6 Personnel Security 6.1.1 Introduction Employees are the most important asset for any organisation. However, staff could also be potent threat sources and actors. Indeed, changes in national information security policies worldwide have roots in high-profile accidental and deliberate disclosures of sensitive national security and personal information. Therefore, it is vital to reduce the likelihood of staff exploiting legitimate access to critical infrastructure facilities, sites, information and staff for unauthorised use. Personnel security is important in the context of defending the cyber supply chain against State and industrial espionage threats. This section outlines the steps that organisations that use, own and/or operate critical infrastructure must take to establish the trustworthiness, integrity and reliability of individuals before granting them access to sensitive information assets. 6.1.2 Personnel Security and Risk Management The themes contained in “Part I – Security Governance” apply to the personnel security functional area in the same way as information and physical security. For example, the personnel security area requires a credible risk management approach as follows. There are no guarantees in security. This is more so concerning personnel security. It is impossible to guarantee that people would always behave reliably. For example, honest individuals experience changes in lifestyle, which could affect their reliability. Changes such as new spouses and starting a family could put individuals under financial pressure challenging their integrity. In other instances, reckless personal behaviour and entrapment could increase susceptibility to blackmail. Therefore, organisations must follow the risk management principle and the mandatory security requirement presented in part 1, to decide the level of acceptable personnel security risk at any given time. As a result, mandatory minimum personnel security requirements are as follows: 6.2 Security Roles & Responsibilities National legislation such as the Official Secrets Act, 1964 and newer laws such as the Computer Misuse Act, 2011 generally aim to reduce unlawful misuse of information, in particular that has been entrusted in confidence to Government officers, employees and contractors. However, it is difficult to enforce such laws in Courts of Law if organisations fail to demonstrate that employees, contractors and third party users understood their responsibilities. Achieving the mandated minimum information security outcomes below would help an organisation show that it has taken due care to ensure that the individuals understand expectations. PS1 – To reduce the risk of theft, fraud or misuse of facilities, organisations must ensure that all users understand their information security responsibilities. As a minimum requirement, organisations must: (a) communicate security expectations to all employment candidates; (b) include security duties in the employment contracts that all staff must agree and sign; (c) require staff to sign

Select target paragraph3