Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

SIAS v1.0 · Domain 16 of 19

WFS: Workforce security

People who work with in-scope systems and data are screened where the law allows and the role warrants it, know and accept their security obligations, are trained for common attacks and for their technical roles, and leave without taking access, assets or data with them.

About this domain

What this domain covers. Screening, security terms and acceptable use, sanctions, awareness and phishing training, role-based training, and the HR side of offboarding and role changes. Technical removal of access is tested under SIAS-IAM-01; third-party personnel supplied under contract are also covered by the TPR domain.

Terms used in this domain.

  • Personnel: employees, contractors, temporary staff and third-party individuals who have access to in-scope systems or to Restricted or other sensitive data (see SIAS-DAT-01).

Personal data minimization. SecurityInspect requests only what shows that a process ran: identifiers, role category, dates and completion status. It never requests the content of screening reports, reasons for separation, medical information, disciplinary details or information about protected characteristics. Where practicable, extracts use employee numbers instead of names, and the applicant keeps the key; analysts corroborate named records under observation without copying them.

SIAS does not assess employment law. SIAS checks that workforce processes exist, run and reach the right people. It does not assess whether an applicant's screening, monitoring or sanction practices comply with employment, privacy or consumer-reporting law. That is the applicant's responsibility, with its own counsel, and SIAS never requires a check that applicable law prohibits.

What the software evaluates and what needs human judgment. SecurityInspect's proprietary security-analysis software must join personnel rosters with acknowledgment, training, screening, access and asset records, and compute completion rates, timeliness and cadence. Analysts judge whether training content fits the organization and its technologies, whether phishing simulations are realistic, whether screening levels are reasonable for each role's risk, and whether sanctions are applied consistently. Automated results count toward a rating only after a technical tester confirms or rejects each result that affects it.

Controls in this domain

5 controls, 3 of them mandatory.

Controls in the WFS domain
ControlTitleMandatorySeverityApplies
SIAS-WFS-01Role-appropriate screeningNoMediumAll scopes (only as permitted by applicable law; SIAS never requires unlawful screening)
SIAS-WFS-02Security terms, acceptable use and sanctionsYesMediumAll scopes
SIAS-WFS-03Security awareness and phishing trainingYesMediumAll scopes
SIAS-WFS-04Role-based security training for technical and privileged staffNoMediumAll scopes
SIAS-WFS-05Offboarding and role changeYesHighAll scopes (HR-triggered process and asset return; technical deprovisioning is tested under SIAS-IAM-01)

SIAS-WFS-01 Role-appropriate screening

Mandatory
No
Severity
Medium
Applies
All scopes (only as permitted by applicable law; SIAS never requires unlawful screening)
SecurityInspect Verified profiles
None

Control objective

People given privileged access or access to sensitive data have been checked to a level that matches the risk of their role, within the law.

Testable requirement

  • The applicant must:
  • 1.define screening levels by role risk, with a higher level for roles that hold privileged access or access to Restricted data;
  • 2.complete the screening for a role's level before privileged access or access to Restricted data is granted, or record an interim restriction (for example supervised or limited access) until it is complete;
  • 3.screen only as permitted by applicable law, recording any role for which the applicant has determined that screening is not permitted;
  • 4.require, by contract, that suppliers of contractors and other third-party personnel who will hold such access screen them to the level the role requires, and obtain the supplier's confirmation for each person;
  • 5.screen again when a person moves to a role with a higher screening level;
  • 6.record completion (date and level) in a system of record, keeping screening results out of any records that SecurityInspect needs to see.

Applicability and scope

All scopes (only as permitted by applicable law; SIAS never requires unlawful screening). Where applicable law prohibits screening for a role, requirements 2 and 5 are met for that role by the recorded determination in requirement 3. Not part of any SecurityInspect Verified profile.

Pass criteria

  • 1.The policy defines screening levels by role risk, including a higher level for privileged and Restricted-data roles.
  • 2.Every holder of privileged or Restricted-data access completed screening before access, or was under an interim restriction or a recorded legal determination.
  • 3.Supplier contracts require screening, and confirmations exist for every sampled contractor.
  • 4.Every move to a higher-level role was followed by the required screening.

Severity

Medium. The global escalation rules apply.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(3)(ii)(B)
PCI DSS v4.0.1
12.7
Trust Services Criteria
CC1.4
ISO/IEC 27001:2022
A.6.1
Theme (SecurityInspect wording)
risk-based personnel screening

SIAS-WFS-02 Security terms, acceptable use and sanctions

Mandatory
Yes
Severity
Medium
Applies
All scopes
SecurityInspect Verified profiles
None

Control objective

Everyone with access knows their security obligations, has agreed to them, and knows that breaking them has consequences.

Testable requirement

  • The applicant must:
  • 1.include confidentiality and information-security obligations, including obligations that continue after the relationship ends, in employment terms, contractor agreements and agreements covering third-party personnel with access to in-scope systems or data;
  • 2.maintain an acceptable use policy covering in-scope systems and devices, data handling, credentials, personal devices (where allowed) and reporting of suspected security incidents;
  • 3.obtain each person's acknowledgment of the acceptable use policy before access is granted, again at least every 12 months, and after each material change to the policy;
  • 4.maintain a documented sanction process for security-policy violations and apply it consistently. The applicant decides outcomes; SIAS checks that the process exists and runs;
  • 5.track acknowledgments in a system of record.

Applicability and scope

All scopes. Covers all personnel. Not part of any SecurityInspect Verified profile.

Pass criteria

  • 1.Agreement templates include security and confidentiality obligations, including obligations that continue after the relationship ends.
  • 2.The acceptable use policy covers every topic in requirement 2.
  • 3.At least 98% of active personnel hold a current acknowledgment, and every sampled new starter acknowledged before access.
  • 4.The sanction process is documented and, where applied in the look-back period, was applied as written.
  • 5.Contractors and third-party personnel are covered by requirements 1 and 3.

Severity

Medium. The global escalation rules apply.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(1)(ii)(C), §164.310(b)
PCI DSS v4.0.1
12.2
Trust Services Criteria
CC1.1, CC1.5
ISO/IEC 27001:2022
A.5.10, A.6.2, A.6.4, A.6.6
Theme (SecurityInspect wording)
security obligations, acceptable use and consequences

SIAS-WFS-03 Security awareness and phishing training

Mandatory
Yes
Severity
Medium
Applies
All scopes
SecurityInspect Verified profiles
None

Control objective

Everyone with access can recognize common attacks, handles data correctly, and knows how to report something suspicious.

Testable requirement

  • The applicant must:
  • 1.train all personnel within 30 days of starting, before any privileged access or access to Restricted data is granted, and at least every 12 months after that;
  • 2.cover in the training: phishing and social engineering (including phone- and message-based pretexts and repeated MFA prompts), password and MFA practice, data handling under the classification scheme (SIAS-DAT-01), safe use of devices and remote work, and how and when to report a suspected incident;
  • 3.run phishing simulations for personnel at least twice a year, and assign follow-up training to people who fail;
  • 4.provide a simple way to report suspected phishing (for example a report button or a dedicated mailbox) that reaches the security function;
  • 5.reach at least 95% completion among active personnel in each annual cycle, tracked in a system of record;
  • 6.update the content at least every 12 months, and sooner when relevant threats change. SIAS does not use phishing click rates as a pass criterion, because that would reward easy simulations. It checks that simulations run, fit the organization, and lead to follow-up.

Applicability and scope

All scopes. Covers all personnel. Not part of any SecurityInspect Verified profile.

Pass criteria

  • 1.Completion in the current annual cycle is at least 95%.
  • 2.Every sampled new starter was trained within 30 days, and every holder of privileged or Restricted-data access was trained before the access grant.
  • 3.The content covers every topic in requirement 2.
  • 4.At least two simulations ran in the 12 months before the assessment or, for a program younger than 12 months, one ran and the next is scheduled within 6 months of it.
  • 5.Follow-up training was assigned to, and completed by, people who failed a simulation.
  • 6.The reporting mechanism worked in M3.

Severity

Medium. The global escalation rules apply.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(5)(i), §164.308(a)(5)(ii)(A)
PCI DSS v4.0.1
12.6
Trust Services Criteria
CC1.4, CC2.2
ISO/IEC 27001:2022
A.6.3
Theme (SecurityInspect wording)
general security awareness for all personnel

SIAS-WFS-04 Role-based security training for technical and privileged staff

Mandatory
No
Severity
Medium
Applies
All scopes
SecurityInspect Verified profiles
None

Control objective

People whose work directly shapes security, such as developers, administrators and incident responders, have the specific security skills their roles need.

Testable requirement

  • The applicant must:
  • 1.identify the security-relevant technical roles in scope, at least: developers of in-scope software, system and cloud administrators, other holders of privileged access, incident responders and people who triage security alerts;
  • 2.define the security competencies each role needs;
  • 3.provide role-based security training at least every 12 months: secure coding and common vulnerability classes for developers, in the languages and frameworks in use; secure administration, privileged access handling and configuration hardening for administrators; the applicant's incident response plan and handling procedures for responders;
  • 4.provide that training before, or within 60 days of, a person taking on the role;
  • 5.record completion and evidence of competence (for example training records, relevant professional credentials or exercise participation) against each role's competencies.

Applicability and scope

All scopes. Covers personnel in the roles identified under requirement 1. Not part of any SecurityInspect Verified profile.

Pass criteria

  • 1.Technical roles and their competencies are defined.
  • 2.At least 90% of role holders were trained within the last 12 months, and every sampled new role holder within 60 days.
  • 3.The content is relevant to the technologies and procedures in use.
  • 4.Completion and competence records exist for every sampled role holder.

Severity

Medium. The global escalation rules apply.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(5)(i)
PCI DSS v4.0.1
6.2, 12.6, 12.10
Trust Services Criteria
CC1.4
ISO/IEC 27001:2022
7.2; A.6.3
Theme (SecurityInspect wording)
targeted training for technical roles

SIAS-WFS-05 Offboarding and role change

Mandatory
Yes
Severity
High
Applies
All scopes (HR-triggered process and asset return; technical deprovisioning is tested under SIAS-IAM-01)
SecurityInspect Verified profiles
None

Control objective

When someone leaves or changes role, the people who manage access find out in time, company assets and data come back, and continuing obligations are reinforced.

Testable requirement

  • The applicant must:
  • 1.have HR, or the owner of a contractor relationship, notify the access-management function of each separation no later than the separation date, and for an involuntary separation before or at the time the person is informed;
  • 2.use an offboarding checklist covering: the access removal request (tested under SIAS-IAM-01); return of devices, security keys, access badges and tokens; retrieval or deletion of company data on personal devices where they are allowed; transfer of ownership of accounts, keys, scripts, scheduled jobs and cloud resources the person owned; rotation of shared secrets the person knew; and a reminder of continuing confidentiality obligations;
  • 3.recover assets within 5 business days of separation, or remotely lock and wipe them;
  • 4.notify the access-management function of each role change within 5 business days, so that access the new role does not need is removed;
  • 5.record the completion of each checklist item with its date.

Applicability and scope

All scopes (HR-triggered process and asset return; technical deprovisioning is tested under SIAS-IAM-01). Covers all personnel. Not part of any SecurityInspect Verified profile.

Pass criteria

  • 1.Every sampled separation was notified on time, and A1 shows at least 95% of all separations in the look-back period notified on time.
  • 2.Every sampled involuntary separation was notified before or at the time the person was informed.
  • 3.Every sampled separation's assets were recovered, or locked and wiped, within 5 business days.
  • 4.Every sampled role change produced an access-change ticket within 5 business days.
  • 5.Every sampled checklist is complete, including shared-secret rotation where it applied.
  • 6.A4 found no in-scope resource still owned by a separated person.

Severity

High. The global escalation rules apply; for example, use of a separated person's access after separation that indicates compromise is a Critical finding, recorded under SIAS-IAM-01.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(3)(ii)(C)
PCI DSS v4.0.1
8.2
Trust Services Criteria
CC6.2
ISO/IEC 27001:2022
A.5.11, A.6.5
Theme (SecurityInspect wording)
access and asset handling at exit

Framework mappings in this domain

The mappings above are informative cross-references by identifier only. They don’t reproduce any framework’s text, and meeting a SIAS control doesn’t mean any framework requirement is met.

What framework mappings mean

SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.

How SIAS relates to other security frameworks

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.