6
Personnel Security
6.1.1
Introduction
Employees are the most important asset for any organisation. However, staff
could also be potent threat sources and actors. Indeed, changes in national
information security policies worldwide have roots in high-profile accidental and
deliberate disclosures of sensitive national security and personal information.
Therefore, it is vital to reduce the likelihood of staff exploiting legitimate access
to critical infrastructure facilities, sites, information and staff for unauthorised use.
Personnel security is important in the context of defending the cyber supply
chain against State and industrial espionage threats. This section outlines the
steps that organisations that use, own and/or operate critical infrastructure must
take to establish the trustworthiness, integrity and reliability of individuals before
granting them access to sensitive information assets.
6.1.2
Personnel Security and Risk Management
The themes contained in “Part I – Security Governance” apply to the personnel
security functional area in the same way as information and physical security.
For example, the personnel security area requires a credible risk management
approach as follows. There are no guarantees in security. This is more so
concerning personnel security. It is impossible to guarantee that people would
always behave reliably. For example, honest individuals experience changes in
lifestyle, which could affect their reliability. Changes such as new spouses and
starting a family could put individuals under financial pressure challenging their
integrity. In other instances, reckless personal behaviour and entrapment could
increase susceptibility to blackmail. Therefore, organisations must follow the risk
management principle and the mandatory security requirement presented in part
1, to decide the level of acceptable personnel security risk at any given time. As
a result, mandatory minimum personnel security requirements are as follows:
6.2
Security Roles & Responsibilities
National legislation such as the Official Secrets Act, 1964 and newer laws such
as the Computer Misuse Act, 2011 generally aim to reduce unlawful misuse of
information, in particular that has been entrusted in confidence to Government
officers, employees and contractors. However, it is difficult to enforce such laws
in Courts of Law if organisations fail to demonstrate that employees, contractors
and third party users understood their responsibilities. Achieving the mandated
minimum information security outcomes below would help an organisation show
that it has taken due care to ensure that the individuals understand expectations.
PS1 – To reduce the risk of theft, fraud or misuse of facilities, organisations
must ensure that all users understand their information security responsibilities.
As a minimum requirement, organisations must: (a) communicate security
expectations to all employment candidates; (b) include security duties in the
employment contracts that all staff must agree and sign; (c) require staff to sign