- Personnel Security
- The set of policies and procedures designed to ensure that individuals with access to organizational assets, data, or facilities meet defined trust and risk criteria.
- Background Check
- A pre-employment or periodic verification of a candidate's identity, criminal history, employment history, and credentials before granting access to sensitive roles.
- Insider Threat
- A security risk originating from a current or former employee, contractor, or partner who misuses authorized access β intentionally or negligently β to harm the organization.
- Least Privilege
- A security principle requiring that each user be granted only the minimum access rights necessary to perform their specific job function.
- Security Clearance
- A formal authorization β issued by an employer or government agency β permitting an individual to access classified, confidential, or sensitive information.
- Offboarding Controls
- The set of steps taken when an employee leaves β revoking system access, collecting credentials and devices, and briefing the individual on post-employment confidentiality obligations.
- Security Awareness Training
- Mandatory instruction that teaches employees to recognize and respond to threats such as phishing, social engineering, and data handling violations.
- Need-to-Know Basis
- An access-control principle limiting information sharing to individuals whose job responsibilities specifically require that information.
- Position of Trust
- A role that grants the occupant unusual access to sensitive assets, systems, funds, or data β typically requiring enhanced vetting before and during employment.
- Non-Disclosure Agreement (NDA)
- A legally binding contract requiring an employee or contractor to keep designated information confidential, often executed as part of onboarding.