Applicable (Y)es / (N)o |
(C)onfidentiality |
(I)ntegrity |
(A)vailability |
RPN (C+I+A) |
(S)atisfactory |
||||||
L1 |
M2 |
H3 |
L1 |
M2 |
H3 |
L1 |
M2 |
H3 |
(O)ther than satisfactory +## |
||
|
|
|
|
|
|
|
|
|
|
|
|
###
ps-4 |
personnel termination |
||
|
assessment objective: Determine if the organization, upon termination of individual employment,: |
||
ps-4(a) |
ps-4(a)[1] |
defines a time period within which to disable information system access; |
|
ps-4(a)[2] |
disables information system access within the organization-defined time period; |
||
ps-4(b) |
terminates/revokes any authenticators/credentials associated with the individual; |
||
ps-4(c) |
ps-4(c)[1] |
defines information security topics to be discussed when conducting exit interviews; |
|
ps-4(c)[2] |
conducts exit interviews that include a discussion of organization-defined information security topics; |
||
ps-4(d) |
retrieves all security-related organizational information system-related property; |
||
ps-4(e) |
retains access to organizational information and information systems formerly controlled by the terminated individual; |
||
ps-4(f) |
ps-4(f)[1] |
defines personnel or roles to be notified of the termination; |
|
ps-4(f)[2] |
defines the time period within which to notify organization-defined personnel or roles; and |
||
ps-4(f)[3] |
notifies organization-defined personnel or roles within the organization-defined time period. |
||
potential assessment methods and objects: Examine: [select from: Personnel security policy; procedures addressing personnel termination; records of personnel termination actions; list of information system accounts; records of terminated or revoked authenticators/credentials; records of exit interviews; other relevant documents or records]. Interview: [select from: Organizational personnel with personnel security responsibilities; organizational personnel with account management responsibilities; system/network administrators; organizational personnel with information security responsibilities]. Test: [select from: Organizational processes for personnel termination; automated mechanisms supporting and/or implementing personnel termination notifications; automated mechanisms for disabling information system access/revoking authenticators]. |