{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Human Resources / Personnel Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-HR-05","description":"Contracts with suppliers and external organizations whose personnel access systems or data require equivalent personnel security measures, including screening, confidentiality agreements, and defined security responsibilities, and oblige the provider to notify the organization of personnel transfers or terminations affecting access. Third-party compliance with these personnel requirements is monitored.","details":{"control_category":"administrative","control_type":"preventive","domain":"Human Resources / Personnel Security","guidance":[],"members":[{"control_id":"PS-7","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.5.20","coverage":"partial","delta":"broader supplier security terms addressed under third-party risk domain","framework":"iso-27001","relationship":"intersects_with"}],"statement":"Contracts with suppliers and external organizations whose personnel access systems or data require equivalent personnel security measures, including screening, confidentiality agreements, and defined security responsibilities, and oblige the provider to notify the organization of personnel transfers or terminations affecting access. Third-party compliance with these personnel requirements is monitored.","title":"Hold third-party personnel to equivalent security terms","unified_id":"UC-HR-05"},"id":"uc:UC-HR-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-HR-05","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-HR-05 — Hold third-party personnel to equivalent security terms","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0fc906b29aa29c07df4a5c5f844d7bc457087e94cf1690a12380278f97b90bff","properties":{"control_id":"PS-7","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-05-4049a32e.json","sourceId":"uc:UC-HR-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ps-7-680a349e.json","targetId":"ctrl:nist-800-53:PS-7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:109ae7a3281ce93df48101168a36f078b44d0abbb825f5f2728c9c2eab4e869b","properties":{},"sourceDetailPath":"/data/v1/records/wf-g24-104b8991.json","sourceId":"wf:G24","targetDetailPath":"/data/v1/records/uc-uc-hr-05-4049a32e.json","targetId":"uc:UC-HR-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:19a67cdf8d0e6cd29a4ac11f520577c57e663c4a62986da65b97a4db3cc9f028","properties":{},"sourceDetailPath":"/data/v1/records/wf-c7-acbef2ee.json","sourceId":"wf:C7","targetDetailPath":"/data/v1/records/uc-uc-hr-05-4049a32e.json","targetId":"uc:UC-HR-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3e2082e49bf5339530af23ee4ccc049fdca8735257a9815012114d7c20ad5136","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-hr-05-4049a32e.json","targetId":"uc:UC-HR-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3f1b9ea154938221b1defc204c43a177d21cac451064cf698d3df8848fb47b3f","properties":{"control_id":"A.5.20","coverage":"partial","delta":"broader supplier security terms addressed under third-party risk domain","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-05-4049a32e.json","sourceId":"uc:UC-HR-05","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-20-fcee3b34.json","targetId":"ctrl:iso-27001:A.5.20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65f30ed34c2d77fe0ce1e9f7ecd158df708cdb2daf4d52b32fd6bc32708c1a88","properties":{"rationale":"Extends screening/vetting requirements to third-party and supplier personnel before access, closing the contractor vetting gap the risk explicitly names.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-05-4049a32e.json","sourceId":"uc:UC-HR-05","targetDetailPath":"/data/v1/records/risk-hr-insufficient-screening-bdce1f80.json","targetId":"risk:hr-insufficient-screening","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:917c47e526cb5662e593df9df444dad343279359310bfda427da1993e5cc6a36","properties":{"rationale":"Requires equivalent security/confidentiality obligations in supplier contracts, directly closing the omitted-supplier-contract-terms gap.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-05-4049a32e.json","sourceId":"uc:UC-HR-05","targetDetailPath":"/data/v1/records/risk-hr-missing-security-terms-discipline-0a47163d.json","targetId":"risk:hr-missing-security-terms-discipline","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9ccddd41682b7cf0ac016a8950c5acac2673ccc0a6cf2253158f5b7ed08b897d","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-hr-05-4049a32e.json","targetId":"uc:UC-HR-05","type":"oversees"}],"schemaVersion":1}
