unified
UC-HR-05 — Hold third-party personnel to equivalent security terms
Contracts with suppliers and external organizations whose personnel access systems or data require equivalent personnel security measures, including screening, confidentiality agreements, and defined security responsibilities, and oblige the provider to notify the organization of personnel transfers or terminations affecting access. Third-party compliance with these personnel requirements is monitored.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Human Resources / Personnel Security
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-HR-05
- title
- Hold third-party personnel to equivalent security terms
- statement
- Contracts with suppliers and external organizations whose personnel access systems or data require equivalent personnel security measures, including screening, confidentiality agreements, and defined security responsibilities, and oblige the provider to notify the organization of personnel transfers or terminations affecting access. Third-party compliance with these personnel requirements is monitored.
- domain
- Human Resources / Personnel Security
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PS-7
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.20
- coverage
- partial
- delta
- broader supplier security terms addressed under third-party risk domain
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-HR-05 — Hold third-party personnel to equivalent security terms maps_to PS-7 — External Personnel Security
- framework
- nist-800-53
- control_id
- PS-7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Subservice Organization & Third-Party Personnel Oversight operates UC-HR-05 — Hold third-party personnel to equivalent security terms
- ISO 27001 SoA Review & Controls Assessment oversees UC-HR-05 — Hold third-party personnel to equivalent security terms
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-HR-05 — Hold third-party personnel to equivalent security terms
- UC-HR-05 — Hold third-party personnel to equivalent security terms maps_to A.5.20 — Addressing information security within supplier agreements
- framework
- iso-27001
- control_id
- A.5.20
- coverage
- partial
- delta
- broader supplier security terms addressed under third-party risk domain
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-HR-05 — Hold third-party personnel to equivalent security terms mitigates Insufficient personnel screening and vetting
- strength
- primary
- rationale
- Extends screening/vetting requirements to third-party and supplier personnel before access, closing the contractor vetting gap the risk explicitly names.
- UC-HR-05 — Hold third-party personnel to equivalent security terms mitigates Missing security terms in contracts and no disciplinary process
- strength
- primary
- rationale
- Requires equivalent security/confidentiality obligations in supplier contracts, directly closing the omitted-supplier-contract-terms gap.
- Third-Party Vendor Risk Lifecycle oversees UC-HR-05 — Hold third-party personnel to equivalent security terms