# PS-07 External Personnel Security — NIST 800-53 Rev5 control

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /control/ps-7

Canonical id: `ps-7` · family `PS`

> a. Establish personnel security requirements, including security roles and responsibilities for external providers; b. Require external providers to comply with personnel security policies and procedures established by the organization; c. Document personnel security requirements; d. Require external providers to notify [personnel or roles] of any personnel transfers or terminations of external personnel who possess organizational credentials and/or badges, or who have system privileges within [time period]; and e. Monitor provider compliance with personnel security requirements.

_Control title and statement: NIST SP 800-53 Rev5 catalog (the pinned commit is in `/api` under `control_text`). The FedRAMP rules reference these controls by id only; everything below is what FedRAMP says about this id._

## Rev5 baseline membership

- certification class B
- certification class C
- certification class D

## Key Security Indicators that reach it

- `KSI-SCR-MON` — Monitoring Supply Chain Risk (Supply Chain Risk)
  Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.

## FedRAMP guidance

{
  "guidance": [
    "CSPs MUST clearly document any nationality requirements for any account type within its platform. If none exists, this must also be explicitly stated."
  ]
}
