Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.9.1OFFICIAL STATEMENT BELOWBASIC REQUIREMENTPENDING NIST SME REVIEW

3.9.1Personnel screening

3.9 Personnel Security · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Screen individuals prior to authorizing access to organizational systems containing CUI.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Before a person is authorized to touch systems holding CUI, the organization checks who they are. For most nonfederal companies this means employment screening — background and identity checks proportional to the role — wired into provisioning so that access follows a completed check rather than preceding it.

Across revisions

Carried into Rev. 3 as 03.09.01 Personnel Screening, with rescreening under organization-defined conditions made explicit.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Define what screening means for your organization and write it down — for most contractors, criminal-background and employment-verification checks at hire, not government clearances.
  • Tie screening completion into account provisioning so access to CUI-bearing systems cannot be granted before the check clears; a policy that HR runs and IT never sees is the common gap.
  • Cover the populations that skip normal onboarding: contractors, temporary staff, interns, and vendor personnel who receive system access.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The written screening standard and where it sits in the hiring and provisioning flow
  • Sampled records showing screening completed before CUI system access was granted
  • How screening is handled for non-employee populations with access
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated