CMMC 2.0 • LEVEL 2 • PERSONNEL SECURITY
PS.L2-3.9.2 — Personnel Termination and Transfer
When individual employment is terminated: Disable system access within exit interview covering CUI obligations and NDA; retrieval of all credentials and property at separation; acknowledgment that CUI confidentiality obligations survive employment (minimum 2 years post-employment)CMMC/STIG, Terminate or revoke authenticators and credentials associated with the individual, and Retrieve security-related system property. When individuals are reassigned or transferred to other positions in the organization: Review and confirm the ongoing operational need for current logical and physical access authorizations to the system and facility, and Modify access authorization to correspond with any changes in operational need.
Assessment Objectives
- upon termination of individual employment, system access is disabled within exit interview covering CUI obligations and NDA; retrieval of all credentials and property at separation; acknowledgment that CUI confidentiality obligations survive employment (minimum 2 years post-employment)CMMC/STIG.
- upon termination of individual employment, authenticators associated with the individual are terminated or revoked.
- upon termination of individual employment, credentials associated with the individual are terminated or revoked.
- upon termination of individual employment, security-related system property is retrieved.
- upon individual reassignment or transfer to other positions in the organization, access authorization is modified to correspond with any changes in operational need.
- upon individual reassignment or transfer to other positions in the organization, the ongoing operational need for current logical and physical access authorizations to the system and facility is reviewed.
- upon individual reassignment or transfer to other positions in the organization, the ongoing operational need for current logical and physical access authorizations to the system and facility is confirmed.
Practitioner Notes
Practitioner commentary coming soon.