PS-7 Third-Party Personnel Security: Same Vendor, Different Vetting

Two agencies. Same checklist answer: third-party personnel security is addressed under PS-7. Both used the same regional IT support vendor for help desk and on-site support. Both rated themselves compliant.

The auditor asked for documentation of the vendor personnel screening requirements and how they were verified.

Agency A explained that the vendor had its own HR department and conducted background checks on all employees. The service agreement required the vendor to comply with applicable laws. The LASO had not reviewed the vendor's screening process, had not specified what screening was required for personnel with CJI access, and had not obtained documentation that any specific individual had been screened to the standard the CJIS policy requires.

Agency B had addressed personnel security in the Security Addendum and in a supplemental agreement: personnel assigned to support the agency's CJI environment were required to have state and national fingerprint-based background checks through the appropriate channels, to complete CJIS security awareness training before accessing CJI systems, and to be identified by name on a list the agency maintained. The agency had documentation for each named vendor employee showing screening completion and training status.

The auditor noted Agency A's finding: PS-7 requires the organization to establish personnel security requirements for third-party providers and to verify that providers meet those requirements. A general contractual obligation to comply with applicable law is not a personnel security requirement. A vendor HR policy is not verification.

What the control actually requires

PS-7 requires the organization to establish personnel security requirements including security roles and responsibilities for third-party providers, to require that third-party providers notify when personnel are transferred or terminated, and to monitor provider compliance with personnel security requirements.

For CJI access, the requirements are not general — they map to the same screening and training standards that apply to agency personnel. Vendor personnel who access systems processing CJI, who have physical access to areas where CJI is processed, or who can access CJI through administrative or support functions are within scope.

What the auditor is looking for

Written personnel security requirements specified in the agreement or addendum for vendor personnel. Documentation that named personnel have met the screening and training requirements. A process for receiving notification when vendor personnel change. Evidence that compliance is monitored rather than assumed.

A vendor's promise to comply is not documentation of compliance. The agency's obligation is to verify, not to trust.

The common failure mode

The vendor was selected based on qualifications and price. The contract required compliance with applicable law. The LASO assumed that the vendor's internal HR process met the required standard. Nobody specified what the standard was or asked for documentation that the specific individuals accessing the agency's systems had met it. The vendor's team changed over time. New personnel were assigned without the agency knowing.

PS-7 is about named individuals, documented screening, and verified compliance — not vendor-level promises.

## PUBLICATION NOTES

Format for each pair: Publish as standalone pages under `/resources/use-cases/` or as a separate section of the Knowledge Center. Each pair links to the corresponding Knowledge Center article where one exists.

Cross-links: - AC-2 pair → `/resources/attestation-is-not-assurance` - AT-3 pair → `/resources/what-role-based-cjis-training-actually-requires` - AU-6 pair → `/resources/what-au-6-requires-and-who-owns-it` - CA-7 pair → `/resources/cjis-compliance-clocks` - IR-6 pair → `/resources/the-one-hour-reporting-requirement` - SC-28 pair → `/resources/protecting-cji-at-rest-what-sc-28-requires` - SA-9 pair → `/resources/what-a-csa-audit-asks-for`

Canonical: `https://cjis360.us/resources/use-cases/[slug]`

SEO metadata to follow in the metadata package update.

The cjis360.com /resources page can point to these pairs as the practical companion to the policy-level articles — "how the policy requirements play out in practice."

Written by Dr. Alexis W. Perdereaux-Weekes

DBA · CISA · CISM · CRISC · CDPSE

Founder, CJIS360 LLC


Sources: CJIS Security Policy v6.1, 06/25/2026 — PS-7 External Personnel Security; §1.4 Terminology Used in This Document.

Questions about how this applies to your agency: agency@cjis360.com

Back to the Knowledge Center