NIST 800-171 · Personnel Security
Requirement 3.9.2
- SPRS weight
- SPRS weight: 5
- POA&M eligibility
- Not POA&M-eligible
- Assessment objectives
- 3 assessment objectives
Official requirement text
Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers
Assessment objectives
Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.
- 3.9.2[a]a policy and/or process for terminating system access authorization and any credentials coincident with personnel actions is established.
- 3.9.2[b]system access and credentials are terminated consistent with personnel actions such as termination or transfer.
- 3.9.2[c]the system is protected during and after personnel transfer actions.
Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.