Screen Individuals
Practice statement
Screen individuals prior to authorizing access to organizational systems containing CUI.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.9.1.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(1)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
individuals are screened prior to authorizing access to organizational systems containing CUI.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
PS.L2-3.9.1Screen Individuals
Screen individuals prior to authorizing access to organizational systems containing CUI.
[a]
individuals are screened prior to authorizing access to organizational systems containing CUI.
Screening clears before the enclave group is granted, not after the start date
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses the Screen Individuals objective: individuals are screened before access to systems containing CUI is authorized.
Screening standard. A written standard defines what screening means for each population and where the requirement comes from: identity verification and employment eligibility for everyone; a criminal history check covering the jurisdictions of residence for the last seven years, employment verification, and education verification where the role claims it, for anyone who will hold enclave access; and a re-check on the same scope every five years or on a role change into the enclave. Where a customer contract imposes more — citizenship or an export-control determination for specific programs — the standard names the contract requirement rather than restating it as a general rule.
Sequencing, which is the whole control. Access requests for the enclave group carry a screening status field populated from the HRIS. The workflow will not route for approval, let alone fulfillment, until that field reads cleared with a date. A new hire can start, take training, and use general corporate systems while screening is pending; the enclave group, the CUI libraries, and the badge zone that covers the engineering floor all wait. Decoupling start date from enclave access is what let us hold the line, because the pressure to let someone start is real and the pressure to let them into CUI on day one usually is not.
Adjudication. Results go to HR, not to the hiring manager. A hit is adjudicated against documented criteria — relevance to the role, how long ago, and the pattern — with legal involved and the applicable fair-hiring requirements followed. The adjudication decision, not the raw report, is what the access workflow sees. Reports are retained by HR with access limited to two people, since a background report is itself sensitive personal information.
Subcontractors and temporary staff. Subcontract language requires the sponsor to screen to our standard and to certify it per individual before we issue a badge or an account. We accept the certification rather than the underlying report, and we say so plainly; the certification names the standard met and the date. Staffing-agency personnel are handled the same way.
Maintenance. Quarterly reconciliation of enclave group membership against cleared screening records — anyone in the group without a current record is investigated as a process failure and removed pending resolution. Annual review of the standard against current contract requirements. Re-screening due dates tracked in the HRIS with reminders at 90 days.
Accepted gap. Screening tells us about someone's history up to the check date; it does not surface a change occurring afterward, and there is no continuous evaluation service in place for this population. The compensating measures are the five-year re-check, the insider threat awareness and reporting program, and the requirement that subcontractor sponsors notify us of relevant personnel actions.
What the evidence looks like
- Written screening standard with scope by population and the contract references
- Access request workflow configuration showing the screening status gate
- Sample completed request with screening cleared date preceding the access grant date
- Adjudication procedure and a redacted adjudication record
- Subcontractor screening certifications and the quarterly membership reconciliation
Environment
~300 staff plus a rotating set of subcontractor engineers. The contract requires screening for anyone who touches CUI, and the old process granted access on day one and chased the background check afterward.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.