Firstly, it mandates screening individuals before authorizing access to CUI systems. This screening assesses an individual's trustworthiness through background checks, reference verifications, and security awareness training. These checks help identify any potential risks before granting access to sensitive information.
Secondly, the focus remains on securing CUI even during personnel changes. The requirement emphasizes procedures to revoke access upon termination or transfer. This includes disabling user accounts, terminating active sessions, and retrieving any government-issued equipment. These measures prevent unauthorized access to CUI after an employee departs the organization.