🇬🇧 CISMP (Certificate in Information Security Management Principles) · subject
CISMP (Certificate in Information Security Management Principles) Procedural and People Security Controls Syllabus
Every chapter and topic of Procedural and People Security Controls examined in CISMP (Certificate in Information Security Management Principles) — 3 chapters, 9 topics and 17 sub-topics, plus 51 flashcards written against it.
Procedural and People Security Controls syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Procedural and People Security Controls in CISMP (Certificate in Information Security Management Principles), not a summary of it.
-
Human Resource Security
3 topics- Security before employment
- Pre-employment screening and vetting
- Terms, conditions and NDAs
- Security during employment
- Roles, responsibilities and disciplinary process
- Acceptable use policies
- Termination and change of employment
- Removal of access rights
- Return of assets
- Security before employment
-
Security Awareness, Education and Training
3 topics- The need for awareness
- Human factors and the insider threat
- Designing awareness programmes
- Tailoring to audiences
- Measuring effectiveness
- Social engineering defence
- Phishing and pretexting
- Reporting and response
- The need for awareness
-
User Access Management and Provisioning
3 topics- Identification, authentication and authorisation
- Something you know, have, are
- Multi-factor authentication
- Access control models
- Least privilege and need-to-know
- Role-based access control
- Account and privilege management
- Joiners, movers and leavers
- Privileged account control
- Identification, authentication and authorisation
Procedural and People Security Controls flashcards for CISMP (Certificate in Information Security Management Principles)
22 of 51 cards from the Procedural and People Security Controls deck — real questions with worked answers.
In information security, what are the three core 'people' processes covered by personnel security within the employment lifecycle?
Security before employment (pre-employment screening), security during employment (ongoing controls and awareness), and termination/change of employment (revoking access and returning assets).
What is the purpose of pre-employment screening (vetting) in personnel security?
To verify a candidate's identity, qualifications, and trustworthiness before granting access, reducing the risk of hiring someone who poses an insider threat or misrepresents their background.
List typical checks performed during pre-employment screening.
Identity verification, right-to-work, employment history references, academic/professional qualifications, criminal record checks, credit/financial checks (for sensitive roles), and gaps in CV.
In the UK, what national vetting levels are used for roles requiring access to government/classified information?
Baseline Personnel Security Standard (BPSS), Counter Terrorist Check (CTC), Security Check (SC), and Developed Vetting (DV) - increasing in depth and intrusiveness.
Which UK vetting level is the minimum standard for staff with access to government assets, and what does it confirm?
BPSS (Baseline Personnel Security Standard). It confirms identity, employment history (3 years), nationality/immigration status, and any unspent criminal records.
What contractual security mechanism should be agreed before employment begins?
Terms and conditions of employment that state the employee's security responsibilities, including signing confidentiality/non-disclosure agreements (NDAs) and acceptable use policies.
Why must screening be proportionate to the role under data protection law?
Excessive or intrusive checks can breach data protection principles (data minimisation and fairness under UK GDPR), so the depth of screening must match the sensitivity and access level of the role.
What security controls apply 'during employment' to keep staff acting securely?
Management responsibilities, ongoing security awareness/training, an acceptable use policy, and a disciplinary process for security breaches.
What is the role of a formal disciplinary process in personnel security?
It provides a documented, fair sanction for staff who commit security breaches, acting as a deterrent and giving the organisation grounds to act consistently and lawfully.
What is meant by an 'insider threat'?
A security risk originating from people within the organisation (employees, contractors, partners) who misuse legitimate access, whether maliciously, negligently, or through coercion.
Distinguish a malicious insider from a negligent (accidental) insider.
A malicious insider deliberately abuses access to harm the organisation; a negligent insider unintentionally causes harm through carelessness, error, or being tricked (e.g. falling for phishing).
What security actions are required on termination or change of employment?
Revoke/adjust logical and physical access rights, recover assets (passes, tokens, devices, keys), remind the individual of ongoing confidentiality obligations, and disable accounts promptly.
Why is timely revocation of access especially critical for a disgruntled leaver?
A disgruntled leaver retaining active credentials presents a high insider-threat risk of sabotage or data theft, so access should be removed immediately - ideally before or at the moment of notification.
When an employee changes roles internally, what access-control principle must be enforced?
Access creep must be prevented by removing privileges no longer needed for the new role, not merely adding new ones - re-baselining entitlements to the new role's least-privilege requirement.
What ongoing obligation typically survives the end of an employment contract?
Confidentiality/non-disclosure obligations (and any restrictive covenants) continue after termination, protecting the organisation's information indefinitely or for an agreed period.
Define security awareness as distinct from security training.
Awareness focuses attention on security so people recognise and respond to threats (the 'what' and 'why'); training builds specific skills and competencies (the 'how') for performing secure tasks.
Why is security awareness considered essential despite strong technical controls?
People are often the weakest link; many breaches exploit human behaviour (e.g. phishing, weak passwords). Awareness reduces human-error risk that technical controls alone cannot prevent.
Distinguish awareness, training, and education in security learning.
Awareness changes attention/behaviour (short, broad), training imparts job-specific skills (focused), and education provides deep, conceptual understanding (long-term, e.g. a qualification).
Name the typical stages in designing a security awareness programme.
Identify objectives and audience, assess current awareness/needs, design content and delivery methods, implement/deliver, then measure effectiveness and review/improve.
Why should an awareness programme be tailored (segmented) by audience?
Different groups (executives, developers, finance, general staff) face different threats and have different responsibilities, so targeted, role-relevant content is more engaging and effective than a single generic message.
Give examples of delivery methods for security awareness.
E-learning modules, posters and intranet articles, newsletters, simulated phishing exercises, classroom/inductions, lunch-and-learn sessions, screensavers, and gamification.
How can the effectiveness of an awareness programme be measured?
Metrics such as simulated phishing click rates, incident report numbers, quiz/test scores, policy acknowledgement rates, completion rates, and trend analysis over time.
See more Procedural and People Security Controls flashcards →
Planning Procedural and People Security Controls for CISMP (Certificate in Information Security Management Principles)
Procedural and People Security Controls is about 11% of the CISMP (Certificate in Information Security Management Principles) syllabus by topic count — 9 of 81 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 10 hours.
The heaviest chapters are Human Resource Security (3 topics), Security Awareness, Education and Training (3 topics), User Access Management and Provisioning (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Procedural and People Security Controls (CISMP (Certificate in Information Security Management Principles)) FAQ
What is in the CISMP (Certificate in Information Security Management Principles) Procedural and People Security Controls syllabus?
Procedural and People Security Controls is split into 3 chapters — Human Resource Security, Security Awareness, Education and Training and User Access Management and Provisioning, containing 9 topics and 17 sub-topics in total.
How is Procedural and People Security Controls structured in the CISMP (Certificate in Information Security Management Principles) syllabus?
3 chapters. Procedural and People Security Controls accounts for about 11% of the topics in the whole CISMP (Certificate in Information Security Management Principles) syllabus (9 of 81).
How long should I spend on Procedural and People Security Controls for CISMP (Certificate in Information Security Management Principles)?
Budget around 10 hours for a first pass through Procedural and People Security Controls — about 45 minutes per topic plus 12 minutes per sub-topic across its 9 topics. Add revision cycles on top.
Are there flashcards for CISMP (Certificate in Information Security Management Principles) Procedural and People Security Controls?
Yes — a 51-card Procedural and People Security Controls deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.