ISP ISP Personnel Security & Insider Threats 2 — Questions and Answers
Question 1: The 'need-to-know' principle in personnel security means:
- Any cleared employee may access all information at their clearance level
- Access to specific information is granted only when operationally necessary for assigned duties (Correct answer)
- Employees need to know all security procedures regardless of role
- Managers must know all employees' personal background information
Correct answer: Access to specific information is granted only when operationally necessary for assigned duties
Need-to-know limits access to information to only what is required for a person to perform their specific job functions.
Question 2: Which process is used to verify that employees only retain access rights appropriate to their current role?
- Periodic reinvestigation
- Access recertification or entitlement review (Correct answer)
- Annual security awareness training
- Visitor log auditing
Correct answer: Access recertification or entitlement review
Access recertification (entitlement review) is the formal process of confirming that each user's permissions still match their job requirements.
Question 3: When an employee is terminated, which security action should be taken IMMEDIATELY?
- Scheduling a 30-day transition period before revoking access
- Revoking all logical and physical access simultaneously upon departure (Correct answer)
- Allowing the employee to retain email access to complete handover
- Waiting for HR to file paperwork before notifying IT
Correct answer: Revoking all logical and physical access simultaneously upon departure
Simultaneous revocation of all access upon termination prevents a departing employee from exfiltrating data or entering the facility.
Question 4: Social engineering targeting employees is BEST countered by:
- Restricting all employee communication with external parties
- Ongoing security awareness training and clear reporting procedures (Correct answer)
- Installing email filters that block all external messages
- Requiring managers to approve every employee decision
Correct answer: Ongoing security awareness training and clear reporting procedures
Awareness training equips employees to recognize social engineering tactics and empowers them to report suspicious contacts.
Question 5: What does 'two-person integrity' (TPI) primarily protect against in a personnel security context?
- Physical injuries during heavy-lifting tasks
- A single insider acting alone to commit theft or sabotage of critical assets (Correct answer)
- Cyber intrusions from external threat actors
- Unauthorized photography on the production floor
Correct answer: A single insider acting alone to commit theft or sabotage of critical assets
TPI requires two authorized individuals to be present during access to sensitive areas or materials, preventing unilateral insider action.
Question 6: Which federal guideline governs adjudicative standards for personnel security clearances in U.S. industrial environments?
- NIST SP 800-53
- The 13 Adjudicative Guidelines (Security Executive Agent Directive 4) (Correct answer)
- ISO 27001 Annex A
- Title 18 U.S. Code Section 1030
Correct answer: The 13 Adjudicative Guidelines (Security Executive Agent Directive 4)
SEAD 4 establishes the 13 Adjudicative Guidelines used to evaluate individuals for U.S. government-related security clearances.
The 'need-to-know' principle in personnel security means: