CMMC Practice PS.2.127
Screen individuals prior to authorizing access to organizational systems containing CUI.
Bold Coast Security Guidance
The organization will need to develop a policy in conjunction with Human Resources and your legal team. HR will provide appropriate guidance on when to get approval from potential hires to conduct the screenings, along with the correct procedures. The results should be kept with your HR department in their personnel file.
A key decision point will be when to re-evaluate or conduct additional checks. Will your company conduct checks only at hire, or repeat them every year? Every other year? Whatever the decision, be sure to put it in your policy.
DRAFT NIST SP 800-171 R2
Personnel security screening (vetting) activities involve the evaluation/assessment of individual’s conduct, integrity, judgment, loyalty, reliability, and stability (i.e., the trustworthiness of the individual) prior to authorizing access to organizational systems containing CUI. The screening activities reflect applicable federal laws, Executive Orders, directives, policies, regulations, and specific criteria established for the level of access required for assigned positions.