1Overview
PS.L2-3.9.2 is the family's five-point requirement and it governs what happens when people leave or move. It requires that systems containing CUI be protected during and after personnel actions such as terminations and transfers, so that access does not linger after the person's need for it ends. It is a five-point requirement with three assessment objectives, and it cannot be deferred on a plan of action.
Access granted to a person has to be removed when that person's relationship to the organization changes. A termination that leaves accounts and credentials active creates a departed insider who can still reach CUI; a transfer that carries old access into a new role accumulates permissions the person no longer needs. This control requires that the system be protected through these personnel actions, which means having a process to terminate access and credentials, actually terminating them in step with the action, and protecting the system across transfers. Its five-point weight reflects that lingering access after departure is one of the most exploited insider gaps.
Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers.
The requirement covers the whole arc of a personnel action. There has to be a policy or process for terminating access and credentials when personnel actions occur; that termination has to actually happen consistent with the action, whether a departure or a transfer; and the system has to be protected during and after transfers, when access needs change rather than end. The three assessment objectives correspond to the process, its execution, and protection through transfers.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.9.2 into three objectives: establish the process, terminate access consistent with the action, and protect the system through transfers.
A policy and/or process for terminating system access and any credentials coincident with personnel actions is established. There is a defined way to remove access when personnel actions occur.
System access and credentials are terminated consistent with personnel actions such as termination or transfer. Access is actually removed in step with the action.
The system is protected during and after personnel transfer actions. Transfers do not leave excess access.
The three objectives are the process, its execution, and transfer protection. The common gap is at objective [b], where a process exists on paper but access is not actually terminated promptly, leaving active accounts for departed people. The assessor looks for all three: a process, its real execution, and protection through transfers.
3Failure Patterns
The failures are about access that outlives the person's need for it.
Accounts active after departure
A termination that does not remove access leaves a departed person able to reach CUI, one of the most exploited insider gaps. Terminating access consistent with the departure closes it.
Permissions accumulate on transfer
Transferring a person to a new role without removing old access lets permissions accumulate beyond need. Adjusting access on transfer protects the system through the change.
Process without prompt execution
A termination process that is slow or inconsistently applied leaves a window where departed access is still live. Access has to be terminated in step with the action, not eventually.
Credentials overlooked
Disabling an account while leaving other credentials, such as shared or system credentials the person knew, active leaves a path open. All the person's access and credentials have to be addressed.
4Ownership
This is a shared HR and IT control, coordinated so access changes track personnel actions.
| Role | Responsibility for this control |
|---|---|
| Human resources | Notifies IT of terminations and transfers so access changes can be made in step. Owns the personnel action trigger. |
| IT and system administrator | Terminates or adjusts access and credentials consistent with the personnel action. Owns the access change evidence. |
| Security or compliance lead | Establishes the process and confirms access is removed promptly and completely. |
5Tooling
The control is delivered by a personnel-action process linked to prompt access changes.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Termination and transfer process | A defined way to remove access coincident with personnel actions. |
| [b] | Account and credential deprovisioning | Actual termination of access in step with the action. |
| [c] | Role-based access review on transfer | Adjustment of access so transfers leave no excess. |
The caveat is that the process has to execute promptly and completely, addressing all of a person's access and credentials. A process that runs slowly, misses credentials, or is applied inconsistently leaves the gap the control targets. The assessor examines all three objectives, so the process, its prompt execution, and transfer protection all have to hold.
6Evidence
The satisfied version of 3.9.2 shows access removed or adjusted in step with personnel actions.
| Evidence | What it demonstrates |
|---|---|
| Termination and transfer process | Objective [a]. A defined process for access changes. |
| Access change records | Objective [b]. Access terminated consistent with the action. |
| Transfer access review | Objective [c]. Access adjusted on transfer. |
The evidence should show a defined process, records of access actually terminated in step with terminations, and access adjusted on transfers. The process together with the access change records is the clearest demonstration, and because this control cannot sit on a plan of action, the practice has to be real at the time of assessment.
Access should end when the need for it does
A departed person with a live account, or a transferred one carrying old permissions, is unneeded access to CUI, and this five-point control requires that the system be protected through those personnel actions. Linking HR events to prompt access changes is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.9.2. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.9.2[a] through 3.9.2[c]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing PS.L2-3.9.2 among the five-point basic security requirements. ecfr.gov