NIST 800-171 Controls · Personnel Security
PS.2.001 — Screen Individuals Before Granting Access
Screen individuals prior to authorizing access to organizational systems containing CUI.
What PS.2.001 means in plain English
Before giving any employee, temp worker, or contractor access to your computers and files that hold government contract information, you need to run a background check on them. This does not have to be expensive — a basic criminal and identity check is a solid start. The point is to make sure you are not handing the keys to someone with a history of fraud, theft, or security violations. Document who you checked and when.
The assessment question
“Do you conduct background screening (such as criminal history checks and identity verification) on all individuals before granting them access to systems or data containing CUI?”
How to implement PS.2.001
- Select a background screening provider such as GoodHire, Checkr, or Sterling — plans start around $30 per check and cover criminal history, identity verification, and employment history.
- Write a short Personnel Screening Policy that states all new hires and contractors must complete a background check before receiving any account credentials or physical access badges.
- Add background screening as a mandatory step in your onboarding checklist before IT creates their user account or issues an access badge.
- Store completed screening records (date completed, provider used, pass/fail result) in a locked personnel file — physical filing cabinet or encrypted digital folder.
Evidence your assessor will ask for
- Written Personnel Screening Policy stating screening is required before access is granted
- Completed background check records or certificates for each employee with CUI access
- Onboarding checklist showing background check step occurs before account provisioning
- Log or spreadsheet tracking screening dates, provider, and results for all personnel
Does AI prompt monitoring help with this control? Honestly, no.
PS.2.001 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Personnel Security controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.