Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.9.2OFFICIAL STATEMENT BELOWBASIC REQUIREMENTPENDING NIST SME REVIEW

3.9.2Personnel action safeguards

3.9 Personnel Security · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Departures and role changes are the moments access is most likely to be wrong. Terminations must disable accounts, cut active sessions, and recover credentials and equipment promptly; transfers must reshape access to the new role instead of letting it accumulate across careers.

Across revisions

Carried into Rev. 3 as 03.09.02 Personnel Termination and Transfer, which enumerates the actions — disabling system access within an organization-defined period, terminating authenticators, and retrieving security-related property.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Build a termination checklist executed the day of separation: disable accounts, revoke tokens and sessions, recover devices and badges, and handle mail forwarding deliberately.
  • Treat transfers as seriously as terminations — access accumulated across role changes is the quieter failure, and only a role-based review catches it.
  • Make the HR-to-IT trigger reliable — an integration or a named handoff with a deadline. This requirement fails at the handoff far more often than at the disablement.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Completed termination checklists sampled against the HR separation list
  • Directory records showing disablement timestamps relative to separation dates
  • Access-review records confirming transferred personnel lost their prior roles' access
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated