{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Human Resources / Personnel Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-HR-01","description":"Every position is assigned a risk designation that determines its screening requirements and is reviewed as roles change. Background verification, including identity, employment and education history, and criminal or other checks as permitted by law, is completed before employment and before access to systems or sensitive information, proportional to position risk and data sensitivity. Personnel in high-risk roles are rescreened at defined intervals, and screening records are retained.","details":{"control_category":"administrative","control_type":"preventive","domain":"Human Resources / Personnel Security","guidance":[],"members":[{"control_id":"PS-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PS-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.6.1","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"HIPAA-164.308","coverage":"partial","delta":"risk analysis, training, contingency, evaluation, and BAAs satisfied in other domains","framework":"hipaa","relationship":"intersects_with"}],"statement":"Every position is assigned a risk designation that determines its screening requirements and is reviewed as roles change. Background verification, including identity, employment and education history, and criminal or other checks as permitted by law, is completed before employment and before access to systems or sensitive information, proportional to position risk and data sensitivity. Personnel in high-risk roles are rescreened at defined intervals, and screening records are retained.","title":"Screen personnel commensurate with position risk","unified_id":"UC-HR-01"},"id":"uc:UC-HR-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-HR-01","sourceIds":["hipaa","iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-HR-01 — Screen personnel commensurate with position risk","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1cb88ad31fad6a9e0e9c8514b3ca39b8af4f9844e4537326a3a6ea5ccda163cf","properties":{},"sourceDetailPath":"/data/v1/records/wf-d31-af2d985a.json","sourceId":"wf:D31","targetDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","targetId":"uc:UC-HR-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2bc3000083b70b18a8b11bb2a3c1c3af8db4c52ea608871c69176b9bdc03be19","properties":{"rationale":"Background verification and position-risk vetting before access is the operative defense against placing unvetted, insider-threat, or compromised individuals in roles.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","sourceId":"uc:UC-HR-01","targetDetailPath":"/data/v1/records/risk-hr-insufficient-screening-bdce1f80.json","targetId":"risk:hr-insufficient-screening","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2d99176afb9138ef5b612f346d10e2d61ff4ba10be933aad97396ae8f8ab4436","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","targetId":"uc:UC-HR-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4c76887f16a729d967fea9d02d6b96e7e66786d121e4537ec8b2390907b24ef4","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","targetId":"uc:UC-HR-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a6ee7bb71598007c95021c955a96b2c1acda401441d403b7218ab5f3411adcb","properties":{"control_id":"A.6.1","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","sourceId":"uc:UC-HR-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-6-1-048c51f3.json","targetId":"ctrl:iso-27001:A.6.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:811dd03d281d40cf4eae6e69325d75c1fdb8a48531d89b295714d52319f8c3b4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c7-acbef2ee.json","sourceId":"wf:C7","targetDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","targetId":"uc:UC-HR-01","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:99add7743fc03c19485dec411957bb1295d8be6e7c3bb47add70c1e2c52e4609","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","sourceId":"uc:UC-HR-01","targetDetailPath":"/data/v1/records/risk-hr-discrimination-harassment-767d6cb7.json","targetId":"risk:hr-discrimination-harassment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b8ac22db464c1e05c1286c62ad846d099b579a8246dde5212f64d48d01418e67","properties":{"control_id":"HIPAA-164.308","coverage":"partial","delta":"risk analysis, training, contingency, evaluation, and BAAs satisfied in other domains","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","sourceId":"uc:UC-HR-01","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-308-d26b6932.json","targetId":"ctrl:hipaa:HIPAA-164.308","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c1bd9215ec9467228146820e6cc816128eca4a888543bb18b551142ff8b1c229","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","targetId":"uc:UC-HR-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e0e1c48886bb1e0816660f1d827f817d5600638062887bad534931adea6e7d12","properties":{"control_id":"PS-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","sourceId":"uc:UC-HR-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ps-2-6e7702ad.json","targetId":"ctrl:nist-800-53:PS-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e31cf06f5eb98c4a323207995149bb3857d8d852661b45a98cf19e9ed679298b","properties":{"control_id":"PS-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","sourceId":"uc:UC-HR-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ps-3-5252df81.json","targetId":"ctrl:nist-800-53:PS-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fdc9f7db49a3601597ca5792f50302eddf6ed6246561f19243008acaf093bcc9","properties":{},"sourceDetailPath":"/data/v1/records/wf-g25-fdd65bfd.json","sourceId":"wf:G25","targetDetailPath":"/data/v1/records/uc-uc-hr-01-c7e14dc5.json","targetId":"uc:UC-HR-01","type":"operates"}],"schemaVersion":1}
