseline for consistent enforcement.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (7)

HRS-09Personnel Roles and Responsibilitiesinformative
HRS-09Personnel Roles and Responsibilitiesinformative
6.2Terms and conditions of employmentinformative
NIS2-Art.21.2.iHuman Resources Security, Access Control and Asset Managementpartial
NIS2-CIR-10.2Verification of Backgroundinformative
AT-1Policy and Procedurespartial
PS-1Policy and Proceduresfull

Evidence (2)

policydocumentmanual

Personnel security policy covering pre-employment, employment obligations, and termination requirements, approved by management and communicated to all personnel.

Example: Personnel Security Policy (Confluence / policy management system), covering: background screening requirements, security obligations during employment, disciplinary consequences, termination procedures, and acknowledgement requirement, with named approver and approval date.

Test: Request the personnel security policy. Verify: (1) pre-employment screening requirements are stated, (2) ongoing employment security obligations are described, (3) termination and exit requirements are included, (4) the policy is approved by a named executive within the last 12 months, (5) evidence of communication to all staff exists (all-staff email, intranet, onboarding workflow).

system_exporttechnicalautomated

Policy acknowledgement records confirming personnel have received and acknowledged the personnel security policy.

Example: Personnel security policy acknowledgement export from HRIS or training platform (BambooHR / Workday / KnowBe4), showing name, acknowledgement date, and policy version for all active employees.

Test: Export acknowledgement records. Verify: (1) all active employees have a recorded acknowledgement of the current policy version, (2) acknowledgement date is at or before the date of first system access for newer employees, (3) any gaps have an open remediation ticket.

Questions (3)

boolean

Does your organisation have a documented personnel security policy?

The policy should span the full employment lifecycle, from background screening before hire through to offboarding obligations, and be approved and communicated to all staff.

select

How do you confirm all personnel have received and acknowledged the personnel security policy?

Digital acknowledgement tracked in HRIS or training platform with a completion reportAcknowledgement captured in signed employment agreementCommunicated but acknowledgement is not formally trackedPolicy has not been formally communicated to all staff

An acknowledgement export showing all active employees with a recorded acknowledgement date at or before their first day of system access is the expected evidence.

multi

Which of the following does the personnel security policy cover?

Pre-employment screeningTerms and conditions of employmentInformation security obligations during employmentRequirements on terminationA named owner and a defined review intervalNone of the above

Options run from the most commonly covered to the least. A policy covering hiring and nothing else leaves the two points of highest risk, role change and departure, without a stated obligation.