Security Management

NOT PROTECTIVELY MARKED

PERSONNEL SECURITY RISK ASSESSMENT
A GUIDE
4th Edition - June 2013

Disclaimer Reference to any specific commercial product, process or service by trade name, trademark, manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation or favour by CPNI. The views and opinions of authors expressed within this document shall not be used for advertising or product endorsement purposes. To the fullest extent permitted by law, CPNI accepts no liability for any loss or damage (whether direct, indirect or consequential, and including but not limited to, loss of profits or anticipated profits, loss of data, business or goodwill) incurred by any person and howsoever caused arising from or connected with any error or omission in this document or from any person acting, omitting to act or refraining from acting upon, or otherwise using the information contained in this document or its references. You should make your own judgment as regards use of this document and seek independent professional advice on your particular circumstances.

NOT PROTECTIVELY MARKED

NOT PROTECTIVELY MARKED

Contents
The aim of this guidance Personnel security Personnel security risk assessment Risk management in personnel security Risk assessment: an overview The organisation-level risk assessment The group-level risk assessment The role-based (individual) risk assessment Next steps Annex A: Blank personnel security risk assessment tables and example completed risk assessment tables Annex B: Diagrams for use in personnel security risk assessments Annex C: Who should be involved and where to find threat advice 3 3 3 4 5 7 15 18 18

19 25 26

NOT PROTECTIVELY MARKED

2

NOT PROTECTIVELY MARKED

The aim of this guidance
Personnel security risk assessment focuses on employees, their access to their organisation’s assets, the risks they could pose and the adequacy of existing countermeasures. This risk assessment is crucial in...